<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with passkey]]></title><description><![CDATA[A list of topics that have been tagged with passkey]]></description><link>https://fusionauth.io/community/forum/tags/passkey</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 23:22:05 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/passkey.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[Does logging in with a passkey update the user&#x27;s last login instant?]]></title><description><![CDATA[<p dir="auto">Yes, successfully logging in with a passkey <strong>will</strong> update the user's last login instant.</p>
<p dir="auto">However, there are edge cases where a passkey can be used without updating the last login timestamp:</p>
Scenarios where passkey use doesn't update last login:


<p dir="auto"><strong>Login flow interrupted</strong> — The user authenticates with the passkey, but the login is stopped before completion due to:</p>

Failed MFA challenge
User action requirement (e.g., forced password reset)
Account lock or suspension
Login validation Lambda or transactional webhook rejecting the login



<p dir="auto"><strong>WebAuthn assertion without login</strong> — If the user performed a WebAuthn assertion directly via the API, this counts as using the passkey but does not constitute a full login flow and therefore doesn't update the last login instant. The <a href="https://fusionauth.io/docs/apis/webauthn/complete-a-webauthn-passkey-assertion" rel="nofollow ugc">Complete a WebAuthn Passkey Assertion API</a> validates the WebAuthn ceremony but "does not authenticate the user into an application." This is different from the <a href="https://fusionauth.io/docs/apis/webauthn/complete-a-webauthn-passkey-authentication" rel="nofollow ugc">Complete a WebAuthn Passkey Authentication API</a>, which validates the passkey and authenticates the user, thus updating the last login instant.</p>


Summary
<p dir="auto">A passkey being "used" is not the same as a completed login. The last login timestamp only updates when the authentication flow completes successfully and issues a token.</p>
Related Documentation

<a href="https://fusionauth.io/docs/apis/webauthn/complete-a-webauthn-passkey-authentication" rel="nofollow ugc">Complete a WebAuthn Passkey Authentication</a> - The API that validates passkeys and authenticates users (updates last login)
<a href="https://fusionauth.io/docs/apis/webauthn/complete-a-webauthn-passkey-assertion" rel="nofollow ugc">Complete a WebAuthn Passkey Assertion</a> - The API that only validates passkeys without authenticating (does not update last login)
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/passwordless/webauthn-passkeys" rel="nofollow ugc">Authentication With WebAuthn &amp; Passkeys</a> - Complete guide to WebAuthn/passkey authentication in FusionAuth
<a href="https://fusionauth.io/docs/apis/login/update-instant" rel="nofollow ugc">Update Login Instant API</a> - Manual API for updating login instants when implementing custom SSO
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/setting-up-user-account-lockout" rel="nofollow ugc">Setting Up User Account Lockout</a> - How account lockouts can interrupt login flows

]]></description><link>https://fusionauth.io/community/forum/topic/3173/does-logging-in-with-a-passkey-update-the-user-s-last-login-instant</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3173/does-logging-in-with-a-passkey-update-the-user-s-last-login-instant</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>