How step-up authentication works
A user logs in once, with a password or a passkey, and the session starts at a certain level of trust. Most actions, like browsing or reading messages, stay within that level. Some actions need more: changing the email or password, adding a payee, withdrawing funds, viewing full card details. For those, the system asks for a second factor right then, even though the user is already logged in.
Step-up can also be triggered by risk rather than by the action. If a login comes from a new device on a new network in another country, the system can ask for extra proof before the session starts, while the same user on their usual phone goes straight in. This is often called risk-based or adaptive authentication.
Good step-up also learns: once a user passes, the device can be marked as trusted for that account, so the same person on the same phone is not asked again next week.
Common triggers and step-up methods
| Trigger | Why it is risky | Typical step-up |
|---|---|---|
| Login from a new device and network | A classic sign of account takeover | One-time code or passkey |
| Change of email, phone or password | Attackers lock out the real owner this way | Passkey or code to the old contact |
| New payee or withdrawal address | Where stolen funds leave | Passkey or in-app approval |
| High-value or unusual payment | Card and account fraud | 3-D Secure challenge |
| Medium risk score at signup or checkout | Possible bot or spoofed device | Invisible challenge first, then a code |
Step-up vs always-on MFA
Always-on multi-factor authentication asks every user for a second factor on every login. It is simple and strong, but it adds friction to every session, and users who face it constantly learn to approve prompts without thinking. Step-up keeps the extra check for the moments that need it, which makes each prompt meaningful.
The weak point of step-up is the decision about when to trigger it. If the risk signal is poor, attackers on a clean-looking session get through, and real customers are challenged for no reason. SMS codes also have limits: they can be phished or intercepted through SIM swaps, and sending them can be abused for SMS pumping. Passkeys and in-app approvals resist phishing better.
How Kavra decides when to step up
Kavra gives your backend the signal that makes step-up precise. Each login or sensitive action is compared with the account's own history: known devices, usual networks, impossible travel, known-bad devices. It returns a recommendation to allow, verify or block, with the reasons. You trigger step-up on verify, and trusted devices per account keep regular customers free of prompts. See how it protects logins in account takeover prevention and credential stuffing protection.