β‘ Major update Headlockr 5 is out now. Passkeys and more are here. Click here to get started with the new setup.
Bring smoother cross-device authentication to Strapi with QR-based sign-in and companion-powered login flows.
Users will be able to approve login attempts from the dedicated Headlockr mobile app using biometric authentication, or complete secure verification challenges similar to modern mobile approval flows used by platforms like GitHub.
Whatβs coming:
QR-driven sign-in across devices
Let users start a login on desktop and securely complete it from their mobile device.
Companion-powered passkey experiences
Enable more flexible passkey flows with the Headlockr mobile app as a trusted companion.
A smoother path to modern authentication in Strapi
Reduce login friction while keeping strong security controls in place.

Trusted devices help reduce unnecessary MFA prompts without weakening security. When a user signs in from a known device, they can choose to skip MFA for a configurable period of time. This keeps the login experience fast and frictionless for trusted environments, while still allowing users & administrators to revoke trusted devices at any moment.

Headlockr now integrates with Have I've been Pwned breach corpus. During login accounts will be checked and administrators will be notified when a password in the environment has been compromised. No passwords will leave your environment during this check. It's an offline check against HIBP hashlist.

You can now force password rotation after a configurable number of days and redirect the user into the reset-password flow when their password has or is about to expire.

Require MFA per role, define allowed enrollment methods, and give new users a configurable grace period before enforcement kicks in.
- Set enforcement rules per role
- Allow only approved factors during enrollment
- Use grace periods before hard enforcement begins

Headlockr is now fully compatible with Strapi v5! Our latest version brings full support for the newest Strapi core, so you can upgrade with confidence and stay secure.

You can now use email as a two-factor authentication method β both for verifying identity and completing logins. Fully supported for admin panel and content API.
We're excited to announce that Headlockr now supports multi-factor authentication for the content API β not just the admin panel. This brings powerful security to your public endpoints as well. SDKs and a starter project are coming soon to make integration even easier.

The MFA challenge grace period will allow users a predefined window of time during which they will not need to re-authenticate via MFA after a successful login. This feature strikes a balance between user convenience and security by reducing repetitive MFA prompts while maintaining secure session management. Administrators will be able to configure the grace period to suit their security policies.

We're working on native support for Passkeys β enabling secure, passwordless authentication using Face ID, Touch ID, device PINs, or hardware keys. Say goodbye to passwords and hello to phishing-resistant logins.

Add another layer of protection: soon you'll be able to restrict logins based on country or region. Useful for limiting backend access to trusted locations only.

Auto logout ensures that inactive users are automatically signed out after a set period of inactivity, reducing the risk of unauthorized access to unattended sessions. Administrators will have the flexibility to configure the inactivity timeout duration based on security requirements. This feature enhances overall account and data security by preventing stale sessions from being exploited.
A robust user management system will allow administrators to efficiently manage user accounts and permissions. This feature will include functionalities such as creating, updating, or deactivating users, assigning roles and privileges, and viewing user activity. Bulk user import and export options will also streamline administration in large organizations.
© 2026 copyright Headlockr, all rights reserved