AddThisFeature

Trusted Devices

Stop asking for a second factor on the laptop they use every day.

involved Security & Reliability

What it adds

A per-device trust token that skips repeat verification on familiar devices, with expiry, naming, and revocation.

What your agent is told to do

5
  1. 1

    Issue a signed, revocable token stored on the device when the user opts to trust it after a successful verification, and record the device server-side so it can be listed and revoked.

  2. 2

    Rotate the token on each use so a stolen copy has a short useful life and reuse of an old token is detectable.

  3. 3

    Expire trust after a fixed period regardless of activity, and drop all trust on password change, second-factor change, or recovery.

  4. 4

    Show the user their trusted devices with a name, last-used time, and a revoke control, plus revoke-all.

  5. 5

    Do NOT trust a browser fingerprint on its own. Fingerprints collide across similar machines and cannot be revoked, which makes them useless as a security boundary.

Edge cases it handles

6
  • A cleared cookie jar means the device simply is not trusted anymore — verify again rather than trying to recover trust from other signals.
  • A copied or cloned browser profile will present a valid token; token rotation plus a reuse alarm is what catches it.
  • High-risk actions — changing the password, adding a payment method, exporting data — must require fresh verification even on a trusted device.
  • Trust is per user and per device: a shared machine must not skip verification for a second account.
  • Cap the number of trusted devices and prompt the user when they hit it, rather than growing the list without bound.
  • Signing in from a trusted device in a new country should still trigger verification.

Definition of done

8
  • Trust is a revocable server-side record backed by a rotating token, not a fingerprint.
  • Trust expires on a fixed schedule and is cleared on any credential change.
  • Users can name, list, and revoke devices, including all at once.
  • High-risk actions require fresh verification regardless of trust.
  • Token reuse after rotation is detected and revokes the device.
  • Trust does not carry across user accounts on the same machine.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.