
Today, we’re introducing multi-factor authentication (MFA) and Scoped Sessions for enterprise teams that need per-action security across the Turnkey wallets they support. Both features are built into Turnkey’s policy engine, which already governs onchain actions through authenticators and programmable rules.
Enterprise teams often need more precise controls than a single account-wide setting can provide. Supporting high-value transactions across a large customer base requires security tailored to each action.
With flat security models, routine balance checks and six-figure transfers receive the same controls and protections. MFA and Scoped Sessions remove that tradeoff. You decide where extra proof is worth the friction and keep every session narrowed to the task at hand.
Flexible security for each session
Most wallet security is applied as a single setting that treats every action the same way.
For example, if a session inherits all of a user’s permissions, a token meant to sign a swap may also be able to export a key or access a wallet it never needs to touch. MFA and Scoped Sessions change this by letting teams define who can authorize a session and exactly what that session can do, with controls enforced inside Turnkey’s secure enclaves.
How Multi-Factor Authentication (MFA) works
Multi-factor authentication (MFA) requires users to verify their identity with an additional authenticator before completing sensitive actions.
MFA lets you choose exactly which operations require an additional authenticator. Gate a high-value transfer, the addition of a new login method, or a wallet export while keeping everyday actions fast.
MFA rules live in the same policy engine that already governs your wallets. Any rule you can express as a policy can trigger it. Requirements can be tiered by transaction value or sensitivity, with thresholds and session durations you define.
With delegated access, operators can set MFA requirements on a user’s behalf. Because those requirements live in the policy engine, the end user cannot switch them off.
MFA can also gate account management actions, including adding a new authenticator. This prevents an attacker who compromises a session from quietly registering new credentials for persistent access.
Turnkey supports six types of authentication: passkey, email OTP, SMS OTP, OAuth, API key, and session.
How Scoped Sessions work
Scoped Sessions enforce least privilege by default. Rather than handing a session the user's full permissions, you grant only what the task needs along three dimensions: which actions are allowed, which wallets are reachable, and how long the session lasts.
That means you can allow transaction signing while blocking key export, open access to one wallet instead of the whole organization, and expire the session after a set duration.
If a session is ever misused, the damage stays contained to the narrow scope you defined.
Because scope is expressed as policy, it is consistent and auditable. There is no separate permissions layer to keep in sync with the rules that already govern the wallet.
Using MFA and Scoped Sessions together
The two controls are strongest in combination. You can require an additional authenticator to unlock a scoped session, then let the user take several sensitive actions inside that session without a fresh challenge on each one.
The result is protection that tracks context. A user is asked for extra proof once, at the moment risk actually rises, and then works within a session already narrowed to the task. Least privilege is the default, and stronger verification appears exactly where it earns its place.
Neither control is a bolt-on toggle. MFA and Scoped Sessions are primitives inside the policy engine, so the same rules that already decide who can sign, how much can move, and which wallets are in play can now trigger a second factor or scope a session.
That design has a practical payoff. Security composes with logic your team has already written instead of living in a parallel system, and there is no new model to learn before you can put these controls to work.
Built for teams that match security to risk
Turnkey has always aimed to give developers the tools to build secure, verifiable, high-performance onchain applications. MFA and Scoped Sessions extend that goal to the shape of each team's own risk.
For consumer apps on Embedded Wallets, that means smooth onboarding and fast routine actions, with a firm check on the operations that could cost a user real money. For teams running Company Wallets, it means operational work stays quick while treasury moves and key operations carry the proof they warrant.
In both cases the principle is the same: apply stronger controls where risk is highest, keep access tightly scoped everywhere else, and never trade speed for safety on ordinary work.
Getting started with MFA and Scoped Sessions
MFA and Scoped Sessions are available through the Turnkey API and SDK.
Existing customers can add these controls without changing how their current policies behave. Extend what those policies enforce, then apply MFA and Scoped Sessions only to the actions and sessions that need them.
If you are integrating Turnkey for the first time, you can build these controls into your wallet architecture from the start, tailoring authentication requirements and session permissions to each use case.
Review the MFA and Scoped Sessions documentation, or get started with Turnkey today.
Related articles

Turnkey expands Monad and Optimism support (TX management, gas sponsorship, balances)
Today Turnkey announces expanded infrastructure support for Monad and Optimism, including balances, transaction management, and gas sponsorship.
.avif)
Turnkey and Breez bring secure, non-custodial Bitcoin payments for applications
Turnkey wallets and the Breez SDK now let developers add instant, non-custodial Bitcoin and stablecoin payments to their applications.
.jpg)
