Websites should not ask me to add a Passkey while I am logging to your site!

Just ran into an extremely frustrating issue where Dropbox asked me to add a passkey to my account. Now I have not fully transitioned all my accounts to passkeys, so I wanted to do it intentionally, on my terms. But my 1Password flow, in conjunction with Dropbox’s Passkey request resulted in me creating a passkey right before logging into my account. Which is not what I desired!

How many users are making such dramatic changes on their accounts without realizing it? Websites and platforms are so adamant about pushing past keys for security. Well, what about considering the UX and user interface challenges that users may be facing?

I know I’m frustrated. I’m sure others are too. I really hope nobody loses their accounts as a result of something like this. But sadly we know this story all too well.