# 2fa security key breaks when migrating to custom domain

**URL:** https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528
**Category:** Bug
**Created:** [June 22, 2020, 8:11am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528 "2020-06-22T08:11:36Z")
**Posts on this page:** 17
**Page:** 1

<div class="post-metadata">

### Author: ![balboah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/balboah/32/184387_2.png) [@balboah](https://meta.discourse.org/u/balboah)
#### Post date: [June 22, 2020, 8:11am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/1 "2020-06-22T08:11:36Z")

</div>

After using the trydiscord domain and then configuring the real custom domain to use, 2fa breaks. I believe fido2 associates domains with the key.

Also another admin can’t disable the key, it becomes “invalid parameters” (same as [Can't turn off 2 factor](https://meta.discourse.org/t/cant-turn-off-2-factor/155513)). Trying to migrate again to the same custom domain will also be denied because “Hostname already exists.”.

My account is then bricked, please advice

---

<div class="post-metadata">

### Author: ![Benjamin\_D](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/benjamin_d/32/277831_2.png) [@Benjamin\_D](https://meta.discourse.org/u/Benjamin_D)
#### Post date: [June 22, 2020, 8:20am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/2 "2020-06-22T08:20:25Z")

</div>

maybe you could try this:

> [@Oops, I lost my phone. How can I OTP now?](https://meta.discourse.org/t/oops-i-lost-my-phone-how-can-i-otp-now/143899/5):
>
> Search “disable 2fa” first result says So: ./launcher enter app rails c id = User.find\_by(username: "YOURUSERNAME").id UserSecondFactor.totps.where(user\_id: id).each(&:destroy!)

---

<div class="post-metadata">

### Author: ![balboah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/balboah/32/184387_2.png) [@balboah](https://meta.discourse.org/u/balboah)
#### Post date: [June 22, 2020, 8:21am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/3 "2020-06-22T08:21:36Z")

</div>

this is the managed discourse paid plan migration. So I’m afraid I don’t think I have that low level access

---

<div class="post-metadata">

### Author: ![itsbhanusharma](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/itsbhanusharma/32/180717_2.png) [@itsbhanusharma](https://meta.discourse.org/u/itsbhanusharma)
#### Post date: [June 22, 2020, 10:57am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/4 "2020-06-22T10:57:39Z")

</div>

I’m afraid there is no permanent solution available at this time but you can contact the Discourse support email mentioned in your discourse admin area, they may be able to disable 2fa for all users.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 22, 2020, 12:50pm UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/5 "2020-06-22T12:50:14Z")

</div>

> [@balboah](#):
>
> . I believe fido2 associates domains with the key.

I think so too. If you don’t have backup keys you’ll need to contact support.

---

<div class="post-metadata">

### Author: ![balboah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/balboah/32/184387_2.png) [@balboah](https://meta.discourse.org/u/balboah)
#### Post date: [June 22, 2020, 1:03pm UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/6 "2020-06-22T13:03:42Z")

</div>

It was solved by support by removing the security keys on my account. Don’t change domain name while having 2fa 🙂  
This should be a kind of common issue as you would change the domain when wanting to upgrade from discourse trial.

Oh and don’t loose access to your e-mail as that’s when you can request to remove security keys 😉

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 22, 2020, 10:15pm UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/7 "2020-06-22T22:15:06Z")

</div>

> [@balboah](#):
>
> Don’t change domain name while having 2fa

FWIW, you can use the backup keys. I’ve done this on staging sites where they have 2fa turned on and the production database gets restored to the staging site with its own domain name.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [June 23, 2020, 5:35am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/11 "2020-06-23T05:35:41Z")

</div>

@balboah quick update, we have this assigned internally and will come up with some better process for moving from “[trydiscourse.com](http://trydiscourse.com)” domain to real domain that accounts for this issue.

---

<div class="post-metadata">

### Author: ![balboah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/balboah/32/184387_2.png) [@balboah](https://meta.discourse.org/u/balboah)
#### Post date: [June 23, 2020, 7:42am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/12 "2020-06-23T07:42:55Z")

</div>

Yeah I might have not paid attention. But I did add 2 keys as a backup and assumed other admins could recover my account.  
This was the physical key flow, not authenticator code

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [June 3, 2021, 12:35pm UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/13 "2021-06-03T12:35:53Z")

</div>

> [@sam](#):
>
> will come up with some better process for moving from “[trydiscourse.com](http://trydiscourse.com)” domain to real domain that accounts for this issue.

Did you already find a solution for this?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [June 4, 2021, 2:37am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/14 "2021-06-04T02:37:21Z")

</div>

I am pretty sure our internal processes account for this today, we reset various settings and so on.

---

<div class="post-metadata">

### Author: ![core](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/core/32/183957_2.png) [@core](https://meta.discourse.org/u/core)
#### Post date: [June 4, 2021, 9:27am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/17 "2021-06-04T09:27:39Z")

</div>

Hi. I’m facing this same conundrum for a self-hosted forum that’s changing domains.

> [@sam](#):
>
> we reset various settings and so on.

Anything in particular that I should consider?

---

<div class="post-metadata">

### Author: ![osioke](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/osioke/32/238946_2.png) [@osioke](https://meta.discourse.org/u/osioke)
#### Post date: [June 4, 2021, 9:30am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/18 "2021-06-04T09:30:44Z")

</div>

See Jay’s reply in this topic: [2fa security key breaks when migrating to custom domain - #7 by pfaffman](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/7)

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [June 4, 2021, 11:52am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/19 "2021-06-04T11:52:41Z")

</div>

It would be nice if there was a better process, though. Using backup keys for a large amount of users will boil down to a large support burden.

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 4, 2021, 3:43pm UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/21 "2021-06-04T15:43:00Z")

</div>

So there’s a way to change the 2fa records to match the new domain? Ooh, that sounds like one more way to make a restore more complicated! 😉

But if that’s the case, it would be nice to be able to do that on staging sites that restore a production database periodically. I can try to have a look at that in a week or two, either in a plugin or a PR.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [August 25, 2025, 4:26am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/23 "2025-08-25T04:26:04Z")

</div>

I will close this old bug topic. If there is anything remaining to do we can reopen it or start a new one.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [August 25, 2025, 4:26am UTC](https://meta.discourse.org/t/2fa-security-key-breaks-when-migrating-to-custom-domain/155528/24 "2025-08-25T04:26:07Z")

</div>


