X is retiring the twitter.com domain for authentication, requiring users to re-register YubiKeys and passkeys to maintain access.
Deadline Alert: Re-Enroll by November 10
Users of hardware-based two-factor authentication (2FA) on X (formerly Twitter) must take immediate action: re-enroll your security key by November 10 or risk being locked out of your account.
- This update only affects physical security keys like YubiKeys or passkeys.
- The move is due to X retiring the twitter.com domain for authentication purposes.
Why This Change Is Happening
According to X, this isn’t about a security breach or vulnerability—it’s about domain migration.
- Keys were originally cryptographically tied to twitter.com.
- Now, they must be re-registered under x.com to remain functional.
“Security keys enrolled as a 2FA method are currently tied to the twitter[.]com domain. Re-enrolling your security key will associate it with x[.]com,” X’s Safety account clarified.
No Impact on Authenticator Apps
If you’re using Google Authenticator, Microsoft Authenticator, or Authy, you’re unaffected by this change.
- These app-based 2FA methods don’t rely on domain-specific registration like hardware keys do.
- You can continue using your current authenticator setup without modification.
The Technical Reason Behind It
Christopher Stanley, a security engineer at X, xAI, and SpaceX, explained the deeper technical reason:
“Getting off of Twitter enrolled keys so we can stop doing hacky things for domain trust,” he said.
“Physical security keys are cryptographically registered to Twitter’s domain and need to be re-enrolled under X.”
This ensures clean domain trust and reduces reliance on legacy systems.
How to Re-Enroll Your Security Key
To update your hardware key association with x.com, follow these steps:
- Go to Settings in the X app or website.
- Navigate to Security and account access.
- Select Two-factor authentication.
- Choose Manage security keys and follow the prompts to re-enroll.
You can either re-enroll your existing key or register a new one.
What’s Next for twitter.com?
It remains unclear whether X plans to fully retire twitter.com beyond security infrastructure. The company has yet to clarify the scope of the change.
- If the transition expands beyond 2FA, additional user action may be required in the future.
- Stay updated through X’s official safety channels for any future developments.
X users who rely on YubiKeys or passkeys must re-enroll them before November 10 to stay logged in. The change supports the shift from twitter.com to x.com and does not affect authenticator apps. This move ensures clean domain trust for hardware-based 2FA.








