-via 'TOTP' later on, even if the realm does not enforce it. As another
-option, if the server has an 'AppId' configured, a user can opt-in to
-'U2F' authentication, provided the realm does not enforce any other
-second factor.
+later on, even if the realm does not enforce it.
+
+Available Second Factors
+~~~~~~~~~~~~~~~~~~~~~~~~
+
+You can set up multiple second factors, in order to avoid a situation in
+which losing your smartphone or security key locks you out of your
+account permanently.
+
+The following two-factor authentication methods are available in
+addition to realm-enforced TOTP and YubiKey OTP:
+
+* User configured TOTP
+ (https://en.wikipedia.org/wiki/Time-based_One-Time_Password[Time-based One-Time Password]).
+ A short code derived from a shared secret and the current time, it changes
+ every 30 seconds.
+* WebAuthn (https://en.wikipedia.org/wiki/WebAuthn[Web Authentication]).
+ A general standard for authentication. It is implemented by various
+ security devices, like hardware keys or trusted platform modules (TPM)
+ from a computer or smart phone.
+* Single use Recovery Keys. A list of keys which should either be
+ printed out and locked in a secure place or saved digitally in an
+ electronic vault. Each key can be used only once. These are perfect for
+ ensuring that you are not locked out, even if all of your other second
+ factors are lost or corrupt.
+
+Before WebAuthn was supported, U2F could be setup by the user. Existing
+U2F factors can still be used, but it is recommended to switch to
+WebAuthn, once it is configured on the server.