Skip to main content

Passkeys

Passkeys

Last verified: 2026-07-08

Passkeys let an account sign in with a WebAuthn credential stored by a device, browser profile, operating system account, hardware security key, or password manager. The device still decides how the user unlocks the passkey, such as fingerprint, face unlock, PIN, password manager unlock, or a hardware-key touch.

Setup

Open Account Security and use the Passkeys panel. The browser will show its own passkey prompt. Follow that prompt, name the passkey in a way you will recognize later, then confirm that it appears in the passkey list.

Register passkeys only from browsers and devices you trust. If the browser prompt says the passkey will be saved to a synced password manager or platform account, treat that account as part of your login security.

Supported browsers and authenticators

Passkeys depend on WebAuthn support from the browser and authenticator. Modern Chrome, Edge, Safari, and Firefox versions generally support passkeys, but the exact experience differs by operating system, password manager, security key, and device policy.

If registration fails, try another current browser, confirm the site is served over HTTPS, and check whether the device or organization blocks passkey creation.

Login challenge behavior

During a protected sign-in, Awthy can offer Use a passkey on the login challenge screen. A successful passkey assertion can complete the second-factor step for that account. If the passkey prompt is unavailable or fails, use an authenticator code, backup code, or recovery path instead.

Passkey challenges are short-lived operational state. Awthy does not store raw passkey challenge material as account data.

Passkeys for administrators and staff are part of the core login-security workflow. Customer passkeys and broader paid limits depend on the site's active Awthy plan. If a panel shows an upgrade prompt, the current plan does not allow that passkey action for that audience.

Do not enable customer passkeys until recovery, support ownership, and customer-facing rollout copy are ready.

Removing a passkey

Use the Passkeys panel to remove a passkey you no longer use or no longer trust. Removal affects only the selected credential. It does not remove other passkeys, recovery codes, trusted devices, or the WordPress password.

Remove old passkeys after replacing devices, losing a hardware key, changing password managers, or offboarding staff. Keep another recovery path available before removing the last usable second factor.

Security boundaries

  • Awthy stores passkey credential records, not passkey private keys.
  • Never send support a passkey prompt screenshot that includes account, device, or browser secrets.
  • Do not treat a synced passkey account as outside your threat model.
  • If a device is stolen, revoke the passkey and any trusted-device record for that browser.