Your email link keeps working. Always.
A passkey is something you can add, never something you must have. Signing in by email stays exactly as it is, for everyone, permanently — it is how you get back in if you lose your phone, and it is there if you would simply rather not bother with any of this. Nothing about your account is worse if you ignore passkeys entirely.
Where this has got to
We are building it at the moment, and this page is here first — so that you can read it before anyone asks you to decide anything. There is nothing for you to do today.
What you would need
Almost certainly nothing you do not already have. This is built into the phones and computers people already use, and it is the same thing that unlocks them.
| If you use | Where the passkey lives | What unlocks it |
|---|---|---|
| An iPhone, iPad or Mac | Already built in | Your face, or your fingerprint |
| An Android phone or tablet | Already built in | Your fingerprint, your face, or your PIN |
| A Windows computer | Already built in | Your fingerprint, your face, or your PIN |
| A password manager you already use | It can hold passkeys too | However you already unlock it |
On a computer running Linux, this is usually not built into the machine itself. You can still use a passkey, and the simplest way needs nothing new: sign in with your phone, exactly as the next section describes. Your phone holds the passkey, and nothing is installed on the computer at all.
If you would rather keep a passkey on the computer itself, a password manager can hold one. KeePassXC is free and open source, and keeps everything in a file on your own machine — no account, and nothing that has to be reachable, which matters if the services involved are unreliable where you are. Bitwarden is free as well and easier to set up, if you would rather it synced between your devices. Ask us if you would like a hand with either.
Signing in on a computer that does not have your passkey
You do not need to set this up on every machine you touch. When you sign in on a computer that does not know you, it shows a square barcode. You point your phone’s camera at it, approve with your face or your fingerprint, and the computer signs in.
Your passkey is not copied onto that computer, and nothing of yours is left behind on it. Your phone answers the question; the computer only receives the answer.
For this to work, Bluetooth needs to be switched on — on the phone and on the computer. They use it to check that your phone is really in the room, which is what stops someone far away from pretending to be you. If the barcode does not seem to work, Bluetooth being switched off is almost always the reason.
Nearly every laptop has Bluetooth. Some desktop computers do not. If yours has not got it the barcode will not work — but you are not stuck, and there is a section further down this page that says what to do instead.
The simplest way to think about it
Add a passkey on each device you use regularly. That is the whole of it, and it saves you having to think about anything else.
Phones and computers often do copy passkeys between your own devices on their own. But that depends on services that are not reachable from everywhere, and on some versions of Windows it does not happen at all. Adding one per device sidesteps every bit of that: a passkey works on the device it was made on, whether or not anything else is working.
If your computer cannot do any of this
You are not stuck, and you will not be. Signing in by email works on any computer with a web browser — no Bluetooth, no camera, nothing built in and nothing installed. That is a large part of why it is staying.
If you would like a passkey on that computer anyway, two things work with no Bluetooth at all. A passkey kept on the computer itself — by Windows, or by a password manager — never needs it. And a security key, a small device that plugs into a USB socket, holds passkeys and needs no radio, no account and no internet service of its own; it behaves the same on every computer, which is what makes it suit a machine with nothing built in.
There is no minimum specification for using daftar, and there will not be one. Bluetooth is needed for a single convenience — the barcode — and for nothing else.
Where not to add one
A shared or borrowed computer is the wrong place to add a passkey. A library machine, a friend’s laptop, a computer in a shared office — not those.
A passkey added on a computer stays on that computer, and whoever uses it next may be able to sign in as you. On a machine that is not yours, use the email link, or sign in with your phone using the barcode. Both leave nothing behind.
What we can see, and what we cannot
Your fingerprint and your face never leave your device, and they never reach us. We never see them, we are never sent them, and we could not ask for them. Your device checks that it is you, and then tells us only that it is satisfied.
What we keep is a small piece of information that can check your device’s answer is genuine, but cannot be used to sign in as you. If our records were ever stolen, there would be nothing in them anyone could use to get into your account.
What it protects you from
A passkey will not work on a fake site. If someone builds a convincing copy of this one and asks you to sign in, your device simply refuses — not because it is being careful, but because a passkey is tied to the real address and cannot be offered anywhere else. No mistake on your part can undo that.
An email link cannot protect you in the same way: a convincing copy can ask you to paste your link into it, and the link would work. That is worth knowing, because the email link is staying — so it remains worth protecting the email account it arrives in.
If any of this is unclear
Ask us. There is no bad question here, and it is better asked than guessed — get in touch and we will answer.
