What is a passkey?
A passkey is a cryptographic credential stored securely on your device (iPhone, iPad, Mac, Android, or Windows PC). Instead of a password, the system uses your device's built-in biometric sensor — Face ID, Touch ID, or Windows Hello — to verify your identity.
- Nothing is sent to the server except a cryptographic signature — your face scan or fingerprint never leaves your device.
- Passkeys are phishing-resistant: they are bound to
openstudio.oneand cannot be used on fake sites. - Each device you register is independent. You can have one passkey per device.
Adding a passkey
- Open Sidebar → Cloud services → Social connect on the device you want to register.
- Find the Passkeys card and click Add this device.
- Your device will immediately prompt you for biometric confirmation (Face ID / Touch ID / Windows Hello PIN). Do not switch apps or lock your screen during this step.
- Once confirmed, the card refreshes and shows your new device in the list with the date it was added.
Tip: The device is automatically named based on your browser (e.g., "iPhone", "Mac", "Windows device"). The name is for your reference only and does not affect how the passkey works.
Signing in with a passkey
- On the login page, click Sign in with a Passkey.
- Your device presents a biometric prompt. Confirm with Face ID, Touch ID, or your PIN.
- You are logged in instantly — no email, no password.
Removing a passkey
- On the Connected Accounts page, find the passkey row you want to remove in the Passkeys card.
- Click the (trash) icon on that row.
- Confirm the removal. The passkey is immediately invalidated — it can no longer be used to sign in.
Lost device? If a device is lost or stolen, remove its passkey here immediately. The thief cannot use the passkey without passing your biometric check, but removing it prevents any future risk if the device is ever unlocked.
One passkey per device
The system enforces one passkey per physical device. If you try to add a second passkey from a device that already has one registered, you will see an error asking you to remove the existing one first. This prevents confusion when signing in — the login prompt will always know exactly which account to load.