Connector · Passwordless sign-in standard

Passkeys, in place of every password.

How our authentication module uses passkeys to sign customers in without passwords: how they work, what your customers see, and how we roll them out.

Website
fidoalliance.org
Modules
Authentication
Standard
FIDO Alliance and W3C

What passkeys are

A passkey is a sign-in credential based on the FIDO standards: a key pair made for one account on one service. The service keeps only the public key. The private key stays with the person, on their phone, computer, password manager or security key, and they approve each use the way they open their device: with a fingerprint, their face or a PIN.

Passkeys rest on WebAuthn, the browser standard published by the W3C, and CTAP, the FIDO Alliance's protocol for authenticators. They are supported in all major operating systems and browsers, and a passkey is only presented to the site or app it was made for, which makes it resistant to phishing. That is why passkeys are at the centre of sign-in in our authentication module.

What it does in your platform

  • Authentication

    Lets customers sign in with a passkey instead of a password, and use it again as the second factor when they confirm a payment. Passkeys can replace passwords entirely, with one-time codes as a fallback on devices that do not support them.

How the connection works

Passkeys need no outside service. The module is the relying party, the service the passkeys belong to; browsers speak WebAuthn, and phones use the passkey support built into iOS and Android.

  1. The customer makes one

    After sign-up, the app offers a passkey. The phone creates a key pair for your service only and asks for Face ID, a fingerprint or the PIN.

  2. The public key is saved

    The phone sends the public key to the module, which stores it against the customer. The private key stays on the phone, or in the password manager that syncs it between the customer's devices.

  3. Signing in

    Next time, the module sends a fresh challenge. The customer approves on the phone, which signs it with the private key, and the module checks the signature against the stored public key.

  4. Confirming a payment

    A transfer or a card payment asks for the passkey again before it goes ahead, as the second factor strong customer authentication requires.

  5. A new phone

    Synced passkeys follow the customer to a new phone through their password manager. Device-bound ones stay behind, and the module's recovery flow lets the customer back in without calling support.

Next to other factors

Passkeys sit next to the module's other second factors: authenticator apps, one-time codes through Twilio Verify and push approval in your own app. Customers whose devices cannot use a passkey fall back to one-time codes, so nobody is locked out.

Passkeys also work under the identity providers we connect to: Keycloak and AWS Cognito, for example, support them as a sign-in method. Where the provider holds the passkeys, the module still keeps the sessions and the payment confirmation.

When passkeys fit best

A strong fit when

  • You want customers to stop using passwords, and stop losing accounts to phishing.
  • Your customers use current phones and browsers, where passkey support is built in.
  • You want one gesture for signing in and for confirming payments.

Also worth a look

  • One-time codes by app, SMS or email, for devices without passkey support.
  • Push approval in your own app, for customers who prefer to approve a request on their phone.

How we get you live

  • Your domains

    We set your domains up as the passkeys' relying party and link your apps to them, so the same passkey works in your app and on your website.

  • The rules

    We decide with you when a passkey is offered, when it is required, and which fallback applies on devices without one.

  • The keys

    The platform stores only public keys, so its database holds nothing a thief could sign in with. There is no provider secret to manage.

  • A full test run

    We test making, using and recovering passkeys on iPhone, Android and the main browsers before your customers see them.

Questions

Asked about this connector.

How do we start offering passkeys?

Talk to us. We help you set up passkeys in the authentication module, link them to your apps and website, decide the fallback rules and test them on every platform before launch.

What if a customer loses their phone?

Passkeys synced through Apple, Google or a password manager come back on the new phone. Otherwise the module's recovery flow lets the customer back in without calling support, and they make a new passkey.

Do passkeys work on our website too?

Yes. Browsers support them through WebAuthn, the W3C standard, so customers can use passkeys on your website as well as in the app.

Are passkeys safe against phishing?

Yes. A passkey is only presented to the site or app it was made for, so a fake site cannot use it, and there is no password for anyone to type into one.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?