Search the docs⌘K
Glossario
Intermediate
ENIT

Passkeys

UPDATED 2026-07-25

A passkey is a sign-in credential that lives on one device — a phone, a laptop, or a hardware security key — and is unlocked by that device's own screen lock, so you prove who you are with a fingerprint, a face scan, or a device PIN instead of typing a secret. Fincanva does not support passkeys yet. This page explains the concept so it is already clear when the feature arrives; it describes no Fincanva flow, because none exists.

Also seen as: passkey, WebAuthn credential, FIDO2 credential

Can I use a passkey with Fincanva today?

No. In your security settings the Passkeys row exists but is inert: its value reads "None" and its button is disabled and labelled "Coming soon". There is nothing to enrol, nothing to name, and nothing to remove.

Until it ships, the ways into a Fincanva account are the three described under passwordless sign-in — an emailed link, an emailed 6-digit code, or a password — plus Continue with Google, each of which can be protected with two-factor authentication.

What is a passkey?

A passkey is a pair of cryptographic keys created for one website and stored on one device. The device keeps the private half and never releases it; the website keeps only the public half, which is useless to anyone who steals it. Signing in means the site sends a challenge, your device unlocks the private key with your fingerprint, face, or PIN, and returns a signature the site can verify.

Two consequences follow from that shape, and they are the whole point of the design:

  • Nothing reusable is transmitted. A signature answers one challenge and cannot be replayed elsewhere, so there is no shared secret in flight to intercept.
  • The credential is bound to the site that issued it. A passkey created for one site will not sign a challenge from a lookalike domain, which is why passkeys resist phishing in a way a typed secret cannot.

Passkeys are the consumer-facing name for credentials built on the WebAuthn and FIDO2 standards, which is why the same passkey works across browsers and platforms that implement them.

How is a passkey different from a password?

In one line: a password is something you know and can therefore be tricked into typing somewhere else, while a passkey is something your device holds and will only ever present to the one site it was made for.

PasswordPasskey
Where it livesin your head or a manageron a device, in its secure store
What travels to the sitethe secret itselfa one-off signature
Phishableyes — you can type it into a fake pageno — it will not sign for the wrong domain
Reusable across sitesyes, and that is the riskno, one per site by construction
Breach exposurethe site holds something worth stealingthe site holds only a public key
How you unlock itby recalling itwith the device's fingerprint, face, or PIN

The practical trade is convenience against portability: a passkey removes the recall step entirely, but it is tied to the device or the platform keychain that holds it, so losing every synced device is a different kind of problem than forgetting a password.

What the Fincanva setting shows today

The security settings page lists Passkeys alongside Password and Two-factor authentication so the eventual home for the feature is visible. The row's state is "None", and its only control is the disabled Coming soon button. No passkey can be created, and none affects how you sign in today.

Where this term is used

Generated · 1 pages

The pages that reference this term — so a term page is somewhere you pass through, not somewhere you land and stop.

Fincanva provides no financial advice. Backtests show what would have happened — not what will.

GLOSSARY · 193 TERMS