A passkey is a sign-in credential that lives on one device — a phone, a laptop, or a hardware security key — and is unlocked by that device's own screen lock, so you prove who you are with a fingerprint, a face scan, or a device PIN instead of typing a secret. Fincanva does not support passkeys yet. This page explains the concept so it is already clear when the feature arrives; it describes no Fincanva flow, because none exists.
Also seen as: passkey, WebAuthn credential, FIDO2 credential
Can I use a passkey with Fincanva today?
No. In your security settings the Passkeys row exists but is inert: its value reads "None" and its button is disabled and labelled "Coming soon". There is nothing to enrol, nothing to name, and nothing to remove.
Until it ships, the ways into a Fincanva account are the three described under passwordless sign-in — an emailed link, an emailed 6-digit code, or a password — plus Continue with Google, each of which can be protected with two-factor authentication.
What is a passkey?
A passkey is a pair of cryptographic keys created for one website and stored on one device. The device keeps the private half and never releases it; the website keeps only the public half, which is useless to anyone who steals it. Signing in means the site sends a challenge, your device unlocks the private key with your fingerprint, face, or PIN, and returns a signature the site can verify.
Two consequences follow from that shape, and they are the whole point of the design:
- Nothing reusable is transmitted. A signature answers one challenge and cannot be replayed elsewhere, so there is no shared secret in flight to intercept.
- The credential is bound to the site that issued it. A passkey created for one site will not sign a challenge from a lookalike domain, which is why passkeys resist phishing in a way a typed secret cannot.
Passkeys are the consumer-facing name for credentials built on the WebAuthn and FIDO2 standards, which is why the same passkey works across browsers and platforms that implement them.
How is a passkey different from a password?
In one line: a password is something you know and can therefore be tricked into typing somewhere else, while a passkey is something your device holds and will only ever present to the one site it was made for.
| Password | Passkey | |
|---|---|---|
| Where it lives | in your head or a manager | on a device, in its secure store |
| What travels to the site | the secret itself | a one-off signature |
| Phishable | yes — you can type it into a fake page | no — it will not sign for the wrong domain |
| Reusable across sites | yes, and that is the risk | no, one per site by construction |
| Breach exposure | the site holds something worth stealing | the site holds only a public key |
| How you unlock it | by recalling it | with the device's fingerprint, face, or PIN |
The practical trade is convenience against portability: a passkey removes the recall step entirely, but it is tied to the device or the platform keychain that holds it, so losing every synced device is a different kind of problem than forgetting a password.
What the Fincanva setting shows today
The security settings page lists Passkeys alongside Password and Two-factor authentication so the eventual home for the feature is visible. The row's state is "None", and its only control is the disabled Coming soon button. No passkey can be created, and none affects how you sign in today.
Where this term is used
Generated · 1 pagesThe pages that reference this term — so a term page is somewhere you pass through, not somewhere you land and stop.
Fincanva provides no financial advice. Backtests show what would have happened — not what will.
GLOSSARY · 193 TERMS