A passkey is a modern, passwordless way to prove it's really you — using your device's built‑in security (Touch ID, Windows Hello, your phone's screen lock) or a hardware security key, instead of typing a code or a password.
Technically, a passkey is built on the WebAuthn standard: a cryptographic key pair is created for your account, the private key never leaves your device (or your password manager's secure storage), and only a signed "proof" is sent to our servers. There is nothing to type, nothing to intercept, and nothing that can be phished — because the passkey is cryptographically bound to our exact domain.
Why use a Passkey?
Faster login — one tap / one glance instead of typing a 6‑digit code.
More secure — resistant to phishing, password leaks.
No need to remember or copy codes — no authenticator app, no manual code entry.
Works across two independent places in your account:
As your login second factor — replaces the OTP (authenticator app) code when you sign in.
As a confirmation method for sensitive actions — payments, invites, API keys, and other operations that currently require a code.
Note: you can enable a passkey for login, for confirming operations, for both, or for neither (in which case it is simply registered but not actively used anywhere). Registering a passkey does not automatically turn it on for anything — you choose where it's used.
Which "methods" can I use to create a Passkey?
A passkey isn't tied to one specific app — it works with anything that supports the WebAuthn standard on your device or browser. The most common options:
Method | How it works | Best for |
Built‑in device biometrics (Touch ID, Face ID, Windows Hello, Android fingerprint) | Your browser (Safari, Chrome, Edge) offers to save the passkey directly to your device's secure chip / your Apple/Google/Microsoft account keychain. | Quickest setup, no extra software. Recommended for most users. |
Password manager (e.g. 1Password, Bitwarden, iCloud Keychain, Google Password Manager) | The password manager intercepts the browser's passkey prompt and stores the key itself. | Users who already use a password manager and want the passkey to sync across their devices/browsers automatically. |
Hardware security key (e.g. YubiKey) | A physical USB/NFC key stores the passkey; you tap/insert it to confirm. | Users who want a portable key independent of any single device or OS account. |
Another device via QR code ("hybrid"/cross-device) | Your computer shows a QR code; you scan it with your phone's camera, and the phone (with Bluetooth on) completes the login/confirmation. | Logging in on a computer that doesn't have its own biometric sensor, using your phone as the key. |
Here's what you might see when you try to set up a passkey — the exact dialog depends on your browser and OS, but it typically looks something like this:
You only need one passkey per account (the system currently allows a single registered passkey per user) — pick whichever method fits how you work.
How to set up a Passkey — step by step
Log in to your account and open Settings → General → Passkey
Click Add passkey.
Your browser will show a system prompt — follow it. Depending on your device and setup, you may be offered:
Biometrics or a device PIN — Touch ID, Face ID, fingerprint, Windows Hello, or your screen-lock PIN.
A password manager — save the passkey there instead (e.g. 1Password, iCloud Keychain, Google Password Manager).
Another device — choose "Use another device" and scan the QR code with your phone.
Give your passkey a recognizable name
Done — the passkey now appears in your list with its creation date and sync status.
Now decide where to use it — go to the toggles for "Use as login method" and/or "Use as confirmation method" and switch on what you need.
Logging in with a Passkey
Enter your email and password as usual.
Instead of an OTP code field, you'll see a "Confirm with passkey" screen.
Click it — your browser/OS will ask you to confirm with Touch ID / Windows Hello / your key.
Once confirmed, you're logged in — no code to type.
Confirming an action with a Passkey
Wherever your account previously asked for an email/Telegram/authenticator-app code (for example, sending a payment, inviting a teammate, creating an API key), if you've enabled passkey as a confirmation method, you'll instead see a "Confirm with passkey" prompt for that specific action.
If you have more than one confirmation method turned on at the same time (e.g. Telegram code and passkey), the system will ask for all of them together for extra-sensitive actions, not just one.
Managing your Passkey
Rename a passkey any time from the list — the new name is saved instantly.
Delete a passkey — you'll be asked to confirm the deletion using the passkey itself (Touch ID/Windows Hello again), not your password.
You cannot delete your only passkey while it is still set as your login method or confirmation method — first turn that off in the toggles, then delete the key.
Passkey and the Telegram Mini App
The Telegram mini app is a lightweight, in-app (WebView) version of your account, and passkeys currently work a bit differently there:
You can't register, rename, delete a passkey, or switch your login method to passkey from inside the mini app. The "Passkeys" section and the login-method choice are hidden there on purpose — do this from the full web version instead. The mini app shows a reminder about this right on the 2FA card.
If passkey is enabled together with another confirmation method (email, Telegram, or authenticator app), the mini app does not show that notice at all — passkey is silently skipped, and you're simply asked to confirm with whichever other method(s) you have enabled, with no mention that passkey was excluded.
Recommendation: if you rely on the mini app day to day, keep at least one other confirmation method turned on alongside passkey (email, Telegram, or authenticator app) — otherwise you won't be able to confirm anything inside Telegram without switching to a browser. The web settings show this exact reminder as soon as passkey is enabled as a confirmation method: "Passkeys don't work in the Telegram mini app yet, so keep at least one code method (email, Telegram or authenticator app) enabled alongside. Mini-app support is coming soon."







