Product / Passkeys

Passkeys that never leave your vault

Create WebAuthn credentials inside your own vault, bound to the authenticator your device already has. Nothing is registered with a third party.

What it does

Passwordless sign-in, stored locally

A passkey is created through the WebAuthn API of your platform, so the private half of the credential never enters the vault in a usable form and never leaves your device. The vault stores the credential id and its metadata so you can recognise and revoke it later.

The page reports which authenticator is available before you create anything, and lets you choose the relying party, display name, account and signature algorithm.

Passkeys sit alongside the rest of the vault rather than in a separate system, so they are encrypted, searchable and restorable in exactly the same way as a password.

How a passkey is created

Your device creates the key pair

The private key is generated inside the platform authenticator — TPM 2.0, Secure Enclave or AndroidKeyStore — and is not exportable.

The vault records the credential

Only the credential id and display metadata are saved, encrypted with the rest of the vault.

Signing happens in hardware

Because the private key is non-exportable, a signature for a site cannot be produced by anything other than the authenticator itself.

Hardware unlock sits next to it

The same settings panel holds the FIDO2 and biometric unlock options, so passkeys and hardware-bound unlocking live together rather than in separate products.

Security Architecture

What passkeys do and do not remove

Passkeys are not a backup plan

A passkey replaces the password at a site; it does not replace your vault. If you lose the device holding your authenticator and have no passkey stored elsewhere, that credential is gone with it. Passkeys also only help at sites that support WebAuthn, which is most large services and a growing share of smaller ones.

WebAuthn

Standard, not a private format

Credentials are created through the WebAuthn API, so they are the same kind of object any compliant site expects.

Dışa aktarılamaz

The private key stays put

Hardware-backed authenticators generate the key pair and never release the private half, so copying your vault does not copy the credential.

AES-256-GCM

Stored like everything else

Credential records are encrypted by the same per-item key scheme as the rest of your vault.

Frequently Asked Questions

About passkeys

Do I still need my master password?

Yes. The vault itself is unlocked by your master password and secret key. A passkey only replaces the password at the specific sites where you register one.

Which authenticators work?

Any platform authenticator your device exposes: Windows Hello, Touch ID, Face ID, Android biometrics, or a FIDO2 security key such as YubiKey.

What if I lose the device?

That specific passkey is lost with its authenticator. Your vault, its passwords and its backups are unaffected, because those never depended on that device.

Related pages

Download Installer