Password-free sign-in with Face ID, your fingerprint or your device lock. Adding a key, what the list tells you, removing keys and the errors you may meet.
Typing a password and reading a code off your phone at every sign-in gets tiring. A reduces both to a single gesture: you sign in with Face ID, your fingerprint or your device lock. The key is stored on your device and shared with nobody — not even the panel's server holds anything equivalent to your password. This guide covers how to add one, what the list tells you, and what the error messages mean.
passkey
💡 A passkey is an alternative to two-step verification, not a replacement. With either one enabled you can enter the panel's sensitive screens (Connection settings, moving an account, deleting an account, deleting a portfolio). Enabling both is the most comfortable.
What a passkey is
A passkey is an authentication method stored on your device. It isn't something you memorise or type: when you unlock your device it tells the panel on your behalf, "yes, this is that person."
That has two practical consequences:
It can't be stolen. The key's secret half never leaves your device; there is no password for a data breach to expose.
It can't be phished. A fake sign-in page cannot use your key, because the key only works on its own site.
Almost every modern phone, tablet and computer supports it. If you use a password manager, the key can live there too and sync across your devices.
Adding a key
Click your user card at the bottom left and pick Security.
Find the Passkeys section.
Click Add a passkey to this device.
The panel verifies your identity first. As the note says: "Verify your identity before adding a new passkey."
If you already have a passkey, you use it via the Verify with passkey button.
If you have two-step verification, you type the code.
On success the panel says "Verified. You can now add a passkey to this device." and adds: "Your identity is verified. Add it to this device within 5 minutes." The window is limited; dawdle and you have to verify again.
Press the button again. The screen says "Waiting for device confirmation…" and your device's own prompt opens.
Confirm with Face ID, your fingerprint or your device lock.
A "Passkey added." notice appears and the key drops into the list.
⚠️ If you just signed up and have no method at all, the panel may say "Sign out and sign back in to add a passkey." That is a security rule: your session has to be fresh to add a key. Sign out, sign in and try again.
What the list tells you
Each key you add becomes a row in the list, showing:
Name. The name your device or password manager gave it. If no name could be derived, it just reads "Passkey".
Date added. In the form "Added on …".
Sync information. One of two states:
Syncs across devices — the key lives in a cloud account or a password manager, so it works on your other devices signed into the same account.
This device only — the key lives only on the device you added it to. If that device leaves your hands, the key goes with it.
That distinction has a practical consequence: if you have a "this device only" key and it is your only method, losing the device locks you out of your account. Keep at least one backup method (two-step verification, or a key on a second device).
With no keys the section reads "You don't have a passkey yet."
Removing a key
Press Remove on the row. The panel asks for confirmation and states the consequence: "Remove the passkey …? You will sign in on this device without a key."
Situations that call for it:
You sold, gave away or lost a device.
You left a key on a browser or computer you no longer use.
There is a row in the list you don't recognise.
Removing doesn't close your account; you just sign in on that device without a key. Make sure you have another method.
Using it at sign-in
At your next sign-in you use the passkey option on the sign-in screen; no password needed. Unlock your device and the sign-in completes.
The same key works inside the panel. Entering Connection settings, moving an account, deleting an account or a portfolio all ask you to verify; with a passkey you pass with one tap. See The security verification screen.
⚠️ Adding a passkey does not close password sign-in. The Security screen reminds you in an info box: because the password route stays open, enabling two-step verification as well completes the protection.
Errors you may meet
The panel reports errors in plain sentences. What they mean:
"This device or browser doesn't support passkeys." You are on an old browser or operating system. Update your browser or try another device.
"No passkey registered on this device was found. Sign in with your password and add one in Security settings." You tried to sign in with a key but this device has none. Sign in with your password and add one here.
"You already have a passkey on this device." A second key isn't added to the same device; the existing row is enough.
"For security, sign out and sign back in, then try again." Your session isn't fresh enough to add a key. Sign out and in.
"The user account is temporarily locked. Contact support." A protection kicked in after too many failed attempts.
"Passkey sign-in is currently disabled." The feature is switched off platform-wide. That is not your setting.
"The operation could not be completed. Please try again." A generic error; the device prompt may have closed or timed out. Try again.
A concrete setup example
A business owner uses the panel from both the office computer and their phone. They set it up like this:
They add a passkey on the office computer. The list reads "This device only".
They sign in on their phone and add a key there too. Because the phone works with a password manager, the list reads "Syncs across devices".
They also turn on two-step verification and print their backup codes.
The result: one tap on either device; a code when neither is to hand; and the backup codes if both are lost at once.
Common mistakes
Relying on a single "this device only" key. If the device goes, so does your account. Keep a backup method.
Assuming the password is gone once you add a key. Password sign-in stays open.
Adding a key on a shared computer. It doesn't let everyone in with their own fingerprint, but anyone who knows the device lock can get in. Don't leave keys on shared devices.
Letting the five minutes lapse after verifying. If the window closes you have to verify again.
Leaving keys for devices you no longer use in the list. Review the list once a year and remove anything you don't recognise.
If it still doesn't work after all these steps
If the key won't add, isn't recognised at sign-in, and none of the error explanations above describes your situation, contact our support team.