Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
A discoverable WebAuthn credential that lets you sign in to a site with a fingerprint, face or screen lock instead of a password.
A passkey is a key pair made for one site. The site keeps the public key; the private key stays with the passkey provider. To sign in, the provider signs a fresh challenge after you verify yourself, and the site checks the signature. Passkeys can be synced through a cloud account or bound to one device. HostSpica Passkey is device-bound: its private keys live in Android Keystore and cannot be exported, so losing the phone loses them.
A short code, usually 6 digits, that an authenticator app computes from a shared secret and the current time and that changes every 30 seconds.
A W3C standard that lets websites sign users in with public-key credentials held by an authenticator instead of with passwords.
The website or service that a user is signing in to and that verifies WebAuthn signatures.
Evidence provided at registration about the authenticator that created a key, such as a certificate chain showing the key lives in secure hardware.
Our expert team can help you leverage Passkey in your project.
Get Free Consultation