How HostSpica Identity links a 2FA code, a passkey and a password to one service
SHORT ANSWER
How does HostSpica Identity know a 2FA account, a passkey and a password belong to the same service?
It reduces each name to a comparable key: a 2FA issuer like GitHub, a passkey site like github.com, a saved address like https://github.com/login and an Android package like com.github.android all become github. Items with the same key are shown together. It is a heuristic with known limits, so you can also merge or split by hand.
Key takeaways
- The grouping is for display and convenience. It never changes or shares your data.
- The key ignores the ending (.com), so it is deliberately loose. Autofill uses a stricter rule that keeps the ending.
- It is not a full public-suffix lookup, so some services will not link on their own. A manual merge covers those.
- Merges can be undone.
The problem
A single service shows up under different names. The 2FA app calls it GitHub, the passkey stores github.com, the Vault entry was saved from https://github.com/login, and an Android app is com.github.android. To show them as one identity, the app needs one comparable key for all four.
The rule
- Lowercase the name, drop
android://, any scheme, the path, query, credentials and port, and a leadingwww.. - If what is left has no dots or contains spaces, it is a plain name such as GitHub or Bank of America: keep only letters and digits.
- If it looks like a package name that starts with a reverse-domain root (
com.github.android), take the second label. - If it ends in a known two-level suffix (
co.uk,com.au,co.inand a few dozen others), take the label before the suffix. - Otherwise take the second-to-last label:
gist.github.combecomesgithub.
| Input | Key |
|---|---|
| GitHub | github |
| github.com | github |
| https://www.github.com/login | github |
| gist.github.com | github |
| com.github.android | github |
| accounts.bbc.co.uk | bbc |
| Bank of America | bankofamerica |
Where it is loose on purpose
The key drops the ending, so github.com and github.xyz have the same key. That is fine for grouping accounts on a screen, where a wrong grouping is a minor annoyance you can fix. It would be wrong for Autofill, where it could offer a password to a lookalike site. See how Autofill protects each fill: web pages there need the exact registered domain, including its ending, and a title-only entry is never offered on a web page.
What it cannot do
Tests
The rule has unit tests for the cases above, including that different services stay apart and that a blank name gives an empty key.
Frequently asked questions
Does linking move my data between features?
No. Each feature keeps its own storage. The Identity tab only groups what is already there.
Can I split a wrong group?
You can merge into another group by hand and undo a merge. The grouping itself is recomputed from the names.
Why not match on the full domain?
Because the 2FA issuer is often just a brand name with no domain, so a full-domain rule would not group those.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED