How to set up a passkey on Android with HostSpica Identity, step by step
SHORT ANSWER
How do I use HostSpica Identity to store passkeys on Android?
On Android 14 or newer, open the Passkey tab and tap Enable provider, which opens Android's passkey settings. Turn on HostSpica Identity there. Then, on a site that supports passkeys, choose to create a passkey and pick HostSpica Identity when Android asks where to save it.
Key takeaways
- You need Android 14 or newer. The Passkey tab is hidden on older versions.
- The Enable provider button opens the right Android screen. Menu names differ by phone brand.
- A passkey made here is device-bound: it is not backed up. Keep another way to sign in.
- Remove a passkey in both places: in HostSpica and in the site's security settings.
What you need
- An Android phone on version 14 or newer, with a screen lock and a fingerprint or face set up.
- HostSpica Identity installed and unlocked.
- A site or app that supports passkeys, such as webauthn.io for a safe test.
Step 1: turn on HostSpica as a passkey provider
- Open HostSpica Identity and go to the Passkey tab.
- Tap Enable provider. Android opens its passkey and autofill settings for apps.
- Turn on HostSpica Identity. The wording and the place differ by brand: look for Passwords, passkeys and autofill, or Preferred service, in Settings.
- Return to HostSpica. The Enable provider button disappears once Android confirms it is on.
You can have more than one passkey provider enabled. Android asks which one to use each time you create or use a passkey.
Step 2: create a passkey
- On a site that supports passkeys, start the sign-up or the passkey option, for example Register on webauthn.io.
- When Android asks where to save the passkey, choose HostSpica Identity.
- Confirm with your fingerprint or face. The site says the passkey was created.
If the site says you already registered, that is the safeguard doing its job: HostSpica refuses to create a duplicate passkey for an account that already has one.
Step 3: sign in with it
- On the site choose to sign in with a passkey.
- Pick HostSpica Identity and confirm with your fingerprint or face.
Signing in on a computer
When a computer shows a QR code to use your phone, scan it with your phone's camera app, not with an app's scanner. Android handles this flow itself and offers your passkey providers, including HostSpica Identity. That flow is run by the system, not by HostSpica, and Android may use the internet and Bluetooth for it.
Removing a passkey
- Open the Passkey tab, tap the passkey and delete it. Its key is removed from the phone.
- Also remove it in the site's security settings, so the site stops offering it.
Frequently asked questions
Why do I not see Enable provider?
It is hidden once Android says HostSpica is already on, and the whole Passkey tab is hidden on Android versions before 14.
Can I move a passkey to a new phone?
No. Device-bound passkeys cannot be copied. Create a new one on the new phone.
Does HostSpica see my fingerprint?
No. The check is done by Android, which only tells the app that it succeeded.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED