Passkey scanner: how the QR code sign-in works
SHORT ANSWER
What is a passkey QR code scanner?
When a computer offers to sign you in with a phone, it shows a QR code. You scan it with your phone's camera or the system scanner, not a passkey app. Android then starts a cross-device sign-in, asks which passkey to use and for your unlock, and finishes over a nearby Bluetooth check.
Key takeaways
- The QR code starts a standard cross-device sign-in, called hybrid transport.
- The phone's camera or system scanner reads it. The passkey app is chosen afterwards.
- The phone and computer must be near each other, with Bluetooth on.
- HostSpica Identity has no scanner of its own for this. It removed its older Bluetooth pairing flow.
Disclosure: HostSpica makes HostSpica Identity, an Android app that is also a passkey provider. Facts about other services come from their own help pages, checked on 4 October 2026, and can change.
What happens when you scan
- On the computer you choose sign in with a phone or passkey from another device.
- The page shows a QR code that carries a one-time connection secret.
- You scan it with your phone camera or Google's scanner.
- The phone shows the passkeys it can offer. You pick one and unlock.
- The phone proves it holds the passkey over a nearby Bluetooth check, and the computer signs you in.
This is the cross-device part of the WebAuthn and FIDO standards. Android does it for apps registered with Credential Manager, so the provider does not run its own scanner.
Why HostSpica Identity has no scanner
We once built our own Bluetooth pairing flow with a QR scanner. Almost no site could use it, so we removed it and now rely on Android's built-in flow. The story is in why we dropped our custom Bluetooth passkey flow.
Passkeys created in HostSpica Identity appear as a choice when you scan a site's QR code with the system scanner. We have tested HostSpica Identity passkeys on Google, GitHub, Microsoft and webauthn.io in Chrome and Brave, including creating a passkey, signing in and the duplicate-passkey check. We have not tested every site, and no site is guaranteed to accept it. We have not completed our own full test of the computer-to-phone flow with every browser, so treat it as supported by Android, not guaranteed by us.
If scanning does nothing
- Turn on Bluetooth on both devices and keep them close.
- Use the camera app or the system scanner, not a random QR app.
- Check that the phone has internet, as the connection may need it.
- Confirm that HostSpica Identity is enabled as a provider in system settings.
- Try a different browser or update the current one.
HostSpica Identity needs Android 14 or newer for passkeys. Its Google Play release is in the final steps as of 4 October 2026, so check the app page for the live link.
Frequently asked questions
Which app should scan the passkey QR code?
Your phone's camera or system scanner. It hands the request to Android, which asks you to choose a passkey.
Does the passkey app need Bluetooth?
Android does the nearby Bluetooth check, not the passkey app. HostSpica Identity declares Bluetooth permissions for its AirAuth feature and no internet permission.
Why did scanning with the app's own scanner do nothing?
Our old in-app scanner used a custom protocol that sites do not support. We removed it.
Is the QR code safe to scan?
Only if you opened the page yourself. A code shown by someone else could approve their sign-in.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED