Why we dropped our custom Bluetooth passkey protocol
SHORT ANSWER
Why did HostSpica remove its own cross-device passkey sign-in?
It only worked on sites that loaded our own script, in browsers that support Web Bluetooth, because no browser or site knew our protocol. Android already offers a standard cross-device flow that lists passkey providers, including HostSpica Identity, when you scan a computer's QR code with the camera. We removed ours in October 2026.
Key takeaways
- A custom protocol needs both ends to speak it. We controlled only the phone end, so almost no real site could use it.
- Our scanner silently failed on a standard passkey QR code, which looked like a bug to users and was a sign the design was wrong.
- The standard flow is run by Android, not by our app, and it may use the internet and Bluetooth. Our app still has no network permission.
- AirAuth, a separate feature, keeps a Bluetooth link for approving sign-ins. That link was not part of this removal.
What we built
Our first design for signing in on a computer used a private protocol we called Mode B. The website's page showed a QR code with a base64 JSON payload: a session ID, the site's origin, a random nonce and an expiry time. The phone scanned it, advertised a Bluetooth Low Energy service for that session, and the page connected to it with the Web Bluetooth API. The challenge and the signed assertion travelled over GATT characteristics, split into fragments that start with a 2-byte length. A script we wrote for websites handled the browser side.
What was wrong with it
- Nobody else spoke it. A site had to add our script. Large sites will not, so the feature could not work for the sites people use.
- Narrow browser support. Web Bluetooth is available in Chromium-based desktop browsers, not in Safari or Firefox.
- A private protocol is a security liability. Standard protocols are examined by many people. Ours had been looked at by us.
- It was a second route next to the standard one. Two ways to do the same thing confuse users and double the review work.
The moment we saw it
On 3 October 2026 we scanned a computer's passkey QR code in two ways. With the phone's camera, Android offered its passkey providers and HostSpica Identity was among them. With the Pair via QR button inside our own app, the scanner closed and nothing happened: the code was not in our format, our parser failed, and the app logged it and returned without telling anyone. The same code worked through one door and silently failed at the other.
What Android does instead
The standard route is the hybrid transport, part of the FIDO specifications. A computer shows a QR code. When you scan it with your phone's camera app, Android takes over: it checks that the phone is nearby and then asks which passkey provider to use, and it calls our provider the same way as for a sign-in on the phone itself. Our code then does what it always does, with its fingerprint or face check. We did not need to write any of the transport.
What we removed, and what stayed
- Removed: the Pair via QR button, the QR scanner launch from the Passkey tab, the Bluetooth permission prompt there, and the pairing and handshake code.
- Kept: AirAuth's Bluetooth link, which approves a sign-in on another screen with your fingerprint. It is a separate feature with its own protocol and the same caveat: it is our own design and has not been independently reviewed.
- Kept: Bluetooth and camera permissions, because AirAuth needs them.
If you want to check how Android handles the standard flow, see how an Android passkey provider works and CTAP 2.3 draft notes. We have confirmed on a real phone that HostSpica Identity is offered in the QR flow. We have not yet recorded a full sign-in on a computer, and we will update this page when we do.
Frequently asked questions
Does cross-device sign-in with HostSpica work now?
The standard flow offers HostSpica Identity as a provider. A complete sign-in on a computer is something we still have to confirm and will report here.
Why not keep both?
Because the private one served almost nobody and added a second route to review, explain and secure.
Is the camera scan a HostSpica feature?
No. It is Android's. We provide the passkey when Android asks for one.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED