---
title: "Passkeys"
description: "A passkey is a sign-in credential bound to one device and unlocked by its screen lock. Fincanva does not support passkeys, and its settings show no passkey row."
canonical_url: "https://fincanva.com/glossary/passkeys"
last_updated: "2026-09-28"
md_url: "https://fincanva.com/glossary/passkeys.md"
---

# Passkeys

A passkey is a sign-in credential that lives on one device — a phone, a laptop, or a hardware security key — and is unlocked by that device's own screen lock, so you prove who you are with a fingerprint, a face scan, or a device PIN instead of typing a secret. **Fincanva does not support passkeys yet.** This page explains the concept so it is already clear when the feature arrives; it describes no Fincanva flow, because none exists.

**Also seen as:** passkey, WebAuthn credential, FIDO2 credential

## Can I use a passkey with Fincanva today?

No. Fincanva has no passkey setting: **Settings → Access and security** lists your password, two-factor authentication, connected accounts and [active sessions](/glossary/active-sessions), and no **Passkeys** row. There is nothing to enrol, nothing to name, and nothing to remove, and no passkey affects how you sign in. What that page holds: [how to manage your account security settings](/docs/account-security/how-to-manage-your-account-security-settings).

Until it ships, the ways into a Fincanva account are the three described under [passwordless sign-in](/glossary/passwordless-sign-in) — an emailed link, an emailed 6-digit code, or a password — plus **Continue with Google**, each of which can be protected with [two-factor authentication](/glossary/two-factor-authentication).

## What is a passkey?

A passkey is a pair of cryptographic keys created for one website and stored on one device. The device keeps the private half and never releases it; the website keeps only the public half, which is useless to anyone who steals it. Signing in means the site sends a challenge, your device unlocks the private key with your fingerprint, face, or PIN, and returns a signature the site can verify.

Two consequences follow from that shape, and they are the whole point of the design:

- **Nothing reusable is transmitted.** A signature answers one challenge and cannot be replayed elsewhere, so there is no shared secret in flight to intercept.
- **The credential is bound to the site that issued it.** A passkey created for one site will not sign a challenge from a lookalike domain, which is why passkeys resist phishing in a way a typed secret cannot.

Passkeys are the consumer-facing name for credentials built on the WebAuthn and FIDO2 standards, which is why the same passkey works across browsers and platforms that implement them.

## How is a passkey different from a password?

In one line: a password is something you know and can therefore be tricked into typing somewhere else, while a passkey is something your device holds and will only ever present to the one site it was made for.

| | Password | Passkey |
|---|---|---|
| Where it lives | in your head or a manager | on a device, in its secure store |
| What travels to the site | the secret itself | a one-off signature |
| Phishable | yes — you can type it into a fake page | no — it will not sign for the wrong domain |
| Reusable across sites | yes, and that is the risk | no, one per site by construction |
| Breach exposure | the site holds something worth stealing | the site holds only a public key |
| How you unlock it | by recalling it | with the device's fingerprint, face, or PIN |

The practical trade is convenience against portability: a passkey removes the recall step entirely, but it is tied to the device or the platform keychain that holds it, so losing every synced device is a different kind of problem than forgetting a password.

Fincanva is for education and illustration only. It is not personalised financial advice, and past or simulated results do not predict future ones. [Read the Terms Addendum](https://fincanva.com/terms/addendum#section-3)
