Passkeys
A passkey lets you verify your sign-in with your fingerprint, face or screen lock instead of a code. This guide explains how to set one up and use it.
What is a passkey?
A passkey is a digital key that your device creates for XFA and keeps safe for you, for example in iCloud Keychain, Google Password Manager or your password manager. When you sign in, your device asks you to unlock the passkey with your fingerprint, face or screen lock.
Your privacy: your fingerprint and face never leave your device, and XFA never sees them. XFA only receives proof that you unlocked your passkey.
Benefits of passkeys:
- Nothing to type or remember
- Works in your browser and in the XFA mobile app
- Only works on XFA's real sign-in page, so a fake site cannot use it
- Saved in iCloud Keychain, Google Password Manager or a password manager, it works on your other devices too
Requirements
Before you start, make sure you have:
- A browser that supports passkeys, such as a current version of Chrome, Edge, Firefox or Safari, or the XFA mobile app version 1.0.116 or later on iOS 16 or later or Android 9 or later
- A device with a fingerprint reader, face unlock or screen lock, or a phone or security key to use instead
- Access to your email, to approve the setup
Setting up a passkey (first time)
Step 1: Choose Passkey
When signing in, you may be asked to choose a verification method. Select Passkey and click Continue. In the XFA mobile app, tap Use a passkey.
If your organization only has passkeys enabled, you won't see this choice and will go directly to the next step.
Step 2: Approve the setup
XFA first asks you to approve the new passkey. You receive an email: open it and approve the request.
The sign-in page continues on its own once you have approved.
If you don't receive the email, check your spam folder or click Send the email again.
Some organizations have auto-approve enabled, in which case you may skip this step.
Step 3: Create the passkey
Your device asks you to create the passkey. Confirm with your fingerprint, face or screen lock.
If your computer has no fingerprint reader or face unlock, your browser offers to use your phone instead. Follow the steps your browser shows, for example scanning a QR code with your phone. To use a security key such as a YubiKey, see Using a security key.
In the browser, your device then asks you to confirm once more with your new passkey. After that, you are signed in and redirected to your application. In the XFA mobile app, creating the passkey is enough.
Using a security key
A security key is a small device you plug in or tap, such as a YubiKey. To set one up, click Use a security key under the button on the passkey screen, then follow what your browser asks: plug in or tap the key, enter its PIN, and touch it.
- Your PIN: most organizations require it. If yours allows keys without a PIN, a touch is enough, and older keys that cannot set a PIN work too.
- Signing in afterwards: use the key the same way each time. You don't have to choose it again.
- In the XFA mobile app: security keys aren't supported yet. Use a passkey there, or sign in on a computer.
Signing in with a passkey
Once your passkey is set up, you'll use it each time you sign in:
- Sign in to your application as usual
- When your device asks, confirm with your fingerprint, face or screen lock
- Continue to your application
If no prompt appears, click Use passkey.
Switching between methods
If your organization has enabled multiple verification methods, you can switch by clicking Set one up, next to Want to use a different method? on the verification screen. In the XFA mobile app, tap Use a different method.
Troubleshooting
"The request was dismissed or timed out"
You closed the prompt or waited too long. Click Create passkey or Use passkey to try again.
"The passkey could not be used"
Click Create passkey or Use passkey to try again. When your device offers more than one passkey, pick the one for this account. If it keeps failing, choose another method or contact your IT help desk.
"No passkey for this account was found"
Your device has no passkey for this account. In the XFA mobile app, you can use a passkey from another device, or choose another method.
"This browser or device cannot use passkeys"
Update your browser or try a different one. You can also click Set one up to use another method. In the XFA mobile app, update your phone or choose another method.
Your security key does nothing when you touch it
- Your key may need a PIN before it can be used. Set one with your key maker's app, for example Yubico Authenticator, and try again
- Older keys cannot set a PIN. They only work when your organization allows keys without one, so ask your IT administrator
- Try another method, or contact your IT help desk
"This page could not be verified as XFA"
Open the sign-in link from your application again and retry. Don't continue on a page you don't trust.
Didn't receive the approval email
- Check your spam or junk folder
- Click Send the email again
- Make sure you're checking the correct email address
Got a new phone or computer
If your passkey is saved in iCloud Keychain, Google Password Manager or a password manager, sign in to that account on your new device and your passkey is there. Otherwise, contact your IT administrator. They can reset your MFA so you can set up a new passkey.
Lost your device or security key
Contact your IT administrator. They can reset your MFA so you can set up a new passkey.
Need help?
If you're having trouble with passkeys, contact your IT help desk.