Passkeys
Your passkey is your signature in Koywe: fingerprint, Face ID, device PIN, or security key. Without it, no operation gets confirmed, so it is the first thing to set up.
What unlocks it
The passkey lives on your device and unlocks with whatever that device already uses to recognize you. Koywe never sees your fingerprint or your face: it only receives the signature the device generates with it.
Your device and your browser decide: Koywe asks for a signature and the system offers the method it has set up. If your passkey is stored in iCloud Keychain or Google Password Manager, it follows you to every device where you use that account; if you created it for a single device, it only works there. That is why signing failures are almost always about the device, not permissions.
The root user’s passkey
The root user is the user who registers the organization with Koywe. The first thing they have to do is create their passkey: when they sign in they see the prompt “Create your passkey to continue” and complete it. With that, the organization is enabled to sign and the rest of the team can register theirs.
Whoever does the onboarding becomes the root user. It is permanent, and only Koywe can step in afterward.
Choose someone who will stay with the company, who works from their own device where passkeys work for them, and who is available when a colleague gets locked out.
Each person’s passkey
Each user signs in and sees “Your operations require a passkey” → Activate passkey.
It does not activate on its own: the root user has to approve it, and has 24 hours to do so before it expires. While waiting, the person sees “Passkey enrollment pending” and cannot sign anything.
Do them at the same time, with both people available. Otherwise, the registration expires and you have to start over.
When the root user approves, the browser asks for their passkey twice in a row. This is normal.
The two ways to sign
Signing is the act of confirming an operation. Depending on how the organization is set up, you sign in one of these two ways:
- Operate and approve
- Change the approval policy rules
- Approve other people’s passkeys
- Sign crypto operations from the wallet
- Operate and approve
- Sign crypto operations from the wallet
- Approve other people’s passkeys
By default, API users do not sign: if the rule allows the operation, it goes straight through.
- The signing code replaces the passkey on each operation. It only exists if Koywe enabled it for your organization.
- The recovery code works only once, to create a new passkey when you lost the previous one. The root user starts it.
Getting one code does not mean you have the other one enabled.
If someone loses their passkey
The root user starts the recovery from the passkeys screen. The person receives a 6-digit code by email and uses it to create a new one. The previous one is revoked permanently.
The exception is the root user: they cannot recover on their own. If they lose their device, they have to email support from the organization’s registered email address, and until it is resolved nobody else can register or recover passkeys.
Recommendations
- Store the passkey in a synced password manager (iCloud Keychain, Google Password Manager, 1Password), not tied to a single machine. Otherwise, switching devices means a recovery.
- Register each person’s passkey before you require approvals. An approver without a passkey is a rule that gets stuck.
- Keep in mind which device you sign from. The most common failures are about the device, not permissions: a passkey created on your phone only works on your computer if the provider syncs it or if you scan the QR code.
Next steps
- Approval policy — the rules that decide whether an operation goes through, is denied, or waits for a signature.
- Troubleshooting — passkeys that do not sign, registrations that expire, and recoveries. Straight to the case: I created my passkey but signing says it is invalid.
- Passkeys & Approvals — the signing mechanics, MFA tokens, and API user keys.