Skip to Content

Passkeys

Your passkey is your signature in Koywe: fingerprint, Face ID, device PIN, or security key. Without it, no operation gets confirmed, so it is the first thing to set up.

What unlocks it

The passkey lives on your device and unlocks with whatever that device already uses to recognize you. Koywe never sees your fingerprint or your face: it only receives the signature the device generates with it.

  • Fingerprint
    Touch ID on a Mac, the fingerprint reader on Android, Windows Hello on a laptop.
  • Face
    Face ID on iPhone or iPad, or Windows Hello facial recognition.
  • Device PIN or pattern
    the same one you use to unlock the screen. It is the fallback when the device has no reader or camera.
  • Physical security key
    a YubiKey or similar, over USB or NFC. Koywe accepts both.
  • Your phone’s passkey, from your computer
    the browser shows a QR code, you scan it with your phone, and you sign there. The passkey is not copied to the computer.
You do not choose which one in Koywe

Your device and your browser decide: Koywe asks for a signature and the system offers the method it has set up. If your passkey is stored in iCloud Keychain or Google Password Manager, it follows you to every device where you use that account; if you created it for a single device, it only works there. That is why signing failures are almost always about the device, not permissions.

The root user’s passkey

The root user is the user who registers the organization with Koywe. The first thing they have to do is create their passkey: when they sign in they see the prompt “Create your passkey to continue” and complete it. With that, the organization is enabled to sign and the rest of the team can register theirs.

Decide who does the onboarding

Whoever does the onboarding becomes the root user. It is permanent, and only Koywe can step in afterward.

Choose someone who will stay with the company, who works from their own device where passkeys work for them, and who is available when a colleague gets locked out.

Each person’s passkey

Each user signs in and sees “Your operations require a passkey” → Activate passkey.

It does not activate on its own: the root user has to approve it, and has 24 hours to do so before it expires. While waiting, the person sees “Passkey enrollment pending” and cannot sign anything.

Registration and approval go together

Do them at the same time, with both people available. Otherwise, the registration expires and you have to start over.

When the root user approves, the browser asks for their passkey twice in a row. This is normal.

The two ways to sign

Signing is the act of confirming an operation. Depending on how the organization is set up, you sign in one of these two ways:

Passkey
Everyone, by default
  • Operate and approve
  • Change the approval policy rules
  • Approve other people’s passkeys
  • Sign crypto operations from the wallet
Email code (OTP)
Only if Koywe enables it for the organization
  • Operate and approve
  • Sign crypto operations from the wallet
  • Approve other people’s passkeys

By default, API users do not sign: if the rule allows the operation, it goes straight through.

Careful: there are two 6-digit email codes and they are easy to mix up
  • The signing code replaces the passkey on each operation. It only exists if Koywe enabled it for your organization.
  • The recovery code works only once, to create a new passkey when you lost the previous one. The root user starts it.

Getting one code does not mean you have the other one enabled.

If someone loses their passkey

The root user starts the recovery from the passkeys screen. The person receives a 6-digit code by email and uses it to create a new one. The previous one is revoked permanently.

The exception is the root user: they cannot recover on their own. If they lose their device, they have to email support from the organization’s registered email address, and until it is resolved nobody else can register or recover passkeys.

Recommendations

  • Store the passkey in a synced password manager (iCloud Keychain, Google Password Manager, 1Password), not tied to a single machine. Otherwise, switching devices means a recovery.
  • Register each person’s passkey before you require approvals. An approver without a passkey is a rule that gets stuck.
  • Keep in mind which device you sign from. The most common failures are about the device, not permissions: a passkey created on your phone only works on your computer if the provider syncs it or if you scan the QR code.

Next steps

Last updated on