OmxusHelp

HelpSigning in

Sign in with a passkey

A passkey lets you sign in with the same fingerprint, face or PIN you use to unlock your device. There's no password to remember or type.

Save a passkey

  • After you sign in, the site offers once to save a passkey. Select Save and follow your device's prompt.
  • Any time, add one in your Omxus Account under Security.

Your device or password manager keeps the private part of the passkey. It never leaves your device, and Omxus never sees it. We keep only the public part, which can check a sign-in but can't be used to sign in.

Sign in with your passkey

  1. On the site, select Sign in.
  2. Choose your passkey when your device offers it, or select Try another way and then Use your passkey.
  3. Unlock with your fingerprint, face or PIN.

Important

A passkey belongs to the website where you saved it. A passkey saved on one site doesn't sign you in on a different site's own sign-in screen. Save a passkey on each site you use often, or on the Omxus sign-in page, which many sites share.

See and remove passkeys

In your account settings on a site, you can see each passkey on your account: which site it's for, when you saved it, when you last used it, and whether it's backed up to a password manager.

  1. Open the passkeys list.
  2. Next to the passkey, choose Remove.
  3. Confirm it's you with your password or a code, unless you signed in within the last 10 minutes.

You can't remove the only way you have to sign in. If a passkey is your only way in, add a password first.

Why do you ask for my fingerprint, face or PIN every time?

A passkey on its own proves you have the device. Unlocking it proves you're the person using it. We require both, every time, so a borrowed or stolen device can't sign in.

"That passkey didn't work here. Try another way to sign in."

Try again, and check you're on the same site where you saved the passkey. If your device offers no passkey, you may have saved it in a different browser or password manager. You can always use another way in and save a new passkey.

What's the research behind passkeys?

Passkeys follow the Web Authentication standard from the W3C (Balfanz et al., 2021). Each passkey is a key pair made for one website, and the browser only uses it on that website. Researchers comparing sign-in methods found that none of the password replacements they studied beat passwords on every count at the time (Bonneau et al., 2012). Passkeys aim at the biggest gap they identified: protection against phishing without extra effort.

Research referred to

  1. Balfanz, D., Czeskis, A., Hodges, J., Jones, J. C., Jones, M. B., Kumar, A., Liao, A., Lindemann, R., & Lundberg, E. (2021). Web Authentication: An API for accessing Public Key Credentials, Level 2. W3C Recommendation. w3.org/TR/webauthn-2
  2. Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2012). The quest to replace passwords: A framework for comparative evaluation of web authentication schemes. IEEE Symposium on Security and Privacy. doi.org/10.1109/SP.2012.44

Need more help?

Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.