How to set up a passkey:
A passkey is a secure, passwordless way to confirm it's really you. It doesn't replace a password, users will still sign in with their email and password, or SSO, exactly as they do today. A passkey is simply another form of authenticating your account: the user confirms it's them using their device's own security, such as Face ID, Touch ID, Windows Hello, or a PIN.
Sprintax never sees or stores biometric data. Face ID, Touch ID, fingerprints, and PINs are handled entirely by the user's own device, browser, or password manager. Identity Server only stores a public key and basic credential details (such as the passkey's name and creation date) needed to verify it at sign-in.
Add a passkey to your account:
Step 1 — Open Account › Security
Sign in to Sprintax, navigate to your account, and select the Security tab. You’ll find the Passkeys section at the top. Select Add Passkey to begin.
Step 2 — Name your passkey
Give it a display name you’ll recognize later — for example “Work laptop” or “My phone.” This name is just for you. Select Continue.
Step 3 — Choose where to save it
Your browser asks where to save the passkey. Pick the option that matches how you want to sign in:
Option A — Save on this device
Store the passkey on the device you’re using, protected by a fingerprint, face, or PIN.
When your browser offers to save the passkey (for example to Microsoft Password Manager, iCloud Keychain, or Google Password Manager), select Create.
Confirm with your device’s security, enter your PIN, or use Face ID, Touch ID, a fingerprint, or Windows Hello.
Option B — Use a phone, tablet, or security key
Save the passkey on your phone by scanning a QR code.
- When your browser asks which device to use, select “iPhone, iPad, or Android device” (or Security key if you use a hardware key).
- A QR code appears, scan it with your phone’s camera and follow the prompt on your phone.
- Once your phone connects, finish the prompt on your phone to complete the passkey.
Step 4 — Complete Setup
However you saved it, you’ll see a “Passkey added successfully” confirmation, and the passkey appears in your Passkeys list with a status of Confirmed. It’s now ready to use as your verification step the next time you sign in.
Removing a passkey
From Account > Security, find the passkey in the list.
Open the “...” actions menu beside it and choose to delete it.
Confirm the deletion. Once removed, that passkey can no longer be used to sign in.
Good to know:
Keep at least one way to sign in. Before deleting any passkey or MFA method, make sure you still have another way to access your account, such as another passkey, an authenticator app, or SMS verification.
You can review or remove your passkeys at any time from Account › Security. To remove one, open the actions menu (the “…” beside the passkey) and choose to delete it, then confirm.
FAQ:
Does a passkey replace my password?
No. You'll still sign in with your email and password, or through SSO. A passkey only replaces the one-time code step afterwards, it's an extra verification (MFA) option, not a new way to sign in.
Does Sprintax store my fingerprint, face, or PIN?
No. Your biometric data and PIN never leave your device or password manager. Sprintax only stores a public key and basic details about the passkey so it can confirm the verification step.
Where is my passkey actually saved?
Wherever you choose during setup, your device's built-in option (iCloud Keychain on Apple, Google Password Manager on Android, Windows Hello on Windows), a password manager like 1Password or Bitwarden, or your phone via a QR code.
What if I lose my device?
Verify using another method you've set up (another passkey, an authenticator app, or SMS), then delete the passkey tied to the lost device from Account › Security.
Do I have to use a passkey?
No. A passkey is an optional, additional verification step. You can keep using Text Message or an authenticator app instead.
My browser says passkeys aren't supported. What now?
Continue with your existing verification method. You can add a passkey later from a supported device and browser.