Overview
A passkey lets you sign in with Touch ID, Face ID, Windows Hello, your phone, or a security key instead of typing a code — and it counts as two-factor authentication on its own.
Steps
- Click your avatar in the top-right corner and choose Profile.
- Select the Security sub-tab.
- Under Passkeys, type a name for the device you’re adding — e.g. “MacBook” or “Work iPhone” — in the Name field.
- If you already have two-factor authentication turned on, a Current code field also appears. Enter a current authenticator app code or a recovery code (this stops a hijacked session from silently adding an attacker’s own passkey).
- Click Add.
- Your browser or device prompts you to complete the passkey — e.g. Touch ID, Face ID, Windows Hello, or a security key. Follow that prompt.
- If this is the first second factor on your account, a “Save your recovery codes” screen appears — see Save and use your recovery codes.
- The new passkey appears in the Passkeys list with its name and the date it was added.
Good to know
- You can add more than one passkey — e.g. one per device — by repeating the steps above.
- To remove a passkey, click Remove next to it in the list, then enter a current authenticator code or recovery code to confirm.
- Removing your last remaining passkey, with no authenticator app set up, turns two-factor authentication off entirely and clears your recovery codes.
- A passkey satisfies your workspace’s “require two-factor authentication” policy the same as an authenticator app — you don’t need both.
Related articles
See also Turn on two-factor authentication with an authenticator app, Save and use your recovery codes, and Turn off or reset two-factor authentication.