Skip to content

Passkeys

A passkey lets you sign in with Windows Hello, Touch ID, Face ID or your device PIN instead of typing a code from an app.

  • There is nothing to type and nothing to copy from a phone.
  • A passkey is phishing-resistant. It is tied to this site only, so it cannot be replayed against a lookalike domain.
  • Tidehawk asks your device for user verification, meaning a biometric or a PIN. Merely having the device plugged in is not enough.

A passkey counts as your second factor, so registering one satisfies the mandatory multi-factor requirement described in Two-factor authentication.

  • Use a browser and device that support passkeys, such as a current version of Chrome, Edge, Safari or Firefox.
  • Have the device’s unlock method available: fingerprint, face, or PIN.
  1. Sign in with your email and password.
  2. On the Secure your account page, select Set up a passkey.
  3. Approve the prompt from your operating system or password manager.

The button shows “Waiting for authenticator…” while the prompt is open. When it completes, Tidehawk shows your recovery codes. Save them before continuing.

If you would rather use an authenticator app, select Use an authenticator app instead on the same page.

  1. Go to the sign-in page.
  2. Select Sign in with passkey.
  3. Approve the prompt on your device.

You do not type a password on this path.

If you sign in with your email and password while holding a passkey, Tidehawk asks you to present the passkey before it issues a session. Registering a passkey and never using it would protect nothing, so the assertion is required on that sign-in too. If you cannot produce it, choose Lost your passkey? Use a recovery code.

A passkey is created for one site. Your Tidehawk passkey works at app.tidehawk.co and nowhere else, and no other site can ask your device for it. That binding is what makes a passkey phishing-resistant, and it is also why a passkey saved on one device is only available on another device if your password manager or platform account syncs it for you.

If you sign in from a device that does not have the passkey, use your email and password with your authenticator app, or use a recovery code.

Removing a passkey lowers the strength of your account, so it requires your password to be entered again. Tidehawk does not currently expose a remove button in Settings, so email support@tidehawk.co to have a passkey you no longer use removed.

Support staff working inside your workspace cannot remove a passkey on your behalf.