> ## Documentation Index
> Fetch the complete documentation index at: https://docs.defendis.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Passkeys

> Set up and use a passkey to sign in to Defendis securely without a password or verification code.

Passkeys let you sign in to Defendis with your fingerprint, face, device PIN, or screen lock. They are easier to use than passwords and are designed to resist phishing.

## How passkeys protect your account

A passkey consists of a cryptographic key pair. The private key stays on your device or in your passkey provider, while Defendis receives only the public key needed to verify your sign-in.

* Your fingerprint and face scan are never shared with Defendis.
* There is no password or one-time code for an attacker to steal or trick you into entering on a fake site.
* Depending on your device, your passkey may sync securely through services such as iCloud Keychain or Google Password Manager.

<Note>
  Your password and authenticator app remain available as recovery and alternative sign-in methods. A passkey is sufficient when you choose passkey sign-in; Defendis will not ask for a separate MFA code.
</Note>

## Add a passkey

1. Sign in to Defendis on a device you trust.
2. Go to **Settings → Account Security → Passkeys**.
3. Select **Add passkey**.
4. Follow your device prompt and confirm with your fingerprint, face, PIN, or screen lock.

<Warning>
  Do not create a passkey on a public or shared device. Anyone who can unlock that device may be able to use its passkey.
</Warning>

## Sign in with a passkey

1. On the Defendis sign-in page, select **Sign in with a passkey**.
2. Choose the passkey requested by your browser or device.
3. Confirm with your fingerprint, face, PIN, or screen lock.

You do not need to enter your password or an authenticator code when the passkey sign-in succeeds.

## Manage your passkeys

Open **Settings → Account Security → Passkeys** to review, rename, or remove your passkeys. Use a clear name such as “Work MacBook” or “iPhone” so you can recognize each one later.

We recommend adding passkeys on more than one trusted device. If a device is lost, remove its passkey from Defendis and use another passkey, your password, or your recovery method to sign in.

## If passkey setup or sign-in does not work

* Update your browser and operating system.
* Confirm that a screen lock, fingerprint, face recognition, or device PIN is enabled.
* Cancel the device prompt and try again.
* Try another supported browser or a different trusted device.
* If your passkey is unavailable, sign in with your password and complete any required verification.

Passkeys require a compatible browser and device. They are not available for accounts that sign in exclusively through single sign-on (SSO).
