A passkey lets you sign in to SalesThumb with Face ID, Touch ID, Windows Hello, or a physical security key instead of typing a password. Unlike the authenticator-app codes or SMS texts covered in "Securing your account with 2FA," a passkey lives on your device itself, so there's nothing to read off a screen and retype. Passkeys are managed from the same page as the rest of your account security: click your avatar in the top-right corner to open your account menu, then click Security & 2FA — or open Settings and click the Security & 2FA tile. Both take you to /app/settings/security.
Setting up your first passkey
On the Security page, below the authenticator-app and SMS cards, you'll find a Passkeys card ("Sign in with Face ID, Touch ID, Windows Hello, or a hardware security key — no password needed."). If your account has no 2FA factor set up yet, click Add a passkey. The button briefly reads "Waiting for Face ID / Touch ID…" while your browser's native prompt is open — approve it with whatever your device offers, and the passkey is saved. It's given a default name pulled from your browser and device (something like "Chrome on Mac" or "Safari on iPhone"); you can rename it afterward.
If this is the very first factor of any kind on your account — no authenticator app, no SMS number, no other passkey — SalesThumb also generates 10 backup codes and shows them once, right after the passkey is saved. Copy them down before navigating away; there's no way to view that exact set again later without regenerating a fresh one.
Adding more passkeys
You can register more than one passkey — a phone, a laptop, a hardware key — and each one shows up as its own row in the Passkeys card. If your account already has an active factor (an authenticator app, SMS, or another passkey), clicking Add a passkey first shows a field asking you to "Enter your authenticator, SMS, or backup code to add a passkey," using whichever method you already have. This is the same ownership-proof step the 2FA page requires before adding a second authenticator app or SMS number — it stops a hijacked, already-logged-in session from silently registering an attacker's own device on your account.
Renaming or removing a passkey
Each row in the Passkeys list shows the passkey's name plus when it was added and when it was last used (or "Never used" if it hasn't been yet). Click the pencil icon to rename it inline, or the trash icon to remove it. Removing a passkey asks you to "Enter your authenticator, SMS, or backup code to remove this passkey" first, same as adding one. If the passkey you're removing is your only remaining 2FA factor and your account is required to have 2FA — your organization requires it, you're an org/shop owner or admin, or you have Super Admin access — the removal is blocked with a message telling you to set up another 2FA method first. If 2FA isn't required for your account, removing your last passkey turns two-factor off entirely, the same as removing your last authenticator or SMS factor would.
Signing in with a passkey
On the login page, type your email into the email field first, then click "Sign in with Face ID / Touch ID / Windows Hello" below the regular Sign in button — it only appears if your browser supports passkeys. You do need to enter your email before clicking it; if the field is empty you'll see "Enter your email above, then tap Sign in with a passkey." Approve the native prompt and you're signed in — no password, and no separate 2FA screen afterward. A successful passkey sign-in is treated as fully satisfying two-factor authentication on its own, so it skips the normal post-login 2FA verification step entirely, even for accounts that require 2FA.
Passkeys vs. turning on 2FA
Setting up an authenticator app or SMS adds a second step after your password — you still type a password, then a code. A passkey replaces that whole exchange: the Face ID/Touch ID/security key check is both your identity proof and your 2FA proof, so there's no password step at all when you sign in that way. Functionally, though, the two overlap. Your first passkey turns your account's 2FA status on exactly like your first authenticator app or SMS setup would, mints the same kind of backup codes, and satisfies an org's or role's 2FA requirement on its own — you don't need to also set up an authenticator app or SMS if a passkey is already in place, and vice versa. If your browser doesn't support passkeys, the Passkeys card tells you directly: "This browser doesn't support passkeys — try Chrome, Safari, or Edge on a device with Face ID, Touch ID, or Windows Hello."
Frequently asked questions
Q: What's the difference between a passkey and turning on 2FA?
A: An authenticator app or SMS code (covered in "Securing your account with 2FA") is a second step after your password. A passkey replaces the password step entirely — the Face ID/Touch ID/security key check is both your identity proof and your 2FA proof. The two overlap functionally: setting up your first passkey turns your account's 2FA status on the same way a first authenticator or SMS setup would.
Q: Do I need to enter a code every time I add a passkey?
A: Only if your account already has an active factor — an authenticator app, SMS, or another passkey. Then you'll enter a current authenticator, SMS, or backup code before the new passkey can be saved. Your very first passkey on an account with no other factor skips this step.
Q: How many passkeys can I add?
A: As many as you want — one per device (phone, laptop, hardware key) is typical. Each one is a separate row in the Passkeys card that you can rename or remove independently.
Q: What happens if I remove my only passkey?
A: If you have no other 2FA factor and your account isn't required to have 2FA, two-factor turns off for your account entirely. If your account is required to have 2FA — org policy, your role, or Super Admin access — you'll be blocked from removing your last factor until you set up another method first.
Q: My browser doesn't show the passkey option — why?
A: SalesThumb only shows the passkey button when it detects your browser supports it. Try Chrome, Safari, or Edge on a device with Face ID, Touch ID, or Windows Hello — the same guidance shown on the Passkeys card itself.