Sign in with passkeys (no password required)

passkey is a phishing-resistant alternative to passwords. Instead of typing a password, you prove you're you using your device's built-in security: fingerprint sensor, face recognition, or device PIN. Passkeys are built on the FIDO2 / WebAuthn standard, which means your phone, laptop, and password manager already know how to use them.

This article covers how to add a passkey to your Simbase account, how to sign in with one, and how to remove one.

Why passkeys

  • No password to type. Faster sign-in. No autofill mistakes

  • No password to leak. The private half of the key never leaves your device. Simbase only stores the public half

  • Phishing-resistant. A fake Simbase login page can't steal a passkey the way it can steal a password

  • Replaces MFA codes. A successful passkey sign-in counts as both factors, so you won't be prompted for an MFA code on top

How passkeys work (the short version)

When you set up a passkey, your device generates a unique cryptographic key pair:

  • The private key stays on your device (or in your password manager)

  • The public key is stored on Simbase

At sign-in, your device proves it holds the private key without ever transmitting it. Simbase verifies the proof using the public key. The two halves never need to leave their respective sides, which is why phishing doesn't work.

You can store passkeys on your computer, phone, tablet, or in a compatible password manager such as iCloud KeychainGoogle Password Manager1Password, or Bitwarden.

Add a passkey

  1. Sign in to dashboard.simbase.com

  2. Open Settings → Personal details

  3. Click Add passkey

  4. Verify with whatever your device uses: fingerprint (Touch ID, Windows Hello), face (Face ID), device PIN, or a hardware security key such as a YubiKey

Once created, the passkey appears in your passkey list with the device name and creation date.

Sign in with a passkey

  1. Go to dashboard.simbase.com and enter your email

  2. Choose Sign in with passkey when prompted

  3. Your browser asks you to verify with the same method you set up (fingerprint, face, PIN, or security key)

  4. You're in. No password, no MFA code

If you have both MFA and a passkey configured, the passkey sign-in covers both. Simbase won't prompt for a separate MFA code.

Remove a passkey

If you've replaced a device, lost a device, or no longer want a particular passkey:

  1. Open Settings → Personal details

  2. Find the passkey in the list

  3. Click the remove icon next to it

  4. Confirm

Always keep at least one alternative sign-in method before removing a passkey.That can be your password + MFA, or another passkey on a different device. If you remove your only sign-in method, you'll lock yourself out and need to go through account recovery.

For most accounts:

  • Set up a passkey on your primary device (laptop or phone) for everyday sign-in.

  • Set up a second passkey on a different device as a backup. If you lose one, you can still sign in with the other.

  • Keep your password and MFA enabled as a final fallback. Don't remove them unless you have multiple passkeys you trust.

What happens if you lose your device

  • If the passkey is synced through a password manager (iCloud Keychain, Google Password Manager, 1Password, etc.), it's already available on your other devices. Sign in there and remove the lost device's passkey from the dashboard.

  • If the passkey is device-bound (not synced, for example a YubiKey or a passkey created without a syncing password manager), you can still sign in with your password + MFA, then remove the old passkey from your profile.

  • If you have no other sign-in method, contact support for account recovery.

Common questions

Yes. Both can be enabled simultaneously. Signing in with a passkey counts as multi-factor by itself (device possession + biometric / PIN), so MFA isn't prompted. If you sign in with your password instead, MFA still kicks in.

Current versions of Chrome, Safari, Edge, and Firefox on Windows, macOS, iOS, Android, and Linux all support passkeys.

Yes. Setup and sign-in work on the mobile browser version of the Simbase dashboard.

No, and you shouldn't try. Passkeys are tied to the individual person. Each team member should set up their own passkey for their own user account.

Not from Simbase directly. Password managers handle the syncing and migration. If you change password managers, follow your manager's migration process.