> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure passkeys

> Use passkeys for phishing-resistant account authentication.

Passkeys let you sign in with a device authenticator, such as biometrics, a device PIN, or a hardware security key. Add a passkey from account security and give it a name that identifies the device.

Register more than one trusted authenticator when practical so one lost device does not become your only route back in. Remove a passkey when the device is lost, replaced, or no longer under your control.

Passkey availability depends on browser and device support.

## Add a passkey

1. Open account security and choose the passkey action.
2. Select **Add passkey**.
3. Follow the browser or operating-system authenticator prompt.
4. Give the passkey a name that identifies the device or hardware key.
5. Sign out and test it before relying on it as a recovery method.

## Use and remove passkeys

At sign-in, choose the passkey option and complete the device prompt. The
private credential remains protected by the authenticator rather than being
typed into Biqli.

Remove a passkey when the device is lost, sold, shared, or no longer trusted.
Keep another working sign-in and recovery method before removal.

If a passkey prompt does not appear, confirm browser support, device sync, and
that you are signing in to the account where it was registered.

## Frequently asked questions

### Is a passkey the same as two-factor authentication?

No. A passkey is a sign-in credential protected by an authenticator. Two-factor
authentication is a separate account security control.

### Can I register several passkeys?

Use the available account controls to add trusted authenticators and name each
one clearly for later removal.
