Passkeys provide a secure way to sign in to your Apaleo account without using a password. They rely on cryptographic keys stored on your device and unlocked using biometrics (such as Face ID, Touch ID, or Windows Hello) or a device PIN. Passkeys can be used as a primary login method or as an MFA verification method.
Because passkeys are tied to your device and the Apaleo service, they are resistant to phishing and cannot be reused or intercepted like passwords.
What is a passkey?
A passkey is a passwordless authentication method based on public-key cryptography.
Instead of entering a password, you confirm your identity using a biometric factor or device PIN. The private key never leaves your device, and Apaleo only verifies the corresponding public key during login.
Passkeys are created per user and managed individually.
Passkey Storage Options
Passkeys are stored and managed by your operating system or a password manager, for example Apple Keychain or Windows Hello, as well as password managers such as 1Password and Bitwarden.
Recommendations
To ensure reliable access to your account when using passkeys:
- Create passkeys on the devices you regularly use to sign in
- Consider using a password manager that syncs passkeys across your devices
- Avoid creating passkeys on shared or temporary devices
- Make sure you have at least one alternative way to sign in before removing a passkey
Creating a Passkey
You can create a passkey after signing in to Apaleo. To do so:
- Open your Profile.
- Go to Security & authentication → Manage Passkeys.
- Select Add a new passkey.
- Follow the instructions shown by your browser or password manager.
Once the setup is complete, the passkey is linked to your user profile and can be used for future logins.
Managing Passkeys
All passkeys associated with your user are listed under Profile → Security & authentication → Manage Passkeys.
From there, you can:
- View existing passkeys.
- Add additional passkeys (for example, for another device).
- Delete passkeys you no longer want to use.
Important: To delete a passkey, you must have access to at least one existing passkey. If you cannot access any of your passkeys, refer to the Removing passkeys for other users section below.
Signing in with a Passkey
When signing in to Apaleo, a passkey can be used in two ways:
- If a passkey is available, your browser or password manager may suggest it automatically during login.
- If no suggestion appears, you can choose Log in with passkey on the login screen.
In both cases, you confirm the sign-in using your device’s biometric method or PIN.
Passkeys and Multi-Factor Authentication (MFA)
Passkeys can be used in two ways in relation to MFA:
- As a primary login method: Instead of entering your email and password, you sign in directly with a passkey. In this case, the MFA step is skipped entirely.
- As an MFA verification method: You sign in with your email and password as usual, and confirm your identity using a passkey during the MFA step instead of a TOTP code.
Account admins can control which MFA methods are available to users. For more information, see Multi-Factor Authentication (MFA).
Removing Passkeys for Other Users
Only account administrators can remove passkeys for other users in their account. This may be required if a user has lost access to all devices associated with their passkeys and is unable to manage them on their own.
FAQ
If I have a passkey set up on my work laptop, how can I log in to Apaleo from my personal phone?
To sign in from another device, you need a passkey that is available on that device.
This can be done by creating a passkey directly on your personal phone or by using a password manager that syncs passkeys across your devices.
If no passkey is available on the device you are using, you can sign in using your existing login method and then create a passkey for that device.