Fingerprint & passkey sign-in
Passkeys let your team sign in with the fingerprint, face or screen lock they already use on their phone or laptop, instead of typing a password. Switch it on under Settings → General.
How your staff set it up: they sign in with their password as usual, go to their WordPress profile, and choose Add a passkey on this device. Their device asks for the fingerprint or face it already knows. That is it — next time the sign-in screen offers Sign in with fingerprint or face.
Each device needs its own passkey, so someone using a phone and a laptop adds one on each. They can add as many as they like.
Passwords keep working. A passkey is an extra, faster way in — never a replacement. If a phone is lost, forgotten or simply refuses to cooperate, the password still signs them in, so nobody can be locked out.
Why it is safer than a password. The fingerprint itself never leaves the device and is never sent to the site. What gets stored here is a key that only works on this exact site, so it cannot be phished, reused elsewhere, or stolen in a database breach. There is no password for anyone to guess.
Passkeys need HTTPS and the OpenSSL PHP extension. If your site does not have both, the setting stays switched off and explains why.
Example
A groomer opens the staff app between dogs, touches the fingerprint sensor and is straight in — no password typed with wet hands.
FAQ
What if someone loses their phone?
Nothing is at risk: the passkey only works with that person’s fingerprint or screen lock on that device. They sign in on another device with their password, and can remove the old passkey from their profile.
Does the site see my fingerprint?
No. The fingerprint stays on the device and is only used to unlock the key stored there. The site never receives it and could not store it if it wanted to.
Do I have to use a passkey?
No. It is entirely optional per person, and passwords always keep working alongside it.
Why is the setting greyed out?
Passkeys need HTTPS and the OpenSSL PHP extension. If either is missing the setting cannot be switched on — ask your host to enable them.
Can customers use passkeys for the client portal?
Not yet. Passkeys currently cover staff sign-in; customers still reach their account through their own private portal link.