Guide: Turn on passkeys without a support wave

Enable them, prove they work on your own device, then let people find them.

About 20 minutes, then a week of watching.

  1. Decide the domain first Before anyone enrols, settle the domain passkeys bind to. If the app might move to app.yourhosting.com later, set the parent domain now. This is the one decision that cannot be undone quietly: changing it invalidates every passkey already created and everyone has to enrol again.
  2. Turn passkeys on, leave verification required The default insists on a fingerprint, face or device PIN. Keep it. Presence alone is weaker than the password it replaces, and every recent phone can satisfy it.
  3. Enrol one yourself and sign out Open the app on your own phone, go to Account, tap Set up a passkey, then sign out and back in with it. Five minutes here tells you whether your certificate, domain and app address all agree, which is where every passkey problem actually comes from.
  4. Confirm it appears Your passkey shows up under Devices with the device name and whether it was verified biometrically. If the column says presence only, the device skipped the fingerprint prompt and you should check the setting.
  5. Say nothing to clients at first Passwords keep working, so there is no migration and no deadline. People discover the option under Account and take it or leave it. Announcing a security change invites questions you do not need to answer; letting it appear quietly gets adoption without a support queue.
  6. Watch the first week Enrolments appearing with no matching support tickets means it is working. If someone does write in having lost a device, their password still signs them in, and they remove the old passkey under Account themselves.