Setting Up Passkeys
Passkeys let you sign in to Proxima Console using biometrics (fingerprint, face) or a security key — no password needed.
What Are Passkeys?
Passkeys are a modern replacement for passwords. They use the same technology that secures online banking and government IDs (WebAuthn/FIDO2). Your passkey is stored securely on your device and never leaves it.
Benefits:
- No passwords to remember or type
- Phishing-resistant — passkeys are bound to the Proxima Console domain
- Faster sign-in — one tap or glance
- Works across devices via iCloud Keychain, Google Password Manager, or Windows Hello
Registering Your First Passkey
- Sign in to Proxima Console with your existing credentials
- Go to Profile & Security (click your avatar → Profile)
- Switch to the Security tab
- Find the Passkeys section
- Enter a name for your passkey (e.g., "MacBook Pro", "YubiKey")
- Click Add passkey
- Follow the browser/OS prompt to create the passkey
Your device will ask you to verify with biometrics (fingerprint, face) or a PIN.
Signing In with a Passkey
- On the login page, click Sign in with passkey
- Your browser will show available passkeys for this site
- Select your passkey and verify with biometrics/PIN
- You're signed in — no email or password needed
After your first passkey sign-in, the login page will remember your preference and show the passkey button prominently.
Using Passkeys as MFA
If you have both a password and a passkey:
- Sign in with your email and password
- On the MFA page, click Verify with passkey (instead of entering a TOTP code)
- Verify with biometrics/PIN
New Account Setup with Passkeys
When you receive an invitation email:
- Click the invitation link
- Choose Create a passkey (recommended)
- Follow the browser/OS prompt
- You're signed in with a passwordless account
You can also choose "Set a password" if you prefer traditional credentials.
Managing Your Passkeys
Go to Profile & Security → Security tab → Passkeys to:
- View all registered passkeys with their names and last used dates
- Rename a passkey by clicking the pencil icon
- Add additional passkeys (recommended: register at least 2 devices)
- Remove a passkey by clicking the trash icon
We recommend registering passkeys on at least two devices (e.g., laptop + phone). This ensures you can still sign in if one device is unavailable.
Recovery
If you lose access to all your passkeys:
- If SSO is configured: Sign in with Google SSO or your organization's identity provider
- If no SSO: Contact your administrator to send a new invitation link
Troubleshooting
"Sign in with passkey" button not visible
- Your browser may not support WebAuthn. Use a modern browser (Chrome 67+, Firefox 60+, Safari 14+, Edge 18+).
- Passkeys may not be enabled on your Proxima Console instance. Contact your administrator.
Passkey verification fails
- Make sure you're on the correct domain (check the URL bar)
- Try a different passkey if you have multiple registered
- Clear the browser's WebAuthn cache and try again
Cannot delete last passkey
If you're on a passwordless account, you must either register another passkey or set a password before removing the last one. This prevents account lockout.