Passkey
A phishing-resistant WebAuthn sign-in credential on a Truestamp account, approved with Touch ID, Face ID, Windows Hello, or a security key, completing sign-in in one usernameless step that skips the TOTP prompt; added, renamed, and removed from the profile page.
Overview
A passkey is a passwordless, phishing-resistant sign-in credential built on the WebAuthn web standard: a cryptographic key pair whose private half never leaves your device, approved with Touch ID, Face ID, Windows Hello, a device PIN, or a hardware security key. Signing in is a single usernameless step: you do not type your email first, you pick the passkey your browser holds for Truestamp and approve it, and that one approval completes the sign-in with no password and no TOTP code: approving a passkey takes both possession of your device and a verifying gesture (a fingerprint, face, or device PIN), so it already stands in for the second factor. A passkey is bound to the genuine Truestamp domain, so a look-alike site can never trigger it. You add, rename, and remove passkeys from the security section of your profile; a passkey cannot register a new account, and password and magic link sign-in always remain as fallbacks, so removing every passkey can never lock you out. The full story is in passkeys, with the surrounding sign-in flow in signing in to Truestamp.