What are passkeys and which devices and browsers are supported in BoldSign?
Passkeys are a modern, secure and phishing-resistant authentication method that lets you sign in to your BoldSign account without entering a password. Built on the WebAuthn (Web Authentication) standard, passkeys use a cryptographic key pair consisting of a private key stored securely on your device and a public key shared with BoldSign to verify your identity.
This article explains what passkeys are, their benefits, and the devices and browsers supported in BoldSign.
What are passkeys?
A passkey is a digital credential that replaces a password with a cryptographic signature. Instead of entering a password that could be guessed, stolen, or reused, your device authenticates you using one of the following methods:
- Biometric verification — Fingerprint authentication (Touch ID) or facial recognition (Face ID, Windows Hello)
- Device PIN or screen lock — The same PIN, passcode, or pattern used to unlock your device
- Physical security key — A hardware token such as a YubiKey
Each passkey is unique to BoldSign and is associated with the device or platform on which it was created. The private key never leaves your device, helping protect your account even if a service is compromised.
How passkeys work?
- Registration: You create a passkey on your device. The device generates a public-private key pair. The private key remains on your device, while the public key is stored in your BoldSign account.
- Authentication: When you sign in, BoldSign sends a cryptographic challenge to your device. Your device signs the challenge using the private key.
- Verification result: BoldSign verifies the signature using the stored public key and signs you in. No password is transmitted during the authentication process.
Passkeys are sometimes referred to as discoverable credentials or resident keys. The terms are used interchangeably.
Benefits of using passkeys
-
Phishing resistance
Passkeys are tied to the specific website or application for which they were created. A passkey registered for
boldsign.comcannot be used on a fraudulent or lookalike website, helping prevent phishing attacks. -
No password to remember or manage
Passkeys use your device’s biometric authentication or PIN for verification, so you do not need to enter, remember, or reset a password. They also help prevent password reuse across multiple services.
-
Faster sign-in
Signing in with a passkey requires only a biometric scan or PIN entry, eliminating the need to manage passwords or reset forgotten credentials.
-
Cross-device sign-in (roaming)
If your passkey is stored on your mobile device, you can sign in on a nearby computer by scanning a QR code. This works across platforms. For example, an Android passkey can be used to authenticate on a Windows device, and an iPhone passkey can be used to authenticate on a macOS device.
-
Available as both a sign-in method and a TFA option
- Passwordless sign-in: Click Sign in with passkey on the BoldSign sign-in page to sign in without entering a password.
- Two-Factor Authentication (TFA): After entering your email address and password, you can use a passkey as the second authentication factor instead of an authenticator code, SMS OTP, or recovery email code.
-
No shared secrets
Unlike passwords, passkeys never expose a shared secret over the network. The private key never leaves your device, and the cryptographic challenge-response mechanism ensures your credential cannot be intercepted.
-
Reduces account recovery overhead
Because passkeys eliminate forgotten passwords and reduce reliance on email OTPs, users are less likely to require account recovery, saving time for both users and support teams.
Supported devices and platforms
BoldSign passkeys work across a wide range of devices, operating systems, and browsers. The table below shows what is supported.
Operating system and platform support
| Platform | Passkey support |
|---|---|
| Windows 10 (version 1903 or later) | ✅ Supported — Windows Hello (PIN, fingerprint, facial recognition) |
| Windows 11 | ✅ Supported — Windows Hello |
| macOS (Ventura / 13.0 or later) | ✅ Supported — Touch ID, iCloud Keychain |
| iOS / iPadOS (16.0 or later) | ✅ Supported — Face ID, Touch ID, device passcode |
| Android (9.0 or later) | ✅ Supported — fingerprint, face unlock, device PIN, screen lock |
| ChromeOS | ✅ Supported — device PIN, fingerprint |
| Linux | ⚠️ Partial — depends on browser and platform-level credential manager support |
Platform-level passkey support may require additional software or configuration updates. For the best experience, keep your operating system and browser updated to the latest version.
Browser support
| Browser | Passkey support |
|---|---|
| Google Chrome | ✅ Supported |
| Mozilla Firefox | ✅ Supported |
| Apple Safari | ✅ Supported |
| Microsoft Edge | ✅ Supported |
| Opera | ✅ Supported |
| Samsung Internet | ✅ Supported (Android) |
Cross-device (roaming) support
| Scenario | Support |
|---|---|
| Desktop to desktop using a security key (YubiKey, etc.) | ✅ Supported |
| Mobile to desktop using QR code | ✅ Supported — Bluetooth must be enabled on both devices |
| Tablet to desktop using QR code | ✅ Supported — Bluetooth must be enabled on both devices |
| Desktop to mobile using QR code | ✅ Supported — Bluetooth must be enabled on both devices |
Physical security key support
| Key type | Support |
|---|---|
| FIDO2 / WebAuthn USB security keys (e.g., YubiKey 5 Series) | ✅ Supported |
| FIDO2 NFC security keys | ✅ Supported on NFC-enabled devices |
| FIDO2 Lightning security keys | ✅ Supported on iOS devices with Lightning port |
Supported authentication methods by platform
| Platform | Fingerprint | Facial recognition | Device PIN | Security key |
|---|---|---|---|---|
| Windows 10 / 11 | Windows Hello fingerprint | Windows Hello facial recognition | Windows Hello PIN | USB / NFC security key |
| macOS | Touch ID | — | Device passcode | USB / Lightning security key |
| iOS / iPadOS | Touch ID | Face ID | Device passcode | Lightning / NFC security key |
| Android | Fingerprint sensor | Face unlock | Device PIN / pattern / password | USB / NFC security key |
| ChromeOS | Fingerprint (selected devices) | — | Device PIN | USB security key |
Available biometric authentication methods depend on your device’s hardware capabilities. For example, Windows Hello facial recognition requires an infrared (IR) camera, and Touch ID requires a Mac or iOS device with a Touch ID sensor.
Requirements for using passkeys
To register and use a passkey in BoldSign, the following must be in place:
- A BoldSign account where you are signed in.
- A supported device and browser from the tables above.
- A supported authentication method configured on your device — such as a fingerprint enrolled in Windows Hello, Face ID configured on an iPhone, or a device PIN on Android.
- (Optional) A physical security key — if you prefer hardware-based passkey storage, a FIDO2-compliant security key such as a YubiKey.
Frequently asked questions
What happens if I lose my device that has a passkey?
- If your device is lost, you can sign in using another method (email and password, SSO, or another registered passkey) and remove the lost device’s passkey from Settings > My Profile > Passkeys.
- Removing a passkey in BoldSign does not automatically delete it from your device’s keychain. If possible, remove the passkey from your device’s settings as well.
Can I have multiple passkeys on the same BoldSign account?
- Yes. You can register multiple passkeys across different devices and platforms. Each passkey must have a unique name.
Can I use passkeys with older browsers?
- No. Passkeys require WebAuthn support, which is available only in modern browsers. If you are using an outdated browser, upgrade to a supported version listed in the browser support table above.
Can I use a passkey stored on my phone to sign in from a public computer?
- Yes. On the BoldSign sign-in page, click Sign in with passkey and select the option to use a phone or tablet. A QR code appears. Scan it with your phone’s camera and authenticate using your phone’s biometric verification or PIN. Ensure Bluetooth is enabled on both devices.
Do passkeys sync across my devices?
- If you create a passkey using a platform credential manager (iCloud Keychain on Apple devices, Google Password Manager on Android/Chrome, or Windows Hello on Microsoft devices), the passkey may sync across devices signed into the same account. This behavior depends on the platform and its configuration, not on BoldSign.
Does removing a passkey from BoldSign delete it from my device?
- No. Removing a passkey from BoldSign only unlinks it from your BoldSign account. The credential remains stored in your device’s keychain, browser, or password manager (for example, Apple Keychain, Google Password Manager, or 1Password) until you remove it from that system’s settings.
What is the difference between a passkey and a password?
- A password is a shared secret that you create and enter manually. A passkey is a cryptographic key pair stored on your device that authenticates you using biometric verification, a PIN, or a security key. Unlike passwords, passkeys cannot be phished, guessed, or reused across websites.