Skip to main content

Passkeys

Passkeys are a secure alternative to traditional passwords that let you log in to apps and websites without entering a password. Built on the standards set by the [FIDO Alliance](https://fidoalliance.org/overview/), passkeys avoid the vulnerabilities of standard passwords, such as phishing.

Save passkeys in your WALLIX Enterprise Vault and use the browser extension or mobile apps to autofill them across the apps and websites you use every day. Stored passkeys are protected by the same end-to-end encryption as the rest of your vault.

## Page Navigation

- [What are passkeys?](#bkmrk-what-are-passkeys)
- [Save and autofill passkeys](#bkmrk-save-and-autofill-passkeys)
  - [Browser extension](#bkmrk-browser-extension)
  - [iOS](#bkmrk-ios)
  - [Android](#bkmrk-android)
- [View passkeys in your vault](#bkmrk-view-passkeys)
- [Delete a passkey](#bkmrk-delete-a-passkey)
- [Export and import passkeys](#bkmrk-export-and-import-passkeys)

## What are passkeys?

Passkeys are a replacement for passwords that provide fast, easy, and secure sign-ins to websites and apps. A passkey is a discoverable FIDO credential that can either be synced to allow passwordless sign-in across your devices, or dedicated to a single piece of hardware as a device-bound passkey.

Some apps and services may ask that a passkey be verified with a PIN, password, pattern, or biometric factor when you save or use it.

Passkeys are stored and used through the WALLIX Enterprise Vault browser extension and mobile apps. Both discoverable passkeys and non-discoverable FIDO2 credentials can be stored and used to sign in to websites that support passkeys.

**Note:** the browser extension will not offer to save or use a passkey for any domain on your [excluded domains](https://vault-doc.wallix.com/books/entreprise-vault-user/page/browser-plugin) list.

## Save and autofill passkeys

### Browser extension

#### Allow passkeys in the extension

1. Open the WALLIX Enterprise Vault browser extension.
2. Go to **Settings** → **Notifications**.
3. Make sure **Ask to save and use passkeys** is checked.

If there are sites you don't want to use WALLIX Enterprise Vault for passkeys with, add them to your [excluded domains](https://vault-doc.wallix.com/books/entreprise-vault-user/page/browser-plugin).

#### Create a passkey

When you create a new passkey on a website or app, the browser extension will prompt you to store it.

[![image.png](placeholder-create-passkey-extension.png)](placeholder-create-passkey-extension.png)
*Save passkey*

**Note:** select **Use your device or hardware key** if you don't want to store the passkey in WALLIX Enterprise Vault.

Only one passkey can be saved per login item. If a passkey already exists for a service, you can either overwrite it or select the **Add** icon to create a new login item and store an additional passkey.

[![image.png](placeholder-overwrite-passkey-extension.png)](placeholder-overwrite-passkey-extension.png)
*Save passkey with an existing login*

#### Sign in with a stored passkey

1. Make sure **Ask to save and use passkeys** is turned on (**Settings** → **Notifications**).
2. Start the passkey sign-in on the website.
3. In the window that appears, select your saved passkey.

[![image.png](placeholder-login-passkey-extension.png)](placeholder-login-passkey-extension.png)
*Log in with passkey*

You can also authenticate with a passkey directly from the inline autofill menu.

**Note:** if you previously chose **Use your device or hardware key** for a site, WALLIX Enterprise Vault won't offer to save or fill a passkey for it. To change this, remove the site from your blocked domains — the extension will then ask to save the passkey again next time you sign in.

### iOS

Passkeys can be saved and used from WALLIX Enterprise Vault on iOS 17.0 and later.

#### Set up the iOS app for passkeys

1. Open the iOS **Settings** app.
2. Go to **Passwords** → **View AutoFill Settings**.
3. Tap **AutoFill Passwords and Passkeys**.
4. Tap **WALLIX Enterprise Vault** in the list of apps.

#### Create a passkey

When you create a new passkey on a website or app, the mobile app will prompt you to store it. Tap **Continue** to save it.

[![image.png](placeholder-create-passkey-ios.png)](placeholder-create-passkey-ios.png)
*Create a passkey*

**Note:** if you don't want to store the passkey in WALLIX Enterprise Vault, tap **Other Options**.

Only one passkey can be saved per login item. If a passkey already exists for a service, you can overwrite it or select the **Add** icon to create a new login item.

#### Sign in with a stored passkey

Start the passkey sign-in on the website. The app offers to sign in with the passkey stored in your vault — tap **Continue**.

**Note:** to sign in with a passkey that isn't stored in WALLIX Enterprise Vault, select **Other Sign In Options**.

### Android

Passkeys can be saved and used from WALLIX Enterprise Vault on Android 14.0 and later.

**Note:** on Android, passkeys stored in WALLIX Enterprise Vault can only be used as a primary sign-in credential. Android doesn't allow third-party passkey providers to support passkey-based 2FA (non-discoverable credentials).

#### Set up the Android app for passkeys

1. Open the WALLIX Enterprise Vault app.
2. Go to **Settings** → **Autofill**.
3. Tap **Passkey management**.
4. Tap **Continue** — this opens your device's **Settings** app.
5. Configure WALLIX Enterprise Vault as your passkey provider.

#### Create a passkey

When you create a new passkey on a website or app, the mobile app will prompt you to store it. Tap **Create** to save it.

**Note:** if you don't want to store the passkey in WALLIX Enterprise Vault, tap **Save another way**.

Only one passkey can be saved per login item. If a passkey already exists for a service, you can overwrite it or select the **Add** icon to create a new login item.

#### Sign in with a stored passkey

Start the passkey sign-in on the website. The app offers to sign in with the passkey stored in your vault — tap **Sign in**.

**Note:** to sign in with a passkey that isn't stored in WALLIX Enterprise Vault, select **More saved sign-ins**.

## View passkeys in your vault

Saved passkeys can be viewed from any WALLIX Enterprise Vault client (web app, browser extension, mobile apps, desktop app). Open the login item — the **Passkey** field shows the date and time the passkey was created.

**Note:** if [master password re-prompt](https://vault-doc.wallix.com/books/entreprise-vault-user/page/personal-vault) is enabled on the item, you'll be asked to re-enter your master password to access the passkey.

## Delete a passkey

To remove a passkey from a vault item:

1. Open the item's **Edit** screen from the web app, browser extension, or desktop app.
2. Select the **Delete** icon next to the **Passkey** field.
3. Confirm by selecting **Delete**.
4. Select **Save**.

## Export and import passkeys

Passkeys are included in JSON exports of your vault and can be re-imported into a WALLIX Enterprise Vault account the same way as any other export.