On this page
How a passkey sign-in works
WebAuthn · RP invoance.comPrivate key
Created when you add the passkey. Stays on the device or in your synced keychain.
Local check
Touch ID, Face ID, Windows Hello, a PIN or a security key confirms it is you, on the device.
- private key
- fingerprint, face, PIN
- password
Origin check
The passkey answers only to invoance.com. A look-alike site gets no prompt and no signature.
invoance.com
- challenge
- 32 random bytes, used once
- assertion
- a signature over that challenge
Public key
Stored when you add the passkey. It can check a signature but cannot make one.
- signature matches the key
- challenge unused, < 5 min
- origin is invoance.com
- user was verified
- counter not rolled back
Session issued
- 01ChallengeInvoance to browser
- 02Confirm it is youBrowser to your device
- 03Signature, nothing elseYour device to Invoance
What changed
The Invoance dashboard now accepts a passkey as a way to sign in. On the login page there is a button that reads Sign in with a passkey, and in Settings there is a card where you add, rename and remove the passkeys on your account. It is available to every user on every plan, alongside the password you already have and the Sign in with Microsoft option that shipped the same week.
A passkey replaces the password step, and because of how it works it also replaces the authenticator code. If you have two-factor authentication switched on, a passkey sign-in does not ask for the six digits. The rest of this post explains why that is sound, how to set one up, and what we did underneath so the result holds up for a product whose job is evidence.
How a passkey sign-in works
When you add a passkey, your device creates a key pair. The private half never leaves the device, or your synced keychain if you use iCloud Keychain, Google Password Manager or a password manager such as Bitwarden or 1Password. Invoance stores only the public half.
To sign in, our server sends your browser a one-time challenge. Your device asks you to confirm it is you, with Touch ID, Face ID, Windows Hello, a PIN or a security key, and then signs the challenge with the private key. The server checks the signature against the public key it stored when you added the passkey. Nothing reusable crosses the wire, so there is nothing to phish, nothing to leak from our database that would let anyone sign in as you, and nothing to brute-force.
The key is also bound to invoance.com. A look-alike site on another domain cannot ask your browser for it. The browser refuses before you ever see a prompt, which is the property that makes passkeys phishing-resistant rather than merely convenient.
Why it replaces the password and the code, not just the password
Two-factor authentication exists to prove two independent things: that you know a secret, and that you hold a particular device. A password covers the first and a time-based code from an authenticator app covers the second.
A passkey sign-in on Invoance requires what the standard calls user verification. The authenticator must confirm the person with a biometric or a PIN before it signs anything, and our server rejects an assertion that was made without that confirmation. One touch therefore proves both that you hold the device and that the person holding it is you. Those are the same two factors the password-plus-code flow proves, obtained with less friction and without a code that can be relayed to a fake site. Asking for the six digits on top would add a step without adding security, so we do not.
Your password and your authenticator stay on the account unchanged. They remain the way back in if a device is lost, and they are still what the password route uses. Nothing is removed by adding a passkey.
Adding a passkey
Open Settings, then the Security section, and click Add passkey in the Passkeys card. Give it a name, your device's name is suggested, and click Create passkey. Your device shows its own prompt, you confirm, and the passkey appears in the list with the date it was added and whether it is synced across your devices or bound to this one.
Adding a credential adds a way into your account, so it needs recent proof that it is you. If you signed in within the last ten minutes, the prompt opens straight away. Later than that, the card asks for your password first. Accounts that sign in with Microsoft and never set a password are offered Continue with Microsoft instead, which brings you back to Settings with a fresh session.
From the same card you can rename a passkey or remove it. Removing one takes effect immediately; a removed passkey can no longer sign in, and the same device can be added again later if you change your mind. You can keep up to ten.
Signing in
On the login page, click Sign in with a passkey. If you have already typed your email, the prompt is scoped to that account's passkeys. If you have not, your browser lists the passkeys it holds for invoance.com and you pick one. On browsers that support it, clicking into the email field also offers your passkey from the autofill menu, so the whole sign-in can be a single touch.
If you keep passkeys in a password manager such as Bitwarden or 1Password, its prompt may appear before your device's own; either one can hold your Invoance passkey. Closing the prompt simply cancels, and the password route stays available.
Sign in to your account
Access your Invoance workspace securely.
Don’t have an account? Get access
The details that matter for an evidence product
Every passkey is bound to invoance.com, the same identifier on every Invoance host, so a passkey you add today keeps working wherever the dashboard lives.
Every sign-in challenge is single use and expires after five minutes. A replayed assertion is rejected, and so is an assertion from a different origin, even if the signature is valid. Hardware security keys also keep a sign counter, and if one presents a counter that has not advanced, the usual sign of a cloned key, the sign-in is refused.
Passkey events are written to your organization's activity log: each passkey added, renamed or removed, and each sign-in, with the device and IP address. A rename records both the old name and the new one. The Analytics page counts a user with a passkey as having a strong sign-in alongside users with an authenticator app, so the security posture score reflects it.
Your integration does not change. API keys, SDKs, proof responses and verification work exactly as before; passkeys protect the people who manage them.
