Home
Home/resources/passkeys on the invoance dashboard
Ed25519 signaturesSHA-256 hashes8 SDKs
Status
Sign inStart free
Home
SecurityPasskeysWebAuthnDashboard

Passkeys on the Invoance Dashboard: Phishing-Resistant Sign-In With One Touch

You can now sign in to Invoance with a passkey instead of a password. One touch proves the device and the person holding it, the key only answers to invoance.com, and your password stays as the way back in. Here is how it works and how to set it up.

Adeola OkunolaFounder, Invoance7 October 2026·6 min read
On this page
  1. What changed
  2. How a passkey sign-in works
  3. Why it replaces the password and the code, not just the password
  4. Adding a passkey
  5. Signing in
  6. The details that matter for an evidence product

How a passkey sign-in works

WebAuthn · RP invoance.com
Your device

Private key

Created when you add the passkey. Stays on the device or in your synced keychain.

Local check

Touch ID, Face ID, Windows Hello, a PIN or a security key confirms it is you, on the device.

Never sent
  • private key
  • fingerprint, face, PIN
  • password
Browser

Origin check

The passkey answers only to invoance.com. A look-alike site gets no prompt and no signature.

Relying party

invoance.com

On the wire
challenge
32 random bytes, used once
assertion
a signature over that challenge
Invoance

Public key

Stored when you add the passkey. It can check a signature but cannot make one.

Checked every time
  • signature matches the key
  • challenge unused, < 5 min
  • origin is invoance.com
  • user was verified
  • counter not rolled back

Session issued

  1. 01ChallengeInvoance to browser
  2. 02Confirm it is youBrowser to your device
  3. 03Signature, nothing elseYour device to Invoance
One touch covers both factors: the device, and the person holding it.invoance.com
What each side holds and checks. Only a single-use challenge and a signature over it cross the network.

What changed

The Invoance dashboard now accepts a passkey as a way to sign in. On the login page there is a button that reads Sign in with a passkey, and in Settings there is a card where you add, rename and remove the passkeys on your account. It is available to every user on every plan, alongside the password you already have and the Sign in with Microsoft option that shipped the same week.

A passkey replaces the password step, and because of how it works it also replaces the authenticator code. If you have two-factor authentication switched on, a passkey sign-in does not ask for the six digits. The rest of this post explains why that is sound, how to set one up, and what we did underneath so the result holds up for a product whose job is evidence.

How a passkey sign-in works

When you add a passkey, your device creates a key pair. The private half never leaves the device, or your synced keychain if you use iCloud Keychain, Google Password Manager or a password manager such as Bitwarden or 1Password. Invoance stores only the public half.

To sign in, our server sends your browser a one-time challenge. Your device asks you to confirm it is you, with Touch ID, Face ID, Windows Hello, a PIN or a security key, and then signs the challenge with the private key. The server checks the signature against the public key it stored when you added the passkey. Nothing reusable crosses the wire, so there is nothing to phish, nothing to leak from our database that would let anyone sign in as you, and nothing to brute-force.

The key is also bound to invoance.com. A look-alike site on another domain cannot ask your browser for it. The browser refuses before you ever see a prompt, which is the property that makes passkeys phishing-resistant rather than merely convenient.

Invoance never sees your private key and never sees your biometric. The device checks you locally and sends a signature. We store a public key and a counter.

Why it replaces the password and the code, not just the password

Two-factor authentication exists to prove two independent things: that you know a secret, and that you hold a particular device. A password covers the first and a time-based code from an authenticator app covers the second.

A passkey sign-in on Invoance requires what the standard calls user verification. The authenticator must confirm the person with a biometric or a PIN before it signs anything, and our server rejects an assertion that was made without that confirmation. One touch therefore proves both that you hold the device and that the person holding it is you. Those are the same two factors the password-plus-code flow proves, obtained with less friction and without a code that can be relayed to a fake site. Asking for the six digits on top would add a step without adding security, so we do not.

Your password and your authenticator stay on the account unchanged. They remain the way back in if a device is lost, and they are still what the password route uses. Nothing is removed by adding a passkey.

Adding a passkey

Open Settings, then the Security section, and click Add passkey in the Passkeys card. Give it a name, your device's name is suggested, and click Create passkey. Your device shows its own prompt, you confirm, and the passkey appears in the list with the date it was added and whether it is synced across your devices or bound to this one.

Adding a credential adds a way into your account, so it needs recent proof that it is you. If you signed in within the last ten minutes, the prompt opens straight away. Later than that, the card asks for your password first. Accounts that sign in with Microsoft and never set a password are offered Continue with Microsoft instead, which brings you back to Settings with a fresh session.

From the same card you can rename a passkey or remove it. Removing one takes effect immediately; a removed passkey can no longer sign in, and the same device can be added again later if you change your mind. You can keep up to ten.

Signing in

On the login page, click Sign in with a passkey. If you have already typed your email, the prompt is scoped to that account's passkeys. If you have not, your browser lists the passkeys it holds for invoance.com and you pick one. On browsers that support it, clicking into the email field also offers your passkey from the autofill menu, so the whole sign-in can be a single touch.

If you keep passkeys in a password manager such as Bitwarden or 1Password, its prompt may appear before your device's own; either one can hold your Invoance passkey. Closing the prompt simply cancels, and the password route stays available.

app.invoance.com/login

Sign in to your account

Access your Invoance workspace securely.

Email addressyou@company.com
Remember my email
Continue
or
Sign in with a passkeyContinue with Microsoft

Don’t have an account? Get access

The sign-in page. The passkey button works with or without an email typed; the same button appears on the password step.

The details that matter for an evidence product

Every passkey is bound to invoance.com, the same identifier on every Invoance host, so a passkey you add today keeps working wherever the dashboard lives.

Every sign-in challenge is single use and expires after five minutes. A replayed assertion is rejected, and so is an assertion from a different origin, even if the signature is valid. Hardware security keys also keep a sign counter, and if one presents a counter that has not advanced, the usual sign of a cloned key, the sign-in is refused.

Passkey events are written to your organization's activity log: each passkey added, renamed or removed, and each sign-in, with the device and IP address. A rename records both the old name and the new one. The Analytics page counts a user with a passkey as having a strong sign-in alongside users with an authenticator app, so the security posture score reflects it.

Your integration does not change. API keys, SDKs, proof responses and verification work exactly as before; passkeys protect the people who manage them.

  • Open Settings and add a passkey Signed-out visitors land on the login page first and return to Settings afterwards.
  • Security What we sign, what we store, and how the dashboard protects an account.
On this page
  1. What changed
  2. How a passkey sign-in works
  3. Why it replaces the password and the code, not just the password
  4. Adding a passkey
  5. Signing in
  6. The details that matter for an evidence product
Adeola Okunola

Adeola Okunola

Founder, Invoance
About the author

I'm Adeola, founder of Invoance.

I build proof infrastructure for audit logs, AI attestations, and business records that need to stand up to security, compliance, and legal scrutiny.

Most systems document what happened. Invoance helps prove it.

All articles by Adeola
Related product

Event Ledger

An append-only, signed record of the business events you may need to prove later.

Open Event Ledger
Keep readingAll articles
Compliance12 min read

SOC 2 Compliance: The Complete Guide for Modern Organizations

SOC 2 has become the baseline trust standard for SaaS companies and service providers. This guide covers the trust service criteria, audit types, preparation strategies, and how verifiable evidence closes the gap between controls and proof.

Adeola Okunola·7 March 2026Read
Certification12 min read

ISO 27001: The Complete Guide to Certification

ISO 27001 is the international gold standard for information security management. This guide covers the ISMS framework, Annex A controls, certification process, and how verifiable evidence strengthens your security posture beyond checkbox compliance.

Adeola Okunola·2 March 2026Read
Trust Infrastructure11 min read

Building Trust: The Complete Guide for Digital Organizations

Trust is the invisible infrastructure of every business relationship. This guide breaks down what trust actually means in digital organizations, why it erodes, and how to build verifiable trust through transparency, security, and cryptographic proof.

Adeola Okunola·6 March 2026Read

Try it on the free plan.

Create a signed record and verify it yourself.

Start freeRead the docs

Proof infrastructure. Records are hashed, signed with your organization's Ed25519 key, and stored append-only, so anyone can check them later.

Products

  • Audit Logs
  • Event Ledger
  • AI Attestation
  • Document Anchoring
  • Traces

Developers

  • Documentation
  • API reference
  • SDKs
  • How it works
  • How traces seal
  • System status

Verify

  • Audit Log
  • Event
  • AI Attestation
  • Document
  • Trace

Company

  • Company overview
  • What is Invoance
  • Pricing
  • Security
  • Compliance teams
  • Finance teams
  • Partners
  • Resources
  • Help center
  • Contact
© 2025 – 2026 Invoance, Inc. All rights reserved.© 2026 Invoance, Inc. All rights reserved.
PrivacyLegal noticeLegal FAQ