Passkeys and suspicious sign-in verification

Sign in securely without a password using a passkey, and learn what happens when a suspicious sign-in is detected.

A password is the weakest link in any account's security. A passkey replaces it: instead of a password, you sign in with your own device's fingerprint, face, or PIN, and no password is stored or sent anywhere.

Create a passkey

Security settings
Create a passkey in the Security section of your settings
  1. Go to Settings and open the Security section.
  2. Choose Add passkey.
  3. Your device asks for your fingerprint, face, or PIN, the same method you use to unlock it.
  4. Give the passkey a name so you'll know later which device it belongs to.
  5. Create a separate passkey for each device you use regularly.

Sign in with a passkey

On the sign-in page, choose the Passkey option. Your device verifies your identity, and you're signed in without entering your email or password.

Signing in with a passkey
You sign in without entering your email or password

Tip: A passkey is tied to a device. If you switch devices, create a passkey on the new device before you retire the old one, so you have another way to sign in.

Verifying a suspicious sign-in

Taskie evaluates every sign-in, and if it sees unusual signs, such as an unknown device, an unusual location, or a suspicious pattern, it asks for an extra verification step.

  1. The message We noticed an unusual sign-in. appears.
  2. A verification code is sent to your email.
  3. Enter the code and click Verify and continue.
  4. If the code doesn't arrive, click Resend code once the countdown ends.
  5. Use Back to sign in to start over.

Warning: If you get a verification code when you didn't try to sign in, someone has your password. Don't enter the code; change your password right away, close your active sessions, and turn on two-factor authentication.

Use security layers together

Active sessions
Sign out devices you don't recognize
  • Passkey: the most secure everyday sign-in method.
  • Two-factor sign-in: a second layer for when you sign in with a password.
  • Active sessions: review them regularly and sign out devices you don't recognize.
  • Sign-in activity: look through your sign-in history to spot unusual behavior early.

If you lose access

If a passkey was your only way to sign in and you've lost the device, use one of the other methods: sign in with your email and password, sign in with an SMS code, or reset your password. That's why we recommend always keeping more than one sign-in method active.

  • Create a passkey on every device you use regularly.
  • Keep your account password active too, so you have a fallback.
  • Keep your two-factor recovery codes somewhere safe.
  • If you give a device away, remove its passkey and session.

For a second layer, see Two-factor authentication, and to manage sessions, see Secure sign-in, sessions, and sign-in activity.

Was this article helpful?