Pular para o conteúdo
HeartBadge docs

Passkeys

Live

How to register and safely use a passkey with HeartBadge.

A passkey lets HeartBadge ask a trusted device or security key to approve a supported action. Depending on your device, approval may use a PIN, fingerprint, face recognition, or hardware security key. Biometric data stays with your device or passkey provider; HeartBadge receives only the cryptographic confirmation needed to verify the passkey.

What a passkey is used for

  • Stronger account security. A passkey provides a stronger check than an email code alone.
  • Approving supported actions. The dashboard may request a passkey before sending rewards or changing security settings.
  • Phishing resistance. A passkey is bound to the site where it was registered, making copied sign-in pages less useful to an attacker.

Register a passkey

  1. Sign in to your HeartBadge dashboard.
  2. Open Account Security.
  3. Choose Add passkey.
  4. Approve the registration with your device or hardware security key.
  5. Return to Account Security and confirm the passkey appears as active.

Choose a passkey you can recover

Passkeys can be stored on a single device, synchronized by a platform account, or kept on a hardware security key. The recovery behavior depends on the option you choose. Before relying on a synchronized passkey, make sure you understand how you would recover the platform account that stores it.

Passkey or authenticator 2FA?

Both improve security, but they are not interchangeable for every action. The dashboard shows which method is accepted. Sending rewards generally requires a verified email plus a passkey or authenticator 2FA, while certain destination changes may require authenticator 2FA specifically.

Managing passkeys

  • Add a replacement passkey before removing access to an old device.
  • Remove passkeys for devices you no longer control.
  • Do not approve a passkey prompt you did not initiate.
  • Use both a passkey and authenticator 2FA when possible.

If a passkey is unavailable

Try another registered passkey or an accepted authenticator method. If you cannot access any registered security method, contact support@heartbadge.com. Support will never ask you to disclose a passkey, device PIN, fingerprint, or face scan.