Add a passkey
A passkey replaces your password with a credential held by your device, password manager, or security key. It cannot be phished or reused elsewhere, because it is bound to ScatterSpoke and never leaves the authenticator that holds it.
Passkeys are per-account and available on every plan, managed on Settings → Account.
Add one
Section titled “Add one”Open Settings → Account and find the Passkeys card under Sign-in & security. Select Add passkey.
Your browser takes over from there, offering whichever authenticators it knows about — Touch ID, Face ID, Windows Hello, 1Password or another password manager, or a hardware security key. Complete the prompt and the passkey appears in the list with the date it was created.
The button reads Opening… while the browser prompt is up. If you dismiss the prompt, nothing is registered and you can simply try again.
Sign in with it
Section titled “Sign in with it”Go to the ScatterSpoke login page and put the cursor in the email field. Your browser offers any passkeys it holds for ScatterSpoke; pick one, complete the device prompt, and you are signed in — no password, no separate button to press.
This uses WebAuthn conditional UI, which the browser drives. If your browser does not support it, the passkey prompt simply does not appear and password or SSO sign-in works as normal.
Remove one
Section titled “Remove one”Each registered passkey has a trash button. Removing it revokes that credential for your ScatterSpoke account.
Delete the passkey from the device or password manager too, or it lingers there as a dead entry.
Removing a passkey is not the same as revoking a session. If you are removing one because a device was lost, also sign out other sessions from the Sessions panel further down the same page.
Passkeys and two-factor authentication
Section titled “Passkeys and two-factor authentication”They solve different problems and it is worth keeping both.
- A passkey replaces the password at sign-in.
- Two-factor authentication protects the password path that still exists — for you, for an administrator using SSO recovery, or on any browser where the passkey is unavailable.
Your account page scores both: registering a passkey and turning on 2FA together take the posture score to its maximum. Both are also offered during onboarding, before you invite anyone else to the workspace.