standard-passkey / manage

Passkeys

DeviceTypeAddedLast usedState

Enrol on every device you would be upset to be locked out from. Revoking is refused when only one passkey remains — that would leave the recovery key as the only way in.

Recovery key

Shown once and never again. Only a scrypt hash is stored, so this cannot be looked up later. Put it in Keychain now: security add-generic-password -a "$USER" -s WEBAUTHN_PASSKEY_ATSIGN -w

Generating replaces any existing key immediately and resets the lockout counter. Rotate after any use, and after typing it on a machine you do not control.

Protected sites

HostnameModeState

monitor logs what would have been blocked without blocking it. Turning a site on in monitor for a day is how you discover the thing you forgot was depending on it.

Recent activity

WhenEventResultFromDetail