AddThisFeature

Passkeys

Sign in with device biometrics instead of a password or a code.

involved Security & Reliability

What it adds

WebAuthn credentials registered per device, listed and named by the user, with a defined fallback for browsers and devices that cannot use them.

What your agent is told to do

5
  1. 1

    Let a user register several passkeys and name each one. One passkey on one phone is a lockout waiting to happen.

  2. 2

    Detect support before offering it, and keep the existing sign-in methods visible. Never make a passkey the only credential on an account.

  3. 3

    Verify the assertion on the server — challenge, origin, and signature counter. A client that says authentication succeeded is not evidence.

  4. 4

    Show each credential with its name, creation date, and last-used date, and let the user remove any of them, with reauthentication required to add or remove.

  5. 5

    Do not require the user to know what a passkey is. Label it by outcome — sign in with Face ID, fingerprint, or device PIN — not by protocol.

Edge cases it handles

6
  • Registration must refuse a credential already registered to the account rather than creating a silent duplicate.
  • Removing the last passkey must be allowed only if another usable sign-in method remains.
  • Cross-device sign-in via a QR code and a phone must be an explicit, explained path, not an unlabelled fallback screen.
  • A user who wipes or loses the device keeps stale credential records; make them removable from another signed-in session and via account recovery.
  • A cancelled or timed-out prompt is not a failure — return the user to a working sign-in screen without an alarming error.
  • Synced passkeys appear on new devices without registration; do not assume one credential means one physical device.

Definition of done

8
  • A user can register, name, list, and remove multiple passkeys.
  • Assertions are verified server-side, including challenge and origin.
  • Unsupported browsers fall back to existing sign-in methods without a dead end.
  • Duplicate credential registration is refused.
  • An account can never be left with no usable sign-in method.
  • Cancelled prompts return cleanly to the sign-in screen.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.