Passkeys and Sign-In Security

Docuslice signs you in with Google, Apple, or an email and a one-time pin. A passkey is a fourth option, and it is the fastest and the most resistant to phishing.

What a passkey is

A passkey is a credential stored on your device and unlocked by whatever already unlocks that device — Face ID, Touch ID, a fingerprint, Windows Hello, your screen lock, or a hardware security key.

There is nothing to remember and nothing to type. There is also nothing to steal in transit: the secret never leaves your device, so it cannot be phished, intercepted or reused on a fake sign-in page.

Adding one

  1. Sign in as you normally do.
  2. Open the Security screen in your account settings.
  3. Choose to switch to a passkey and confirm with your device unlock.

Add one per device you regularly use. Where your platform syncs passkeys — an Apple or Google account, or a password manager — one passkey may already work across several of your devices.

What enrolling actually changes

Switching to a passkey turns the emailed pin off. From then on your account signs in with the passkey, and requests for a one-time pin are refused. That is the point — the pin is the weakest route into an account, and closing it is most of the security benefit.

So before you enrol, know your fallback:

  • Google or Apple sign-in still works if your account is linked to one. This is the recovery path if you lose the device.
  • Passkeys synced through your Apple or Google account, or a password manager, survive a lost device because the passkey is not only on that device.

You can remove a passkey from the same screen, with one exception: you cannot remove the last one while your account is set to sign in with passkeys. Add another, or switch your sign-in method back, first.

Two-factor

The Security screen also offers a two-factor mode: passkey and an emailed pin, both required. It is the strongest option and the slowest. Turning it on or off asks for an emailed code either way, so neither direction can be flipped by someone who only has your unlocked device.

Signing in with a passkey

Choose Sign in with a passkey and confirm with your device unlock. No email, no pin, no waiting for a message.

A one-time pin you did not request

If a pin arrives that you did not ask for, someone typed your email address into the sign-in screen.

Your account is not compromised. A pin on its own does nothing — it has to be entered by whoever holds the mailbox it was sent to, and it expires. Ignore the email and no sign-in happens.

What is worth doing:

  • Do not forward the pin to anyone. No support process will ever ask you for it.
  • Switch to a passkey, which closes the pin route into your account altogether.
  • If the emails keep arriving, tell us at [email protected] — repeated requests are a signal we want to see.

Keeping the account secure

  • The Security screen can sign you out of other devices, or all of them at once. That is the first thing to do if a device is lost or stolen.
  • Review your registered devices occasionally and remove any you do not recognise.
  • Your account holds your plan and preferences. It does not hold your projects — those are on the device that made them and are never uploaded. See projects and where your work is saved.