Skip to main content
Workspace managementWorkspace admins

Passkeys and trusted devices

Heads up: Passkeys and trusted devices are managed from My account → Security . They protect key material in the browser, separate from SSO identity…

1 MIN READUPDATED SEP 9, 2026
On this page
The account Security page, covering passkeys, two-factor authentication and client-side vault lockout. A This browser panel explains that the browser keeps an encrypted copy of the account keys protected by the operating system account, with a Keep me signed in on this browser toggle that is on by default, and a Require passkey to unlock on this browser toggle for stronger protection where every unlock needs a biometric or security key.
My account, Security - where passkeys and this browser's unlock behaviour are set.

InviziPoll supports WebAuthn passkeys with a strict zero-knowledge rule: the passkey's PRF output never leaves the browser. It acts as a local key-encryption key for vault wrap/unwrap instead of (or alongside) a password.

Managing devices

Navigate to My accountSecurity to view your passkeys and trusted devices, with options to register new devices or revoke existing ones.

Signing in with a passkey

"Sign in with Passkey" is offered on the sign-in page. If your authenticator doesn't support PRF, the app falls back to password-based key derivation.

Onboarding

The setup wizard may prompt you to register a passkey after creating your workspace.

SSO interaction

Enterprise SSO authenticates your identity only - vault access still requires a trusted device, passkey, device handoff, or recovery material. See Recovery, emergency kit, and device handoff.