Passkeys let users sign in with a platform authenticator or a roaming security key. The private key stays on the authenticator. Authdog stores the public credential and verifies the WebAuthn ceremony. Enable the method per environment.

## Enable passkeys

In the [Authdog console](https://console.authdog.com):

1. Select the project and environment.
2. Open **Authentication > Methods**.
3. Enable **Passkeys**.

No vendor credentials are required. The relying-party ID is the identity host for that environment, including a [custom domain](/docs/custom-domains) when one is in use. A passkey registered on one host does not sign in on another.

Keep another sign-in method enabled. A user who loses every authenticator needs a path back in.

## Register and sign in

Registration requires an authenticated session. A user signs in with another method first, then adds a passkey from the account session. Authentication uses a discoverable credential and local user verification.

Authdog accepts ES256 and RS256 keys and requests no attestation, so the ceremony does not collect device-identifying attestation.

## Test it

1. In development, sign in with email or a social provider.
2. Register a passkey from the authenticated account session. Try a platform authenticator and, if you support them, a security key.
3. Sign out and sign in with the passkey.
4. Cancel the prompt once and confirm the user can fall back to the other method.
5. Repeat in production on the production identity host. A passkey created against the development host will not work there.

## Related

| Read | To learn how to |
| --- | --- |
| [Passkeys](/docs/passkeys) | Registration, verification, and recovery |
| [Authentication](/docs/console/authentication) | Methods on the same screen |
| [Marketplace](/marketplace/passkeys) | The listing for this integration |
