Running the Business

Passkeys: Signing Into Your Business Without a Password

A passkey replaces your password at sign-in. This guide covers what a passkey is, why phishing can't touch it, and how to set one up for your business.

The password protecting your business account is probably protecting three other accounts too. Somewhere between the email login, the social media login, and that food delivery app, one of them leaked, and the combination now sits in a list that criminals test against everything. For a personal account that's bad. For the account where your money lives, it's a business risk with your name on it.

Passkeys exist to end this whole category of problem. They're already supported on the phones and laptops you own, they take a minute to set up, and they remove the thing attackers actually steal. Here's what a passkey is, in plain language, and why your business account should have one.

What is a passkey?

A passkey is a sign-in method that replaces your password with a cryptographic key stored on your device, approved each time with your fingerprint, face, or device PIN. Nothing is typed and nothing is memorized. The key never leaves your device, and it only works on the genuine website it was created for.

That last property is the quiet superpower, and it deserves its own section.

Why passwords keep failing business owners

Passwords fail in ways that have nothing to do with carelessness and everything to do with being human.

  • Reuse. Nobody remembers forty unique passwords, so people repeat them, and one leaked site exposes the rest.
  • Phishing. A convincing fake login page captures whatever you type into it. Type your real password into a fake page once, and the attacker owns the account.
  • Sharing. Small businesses hand the password to a cousin who "helps with the page", and now the secret lives in two more phones and a chat history.
  • Resets. Forgotten passwords route through email, which means anyone who compromises your inbox inherits everything built on top of it.

Every one of these failures shares a root cause. A password is a secret that must be told to be used, and secrets that get told eventually get overheard.

How a passkey shuts phishing down

With a passkey there is nothing to type, so there is nothing to capture. Sign-in becomes a cryptographic handshake: the site issues a challenge, your device signs it with a private key that never leaves the hardware, and your fingerprint or face simply approves the signing. A fake site gets nothing useful, because the passkey is mathematically bound to the real site's identity and will not respond to an imposter, no matter how convincing the page looks to you.

Notice what this means for the scam texts that plague Jamaican business owners, the "verify your account now" messages with urgent links. A password holder can be tricked into typing the secret. A passkey holder cannot be tricked into handing over a key they cannot see, read, or forward. The human stops being the weak point.

Your biometric data stays home too. The fingerprint or face scan happens on your device, exactly as it does when you open your phone, and is never sent to the website. The site learns only that your device approved the sign-in.

Password managers deserve an honourable mention here, since a good one generates unique passwords and refuses to autofill on a lookalike domain. They fix reuse and blunt phishing, and they remain a fine bridge. A passkey simply goes further by removing the secret entirely, which is why the banks, phone makers, and platform companies are converging on it as the successor rather than a supplement.

Setting up a passkey for your business account

The flow is similar on any platform that supports passkeys, and it's genuinely quick:

  1. Open your account's security settings and choose the option to add a passkey.
  2. Your phone or laptop prompts you to approve with fingerprint, face, or PIN.
  3. Name the passkey so you recognize it later, such as "my phone".
  4. Add a second passkey from another device you own, which is your backup.
  5. Keep another way in available, such as an emailed sign-in code, for when a device isn't to hand.

Inkress has gone further and dropped passwords entirely. You sign in to the dashboard with a passkey, or with a one-time code sent to your email, so the account that holds your sales, payouts, and customer records has no password to leak, phish, or reset. Add a passkey from Settings → Security after your first sign-in.

One habit is worth adopting immediately: register passkeys on two devices. A passkey on your phone plus one on a laptop or tablet means losing either device is an inconvenience rather than a lockout.

Rolling passkeys out across a small team

If more than one person touches the business account, sequence the rollout. The owner goes first, on two devices, so the strongest protection sits on the login with the most power. Then each staff member who genuinely needs access gets their own login with their own passkey, scoped to what their role requires, never a copy of yours.

The leaver's checklist matters as much as the joiner's. When someone exits the business, remove their access the same day, and the passkey model makes that clean. You revoke their login, and nothing they carry in their head keeps working, because nothing was ever in their head. Compare that with the shared-password world, where every departure should trigger a password change and rarely does.

A five-minute access review each quarter, checking who can sign in and removing anyone who no longer should, finishes the job. Small teams skip this because it feels corporate. It's actually the cheapest security work available to a business of any size.

Common worries, answered honestly

"What if I lose my phone?" Sign in from your second device, or with an emailed sign-in code, and remove the lost phone's passkey. This is exactly why the two-device habit exists. Losing a phone with a passkey on it is also safer than losing a phone with a password saved in the notes app, because the passkey still requires your fingerprint or face to use.

"Is my fingerprint being uploaded somewhere?" No. Biometrics never leave the device. The website only receives a yes-or-no confirmation that the device's owner approved.

"My staff need access too." Then staff should have their own access, not a copy of yours. Shared credentials are how businesses lose track of who did what, and a shared secret is only as careful as its least careful holder.

"Which devices support this?" Recent phones, tablets, and laptops across the major platforms hold passkeys natively, and support keeps widening. If a device opens with a fingerprint, face, or PIN, it can almost certainly hold a passkey.

"Passwords have worked fine so far." Survivorship talking. Account takeovers don't announce themselves in advance, and the attacker's first move is usually changing the contact details so recovery gets harder. The time to upgrade the lock is before the burglary, and this particular upgrade is free.

Passkeys are the rare security improvement that's also a convenience improvement. Sign-in gets faster, there's nothing to remember, and the most common attack against your account stops working entirely. The technology behind it is an open industry standard backed by the major device makers, documented plainly at the FIDO Alliance, and the platform where your business banking-adjacent life happens is exactly where it belongs first. How your payments platform protects the payment side is a separate, equally fair question, and our fraud defense overview covers that half.

Protect the account like the asset it is. If your business runs on an Inkress dashboard, adding a passkey takes about a minute in security settings, and if you're not set up yet, registration is where it starts.

Common questions

What is a passkey in simple terms?

A sign-in method that swaps your password for a cryptographic key stored on your device, approved each time with your fingerprint, face, or PIN. Nothing is typed, and the key only works on the genuine site it was created for.

What happens if I lose the phone that has my passkey?

Sign in from a second device where you also registered a passkey, then remove the lost phone's passkey in security settings. Registering passkeys on two devices from the start turns a lost phone into an inconvenience instead of a lockout.

Can a passkey be phished?

Not the way passwords can. There is nothing to type into a fake page, and the passkey refuses to respond to any site other than the genuine one it is bound to, regardless of how convincing the imposter looks.

Does using a passkey share my fingerprint with the website?

No. The biometric check happens entirely on your device, exactly like opening your phone. The website only receives confirmation that the device's owner approved the sign-in.