How to set up a passkey on an Avistra website

Every admin on an Avistra website signs in with two things: a code we email to you, and a passkey. The code proves the address is yours. The passkey proves it is really you, so nobody who gets into your email can change your site or see the people on it. This note covers setting one up, adding a second device, keeping your backup codes, and what to do if you lose your phone. If you have not opened the tool before, How to make edits on an Avistra website shows the sign-in.

What a passkey is

A passkey is your fingerprint, your face or your device PIN: the same thing that already unlocks your phone or your computer. It is not a password. There is nothing to remember, nothing to type and nothing to reset. Your device keeps it, and your site only ever sees proof that you used it, never your fingerprint or your face.

Why it is required

A passkey is needed for any change to the site and for anybody's details: names, addresses, payments, registrations. That is true for every admin, including somebody who only looks, and there is no setting that turns it off. Signed in with only the emailed code, you can still look at the site, open Security and send us a support request, but Make an edit is hidden and every panel that shows people asks you to set up a passkey or use it first.

The first time you sign in

After you type the emailed code, a card asks you to Set up a passkey. Choose it and your browser takes over for a few seconds:

  • iPhone or iPad: Face ID or Touch ID, and the passkey is saved to your iCloud Keychain.
  • Android: your fingerprint, face or screen lock, saved to your Google Password Manager.
  • Mac: Touch ID, or your Mac's password if it has no Touch ID.
  • Windows: Windows Hello, which is your face, fingerprint or PIN.

Some browsers also offer to save it on a phone or a security key instead. Either is fine; choose whatever you will have with you.

Then come two short steps.

  • Add another device? If you also make changes from a phone or a second computer, choose Add another device and do the same there, so losing one never locks you out. Or choose Skip.
  • Keep these backup codes. You are shown ten one-time codes, once. Copy them, tick I have kept these, and choose Done.

Setting up a passkey: after the emailed code, the Set up a passkey card and the browser asking for a fingerprint; then Add another device? with Add another device and Skip; then Keep these backup codes, ten codes in two columns, I have kept these ticked, and Done.

You can choose Not now on the first card instead. Until you add a passkey you can look at the site and send us a support request, but not change anything or see members' details. The card asks again next time, and Security, behind the dots, is where you add one whenever you are ready.

Using a phone and a computer

The simplest setup is a passkey on each device you use: your phone and your computer, added one after the other with Add another device. If you would rather keep a passkey only on your phone, most computers can still use it. When the browser asks for your passkey, it offers to use a phone instead and shows a QR code. Scan it with your phone's camera, unlock your phone, and the computer is signed in.

Backup codes

The ten backup codes are for the day you do not have your passkey with you.

  • Each code works once.
  • They are shown once, straight after your first passkey. The site keeps no copy it can show you again.
  • Keep them somewhere that is not your phone: a password manager, or printed and put with your other important papers.
  • Make new codes, in Security, gives you a fresh ten and stops the old ones working. Do it if you have used most of them, or if you think somebody else has seen them.

Security shows how many you have left, for example "7 left".

Signing in after the first time

Every sign-in is the same two steps. Type your email address, type the code we send, then choose Use your passkey and give your fingerprint, face or PIN. If your passkey is on a device you do not have with you, choose Use a backup code instead and type one of your ten.

Security, behind the dots

Choose the dots at the end of the bar, then Security. Everything about how you sign in is here, and nothing in it shows anybody else's details, so it opens even before you have a passkey.

  • Passkeys: each one by device, with the day it was added and the day it was last used. Add another device sets up another; Remove takes one away. Removing your last passkey warns you first, because you would need a new one before you can make changes.
  • Backup codes: how many are left, and Make new codes.
  • Signed in: this device, and every other place you are signed in, with when it was last seen. Sign out ends one of them; Sign out everywhere else ends all but the one you are using.

If you lose your phone

  1. Sign in on another device with the emailed code, then Use a backup code instead.
  2. Open Security. Under Signed in, choose Sign out everywhere else. Under Passkeys, Remove the lost device.
  3. Add your new phone with Add another device when you have it.

If you have no backup code either, ask a full admin on your site to open Admins, behind the dots, and choose Reset their passkeys on your row. You are signed out everywhere and set up a new passkey at your next sign-in. If you are the only full admin, send us a support request and we will help you back in.

A browser that cannot make a passkey

A few older browsers and some shared or locked-down computers cannot make a passkey. The tool tells you so. Set up your passkey on another device, such as your phone, then sign in on this computer with a backup code, or use the phone's QR code described above.

If you get stuck

Support request, in the bar, works before you have a passkey, so it is always there. Say what happened and we will sort it out with you. How to submit a support request on an Avistra website shows how.