Using passkeys

Passkeys are a more secure replacement for passwords that let you log in with your face, fingerprint, PIN, or screen lock. They allow you to log in to an account without entering a password, and are designed to be faster and simpler than a password. Using passkeys removes the possibility of forgetting and needing to reset a password, or entering the wrong password and becoming locked out of your account.

Using a passkey can help you avoid phishing scams, as well as having your password stolen.

You can add a passkey using any method that you use to unlock your device, such as a fingerprint or face recognition, or a device PIN. Learn more about passkeys and two-step authentication.

Where a passkey is saved

A passkey works the same way wherever it's saved. What changes is which devices you can use it on. In the Passkeys section of the Security tab, a passkey is marked Synced across devices or Only on device when that information is available.

  • Synced across devices: The passkey is saved to a password manager, such as iCloud Keychain or Google Password Manager. You can use it on any device where you're logged in to that password manager, and it survives a lost or replaced device.
  • Only on device: The passkey is saved on that device alone and never leaves it, so you can use it only on that device. If you expect to log in from a computer that doesn't have your password manager or a passkey of its own, then create a passkey on a second device and keep it on your phone.

Moving between your phone and your computer is a common reason to check where a passkey is saved. A passkey shown as Synced across devices is available on both, when you're logged in to the same password manager on each. A passkey saved only on your phone can still be used to log in on a computer by using a passkey from another device, and the passkey stays on your phone. If you log in from the same computer often, then create a passkey on that computer as well, so that you don't need to scan a QR code each time.

Passkeys and two-step authentication

A passkey replaces your password. It isn't a two-step authentication method, and the two are set up and removed separately.

  • Adding or removing a passkey doesn't change the two-step authentication methods on your account.
  • Adding or removing a two-step authentication method doesn't change the passkeys on your account.

Set up two-step authentication in addition to your passkey. It gives you a second way to verify your account when your passkey isn't available, and it keeps your account secure however you log in.

Create a passkey

You can create more than one passkey, and save them on different devices or platforms. Create a second passkey as a backup. If you lose access to the device or password manager that holds your only passkey, then a second passkey is what keeps you from being locked out of your account. Learn more about where a passkey is saved.

You need a verified email address to create a passkey. If your email address isn't verified, then the Create passkey button is unavailable and you're prompted to verify your account email first.

Steps:

Desktop
  1. From your Shopify admin, click your store name.

  2. Click your profile, and then click Security.

  3. In the Passkeys section, click Create passkey.

  4. If you're prompted for verification, verify your account, and then click Next.

  5. In the browser prompt, click Continue, and then authenticate by using any method that you use to unlock your device, such as Windows Hello or Touch ID.

  6. Optional: To add a backup, create a passkey on a second device.

Mobile
  1. From the Shopify app, tap your account icon in the upper-right corner.

  2. Tap Menu > Manage account.

  3. Tap Security.

  4. In the Passkeys section, tap Create passkey.

  5. If you're prompted for verification, verify your account, and then tap Next.

  6. Tap Continue, and then confirm with Face ID, fingerprint, or your device passcode or screen lock.

  7. Optional: To add a backup, repeat these steps on another device that you use to log in, such as your computer.

After a passkey is created, it's added to the Passkeys section of the Security tab of your Shopify account, along with the date that it was created and where it's saved.

Create a passkey on a second device

Keeping a passkey on more than one device means that you aren't locked out when you lose access to the first one. This matters most when your only passkey is saved on a computer, because a passkey that's saved only on a computer can't be used to log in anywhere else. Start these steps on a computer, and keep the phone or tablet that you want to save the passkey to nearby, because it needs to scan a QR code.

Steps:

  1. From your Shopify admin, click your store name.

  2. Click your profile, and then click Security.

  3. In the Passkeys section, click Add another passkey.

  4. In the browser or device prompt, choose the option to save the passkey another way, such as Save another way.

  5. Choose the option to use another device, such as Use a phone or tablet.

  6. Turn on Bluetooth on both devices, scan the QR code with the device that you want to save the passkey on, and then follow the prompts on that device.

Log in with a passkey

From the Shopify login page, use one of the following methods to log in:

Use Sign in with passkey

You can use the Sign in with passkey flow to quickly and securely log in to your Shopify account using a saved passkey.

Steps:

Desktop
  1. Click Sign in with passkey to open an autofill dialog box.
  2. Click the saved passkey that you want to use. If you're prompted, then use your Touch ID.
Mobile
  1. Tap Sign in with passkey.
  2. Tap the saved passkey. If you're prompted, then confirm with Face ID, fingerprint, or device passcode.

Use your email address

You can enter your email address and then log in with a passkey.

Steps:

Desktop
  1. Enter your email address and click Continue with email.
  2. Select the passkey that you want to use. If you're prompted, then use your Touch ID.
Mobile
  1. Enter your email address and tap Continue with email.
  2. Tap the saved passkey.

Use a passkey from another device

Steps:

Desktop
  1. On your device, attempt to log in with a passkey.
  2. From your browser prompt, choose the option to use a passkey from another device, and then follow the on-screen instructions to display a QR code on the screen.
  3. Using the mobile device where your passkey is saved, scan the QR code.
  4. To log in faster next time, create a passkey on the computer that you're using.
iPhone
  1. On your device, tap Sign in with passkey.
  2. If required, tap Other options or similar, and then follow the on-screen instructions to display a QR code.
  3. Use the device that has your passkey to scan the QR code.

For more details, follow the instructions provided by Apple.

Android
  1. On your device, tap Sign in with passkey.
  2. When prompted, choose to use a passkey from another device to display a QR code.
  3. Use the device that has your passkey to scan the QR code.

If you want to log in on a different device using the passkey stored in Chrome, then follow the instructions provided by Google.

Verify your account with a passkey

Some actions in the Shopify admin ask you to verify your account before you can complete them, such as changing your security settings. Verifying isn't the same as logging in. The prompt asks for the most secure sign-in method that's set up on your account, so it can offer different options than the login page does.

  • If your account has both a passkey and a two-step authentication method, then you can use either one to verify.
  • If a passkey is the only secure sign-in method on your account, then it's the only way to verify. To clear the prompt when you can't use the passkey, remove the passkey.

Learn more about troubleshooting verification prompts in the Shopify admin.

Remove a passkey

You can remove a passkey from the Security tab. To complete the removal, you might be prompted to verify your account. If a passkey is your only secure sign-in method and your account is required to have one, then you can't remove it until you set up an alternative method.

If a passkey was created for you automatically, then removing it from the Security tab also stops another one from being created for you the next time that you log in.

When you're logged in to your account

Steps:

Desktop
  1. From your Shopify admin, click your store name.

  2. Click your profile, and then click Security.

  3. In the Passkeys section, click Remove beside the passkey that you want to remove.

  4. If you're prompted, then verify your account using one of the methods that's set up on your account.

Mobile
  1. From the Shopify app, tap your account icon in the upper-right corner.

  2. Tap Menu > Manage account.

  3. Tap Security.

  4. In the Passkeys section, tap Remove beside the passkey that you want to remove.

  5. If you're prompted, then verify your account using one of the methods that's set up on your account.

When you're logged out of your account

If you can't use the passkey that you want to remove, then log in with a method that still works, and then remove the passkey.

Steps:

  1. From the Shopify login page, enter your email address and click Continue with email.
  2. Click Log in using a different method, and then choose another method that's set up on your account: your password, a one-time code sent to your email address, or a third-party login service such as Sign in with Google or Sign in with Apple.
  3. After you log in, remove the passkey from the Security tab.

If none of your login methods work, then reset your password. Resetting your password removes the passkeys on your account, and any third-party login services such as Sign in with Google or Sign in with Apple, which you can add again after you log in. If you created your account with a third-party login service and never set a password, then there's no password to reset, and the login page doesn't show Forgot password?. Learn more about troubleshooting logging in when you can't use your passkey.

Troubleshooting passkeys

A passkey works only where it's saved, so most passkey problems come down to the device, browser, or password manager that you're using. Check where your passkey is saved first, and then select the problem that you're experiencing.

Troubleshoot a passkey that isn't offered when you log in

If your passkey isn't offered when you try to log in, then it isn't available on the device, browser, or password manager that you're using. A passkey works only where it's saved. Learn more about where a passkey is saved.

Steps:

  1. If you saved the passkey to a password manager, then make sure that you're logged in to that password manager on the device that you're using, and that it's turned on for passkeys.
  2. If you saved the passkey to a computer, then use that computer to log in. A passkey that's saved only on a computer can't be used to log in on another device.
  3. If you saved the passkey to a phone or a tablet, then you can use it to log in on a computer by scanning a QR code. Learn more about using a passkey from another device.
  4. If the error This passkey was either deleted or removed after a password reset. Use another login method to continue. is displayed, then the passkey is no longer on your account. Log in with another method, and then create a passkey.
  5. If you no longer have the device that the passkey was saved on, then refer to troubleshoot a lost device that had your passkey.
Troubleshoot creating a passkey

If the Create passkey button is unavailable, if the prompt closes without saving a passkey, or if the error Adding a passkey is unavailable. Try with a different browser or choose another method. is displayed, then check the requirements for creating a passkey.

Steps:

  1. Make sure that your email address is verified. Until it's verified, the Create passkey button is unavailable. Learn more about how to verify your account email.
  2. Make sure that your browser supports passkeys. Learn more about the platforms and operating systems that currently support passkeys.
  3. Make sure that your device has a screen lock set up, such as a fingerprint, face unlock, or a PIN. On a PC this is Windows Hello, and on a Mac it's Touch ID. Without a screen lock, your browser can't save a passkey to the device.
  4. If the computer that you're using doesn't have a screen lock, then create a passkey on a second device instead, and save it to your phone.
Troubleshoot a verification prompt that won't accept your passkey

Some actions in the Shopify admin ask you to verify your account, and the prompt asks for the most secure sign-in method that's set up on your account. Verifying isn't the same as logging in, so the prompt can offer different options than the login page does.

Steps:

  1. If your account has a two-step authentication method as well as a passkey, such as an authenticator app, then use that method to clear the prompt. The options that are offered depend on what's set up on your account.
  2. If a passkey is the only secure sign-in method on your account, then the prompt can be cleared only by using the passkey. To clear it, remove the passkey from your account.
  3. Refer to troubleshoot verification prompts in the Shopify admin for more information.
Troubleshoot logging in when you can't use your passkey

A passkey is one of several ways to log in, so start with another method that's set up on your account.

Steps:

  1. From the login page, enter your email address, click Continue with email, and then click Log in using a different method. Choose another method that's set up on your account: your password, a one-time code sent to your email address, or a third-party login service such as Sign in with Google or Sign in with Apple.
  2. After you log in, remove the passkey that you can't use, and then create a new one.
  3. If none of your other login methods work, then reset your password. Resetting your password removes the passkeys on your account, and any third-party login services, which you can add again after you log in.
  4. If you created your account with a third-party login service, such as Sign in with Google or Sign in with Apple, and you never set a password, then there's no password to reset and the login page doesn't show Forgot password?. Log in with that service to remove the passkey.
  5. If you can't log in after trying these steps, then contact Shopify Support.
Troubleshoot a lost device that had your passkey

If the device that holds your passkey is lost, broken, sold, or reset, then whether you can still use the passkey depends on where it was saved.

If the passkey is saved to your password manager and not only to that device, then log in to the same password manager on another device, and then use the passkey there. If the passkey is saved on that device alone, then log in with another method that's set up on your account, such as your password or a third-party login service, and then remove the passkey and create a new one.

If the passkey was your only way to log in, then refer to troubleshoot logging in when you can't use your passkey. Learn more about where a passkey is saved.

Troubleshoot a passkey that you don't recognize

You might see a passkey in the Passkeys section that you don't remember creating, or get an email telling you that a passkey was created. There are two reasons that this happens, and they need different actions.

Steps:

  1. If a passkey was created for you, then it's in your own password manager account. A passkey can be created for you when you log in and an eligible password manager, such as iCloud Keychain or Google Password Manager, upgrades your password to a passkey. To stop this, remove the passkey from the Passkeys section of the Security tab. Resetting your password removes your passkeys, but it doesn't stop a new one from being created the next time that you log in.
  2. If you think the passkey is the result of unauthorized activity and you can still log in, then remove the passkey. Review your account for activity that you didn't carry out, such as logins that you don't recognize, changes to your email address or two-step authentication, staff accounts that you didn't add, or changes to your bank or payout details. Learn more about account security best practices.
  3. If you can't log in, then contact Shopify Support.