Passkeys
Sign in with Face ID, Touch ID, a fingerprint or your device PIN instead of a password. A passkey cannot be phished or reused anywhere else, and your private key is never sent to Hjarni. It is optional, and on every plan.
Add one
- Open Settings, find Passkeys and press Add a passkey.
- Your browser asks where to keep it: this device, your password manager or a hardware key.
- Confirm with Face ID, Touch ID, a fingerprint or your PIN. The passkey appears in the list, named for the device it was made on.
Works with iCloud Keychain, Google Password Manager, Windows Hello, 1Password, Bitwarden, and hardware keys such as a YubiKey.
If you signed in more than ten minutes ago, Hjarni asks you to sign in again first. A passkey is a way into your account, so adding or removing one gets the same care as turning on two-factor authentication: someone who finds your laptop unlocked an hour later cannot add their own. Hjarni emails you whenever a passkey is added or removed. You can hold up to twenty.
Signing in
On the sign-in page, press Sign in with a passkey. Your browser shows the passkeys it holds for hjarni.com; pick your account and confirm on your device. You never type your email address, so there is nothing to mistype and nothing for a fake sign-in page to collect.
The same button is on the screen Claude, ChatGPT and other assistants send you to when you connect them, so connecting an assistant is one tap too.
Your password, and Google, Apple, GitHub or SSO, all keep working. A passkey is an extra way in, not a replacement. The one account it cannot sign in is a member of a team that requires SSO: that team's rule wins, and the passkey button sends you to the SSO sign-in instead.
Two-factor authentication
A passkey sign-in does not ask for a two-factor code, even when you have it turned on. Your device verified it was you before it signed, and the key itself proves the device is yours, so a passkey is already both factors. Password and social sign-ins still ask for the code as before.
Keep two-factor authentication on if you use it. It still protects every sign-in that is not a passkey. See Two-factor authentication.
A lost device
Sign in another way, open Settings and press Remove next to the passkey. Each one shows the date it was added, so you can tell them apart. Hjarni cannot sign in with a passkey without your device confirming it is you, so a lost phone alone does not open your account.
One kept in iCloud Keychain, Google Password Manager or a password manager is on your other devices as well, and comes back on a new one when you sign in to that account.
Lives on that key only. Remove it from Settings and add a new one.
Remove it, change your password, and reply to the email Hjarni sent when it was added. Resetting your password signs out every session but does not remove passkeys, so remove it first.
Where it works
Where
- hjarni.com in Safari, Chrome, Edge and Firefox, on a computer or a phone.
- The iPhone, iPad, Mac and Android apps, from their latest version.
- The sign-in page, and the connect screen for Claude, ChatGPT and other assistants.
- Every plan, Free included.
No button?
- In the app, update to the latest version. Earlier versions keep their current sign-in.
- On Android, the phone's Android System WebView also needs to be up to date.
- Browsers without passkey support show no button; the other ways to sign in are unchanged.
A passkey is bound to hjarni.com. Claude, ChatGPT and other connected assistants use separate credentials, and so do API tokens; adding or removing a passkey does not touch them. To cut one off, revoke it in Settings > Connections.
Common questions
FAQ
What is a passkey?
A sign-in key stored on your device or in your password manager. Your device confirms it is you with Face ID, Touch ID, a fingerprint or a PIN, and signs a one-time challenge from Hjarni. Nothing reusable is sent to Hjarni, and the key only works on hjarni.com, so a look-alike site cannot use it.
Is it a Pro feature?
No. Passkeys are on every plan, Free included.
Where can I use one?
On hjarni.com in any current browser, including the screen Claude and ChatGPT send you to when you connect them. The iPhone, iPad, Mac and Android apps support them from their latest version; update the app if you do not see the button.
Do I still need my password?
Keep it. A passkey is an extra way in, not a replacement, and you need a fresh sign-in to add or remove passkeys. You can keep using Google, Apple, GitHub or SSO as well. If your team requires SSO, that rule wins and a passkey sign-in is refused.
Does it ask for my two-factor code?
No. Your device already verified it was you before it signed, so a passkey counts as both factors. Password and social sign-ins still ask for the code as before.
What if I lose the device?
Sign in another way, open Settings and remove the passkey. A synced passkey (iCloud Keychain, Google Password Manager, 1Password) is also on your other devices and comes back on a new one. Hjarni cannot use a passkey without your device, so a lost phone alone does not expose your account.
Will my ChatGPT or Claude connection stop working?
No. Connected assistants and API tokens use their own credentials and are not affected by adding or removing a passkey.
Related docs
Questions about signing in?
Email evert@hjarni.com
Give your AI a memory. Free.
Connect Claude or ChatGPT to notes they can actually read and write.
Give your AI a memory. Free.