Passkeys
GoodWorkshop has no password. You sign in either through a sign-in link by e-mail or with a passkey. A passkey is a key that lives on your device and that you unlock with your fingerprint, face, device PIN or a security key. The key itself never leaves your device.
The advantage: you don’t have to wait for an e-mail. Especially on your phone in the workshop room, that is often the faster way in.
Create a passkey
Section titled “Create a passkey”- Open the account menu at the top right and choose Security.
- Under Name (optional), enter a name by which you’ll recognize the device later, such as “MacBook”, “iPhone” or “YubiKey”. If you leave the field empty, GoodWorkshop assigns one.
- Click Create a passkey. The button now shows Waiting for the device …
- Confirm in your browser’s or operating system’s dialog, for example with your fingerprint.
The page then reloads, and the passkey appears in the list.
Read the list
Section titled “Read the list”Each passkey is listed with its name, plus:
| Detail | Meaning |
|---|---|
| synced | The passkey is synced across your devices, for example through a password manager. |
| last used and a date | When you last signed in with it. |
| not used yet | You created it but have never used it to sign in. |
If you don’t have a passkey yet, it says: “No passkey yet. Until there is, every sign-in goes through a link by e-mail.”
Sign in with a passkey
Section titled “Sign in with a passkey”On the sign-in page, click Sign in with a passkey and confirm on your device. You don’t need to type an e-mail address for that.
The sign-in link by e-mail keeps working, even if you have passkeys. It’s your way in when you’re sitting at someone else’s device.
Remove a passkey
Section titled “Remove a passkey”Click Remove in the passkey’s row. It disappears immediately, without confirmation. Remove a passkey, for example, when you sell or lose a device.
When no passkey can be created
Section titled “When no passkey can be created”Browsers only allow passkeys over HTTPS (or on localhost). If an installation runs on a plain
http:// address, the page shows a notice, and Create a passkey is locked. The sign-in link
by e-mail then remains the way in.
Other messages and what they mean:
- The passkey could not be confirmed. The device responded, but the server couldn’t verify the response. Try again.
- This passkey is unknown. A passkey GoodWorkshop doesn’t know was used to sign in – for example because it was removed. Sign in with a sign-in link and create a new one.
If you cancel the device’s dialog yourself, simply nothing happens – that isn’t worth an error message.