Pro Plan10 minutesintermediate

WebAuthn Security Keys

Set up hardware security keys or platform authenticators for the strongest account protection.

webauthnsecurity-keyyubikeyfido2passkey
Last updated: January 15, 2025

WebAuthn security keys provide the strongest protection against phishing and account takeover. They use cryptographic hardware to verify your identity.

Pro Plan

What is WebAuthn?

WebAuthn (Web Authentication) is a modern standard for passwordless and multi-factor authentication using:

  • Hardware security keys: Physical devices like YubiKey
  • Platform authenticators: Built-in systems like Touch ID, Face ID, Windows Hello

Why WebAuthn is Secure

  • Phishing-resistant: Keys verify the website domain
  • Cryptographic: Uses public-key cryptography
  • No shared secrets: Private keys never leave the device
  • Tamper-resistant: Hardware-based security

Security Key Options

Hardware Security Keys

BrandModelsFeatures
YubiKey5 Series, Security KeyUSB-A, USB-C, NFC
Google TitanUSB-A, USB-CBluetooth option
ThetisPro, BioFingerprint models
FeitianePass, BioPassVarious form factors
SoloKeysSolo V2Open source

Platform Authenticators

PlatformTechnologyRequirements
macOS/iOSTouch ID / Face IDApple device with biometrics
WindowsWindows HelloWindows 10/11 with compatible hardware
AndroidFingerprint/FaceAndroid 7+ with biometrics
ChromeProfile-basedChrome 70+

Setting Up a Hardware Security Key

1

Get a Security Key

Purchase a WebAuthn-compatible security key. YubiKey 5 series is recommended.

2

Go to Security Settings

Navigate to SettingsSecurity in Zenovay.

3

Add Security Key

Click Enable MFASecurity Key, or if MFA is enabled, Add Security Key.

4

Insert Your Key

Insert your security key into a USB port (or have NFC ready on mobile).

5

Touch the Key

When your browser prompts, touch the button on your security key.

6

Name Your Key

Give it a recognizable name like "Office YubiKey" or "Backup Key".

7

Add Backup Method

Register a second key or another MFA method for recovery.

Always register at least two security keys, or have backup codes ready. If you lose your only key, you could be locked out.

Setting Up Touch ID / Face ID

macOS with Touch ID

1

Ensure Touch ID is Set Up

Go to System SettingsTouch ID & Password and add a fingerprint.

2

Use Safari or Chrome

Use a browser that supports Touch ID authentication.

3

Add in Zenovay

Go to SettingsSecurityAdd Security Key.

4

Authenticate

When prompted, use Touch ID to register.

5

Name It

Name it something like "MacBook Touch ID".

iOS with Face ID

1

Use Safari

Open Zenovay in Safari on your iPhone/iPad.

2

Add Security Key

Navigate to SettingsSecurityAdd Security Key.

3

Select Platform Authenticator

When prompted, allow Face ID or Touch ID.

4

Verify Identity

Complete Face ID or Touch ID verification.

Windows Hello

1

Set Up Windows Hello

Go to Windows SettingsAccountsSign-in options. Set up fingerprint, face recognition, or PIN.

2

Use Edge or Chrome

Open Zenovay in Microsoft Edge or Chrome.

3

Add Security Key

Go to SettingsSecurityAdd Security Key.

4

Authenticate with Windows Hello

Use your configured Windows Hello method.

Using Security Keys to Log In

Once set up, when you log in:

  1. Enter your email and password
  2. Browser prompts for security key
  3. Insert your key (if not already inserted)
  4. Touch the button or use biometrics
  5. You're logged in

NFC Security Keys (Mobile)

On compatible Android devices:

  1. When prompted, tap your NFC security key to the back of your phone
  2. Hold until verified

Managing Multiple Security Keys

We recommend registering multiple keys:

  • Primary key: For daily use
  • Backup key: Stored securely at home or office
  • Travel key: Smaller form factor for travel

Adding Additional Keys

  1. Go to SettingsSecurity
  2. Click Add Security Key
  3. Follow the registration process
  4. Give each key a unique name

Removing Keys

  1. Go to SettingsSecurity
  2. Find the key in your list
  3. Click Remove
  4. Confirm with another MFA method

Never remove your last security key without having a backup method configured.

Browser Compatibility

BrowserSupport LevelPlatform Authenticator
Chrome 67+FullYes
Firefox 60+FullYes
Safari 13+FullYes (Touch ID, Face ID)
Edge 79+FullYes (Windows Hello)

Browser Settings

Ensure your browser allows security keys:

  • Chrome: Settings → Privacy → Security → Use security key
  • Safari: Security keys work by default
  • Firefox: about:config → security.webauth.webauthn enabled

Troubleshooting

Key Not Detected

  1. Try a different USB port
  2. Check USB hub compatibility (try direct connection)
  3. Update browser to latest version
  4. Try a different browser
  5. Check if the key works on other sites

"Security Key Not Allowed"

  • Ensure you're using HTTPS (not HTTP)
  • Check browser supports WebAuthn
  • Update your browser
  • Try incognito mode

Touch ID / Face ID Not Working

  • Ensure biometrics are set up on your device
  • Try re-registering the platform authenticator
  • Check browser has permission to use biometrics
  • Restart browser and try again

"This Site Can't Use Your Key"

This can happen if:

  • The domain changed (phishing protection working)
  • Key was registered on different domain
  • Browser security settings block the key

Security Best Practices

Physical Security

  • Store backup keys securely: Safe, safety deposit box, or secure drawer
  • Don't leave keys plugged in: Remove when not in use
  • Keep track of keys: Know where each one is

Digital Security

  • Register multiple keys: At least two for redundancy
  • Keep firmware updated: Update security key firmware when available
  • Use with strong password: WebAuthn is MFA, not password replacement (yet)

Enterprise Considerations

Enterprise Plan
  • Standardize on key type: Easier management
  • Inventory keys: Track which employees have which keys
  • Develop key loss procedures: Know how to handle lost keys
  • Consider attestation: Verify keys are genuine

Passkeys (Future)

Zenovay supports WebAuthn, which is the foundation for passkeys. As passkey support expands, you'll be able to:

  • Sign in without passwords
  • Sync authentication across devices
  • Use the same credential everywhere

Next Steps

Was this article helpful?