Signing in and passkeys

One-time codes and passkeys — how passwordless sign-in works, and what to do when you lose the device.

4 min read

There is no password field anywhere in SignlOS. The most common way accounts are compromised is a reused password, and the cheapest way to prevent that is to never ask for one.

One-time codes

Enter your email or phone number, receive a short code, type it in. The code is single-use and short-lived. This is the default and always works.

Passkeys

A passkey is a key pair held by your device and unlocked by Touch ID, Face ID, a PIN, or a hardware security key. The private half never leaves the device and there is nothing on our side worth stealing. Register one from Settings → Security once you are signed in.

  • Faster than waiting for an email — one biometric prompt.
  • Phishing-resistant: a passkey is bound to signlos.com and will not offer itself to a lookalike domain.
  • Register one per device you regularly use.

Keep a second way in

A passkey is bound to the device that created it. Register one on a second device, or make sure you can still receive mail at the account address — the one-time code path is the recovery route, and it is the only one.

NextSecurity and your data

Common questions

Does SignlOS use passwords?
No. Sign-in is a one-time code sent by email or SMS, or a passkey using Touch ID, Face ID, or a hardware security key. There is no password to choose, reuse, leak, or reset.
What happens if I lose the device holding my passkey?
Sign in with a one-time code to the email on the account, then remove the lost passkey and register a new one. The one-time code path always remains available as the recovery route.

Something unclear or wrong? Tell us — or post it on our board.