Skip to content

Passkeys

A passkey is a WebAuthn credential: a hardware security key, or a platform authenticator built into your device or browser. In Churchill, passkeys serve two jobs. Every operator can sign in with one instead of a password. For CAB members, a passkey is also the signing key that casts approval receipts.

How central the passkey is depends on how the account was created:

  • Password accounts sign in with a password and can also use a registered passkey. The password remains a fallback.
  • Invited operators are passkey-only. An operator invited by email creates a passkey while redeeming the invitation, and that passkey is the account’s only sign-in credential. No password is ever set. See Operators.
  • CAB members create a passkey from their board invitation. It is both their signing key and their console sign-in. See Joining the CAB.

The sign-in page shows a Use security key button below the password field. To sign in with a key:

  1. Enter your operator identity. The console needs it to look up the keys registered to you. A security key alone is not enough. If the identity field is empty, the console asks you to fill it in before it will start.
  2. Select Use security key. The button reads Waiting for security key… while your browser prompts you to activate your key.
  3. Complete the browser prompt. On success you land in the console, exactly as with a password sign-in.

If you cancel the browser prompt, the page reports that security-key sign-in was cancelled. You can try again, or fall back to your password if your account has one. The button only appears in browsers that support security keys.

A security key does not bypass a locked account. After three failed password attempts an identity is locked, and a key assertion against it is denied like any other sign-in. The console tells you to contact your CAB chair to restore access. A successful sign-in clears your failed-attempt count. For the full sign-in flow, including lockout, see Signing in.

Passkeys show up in two places in the console:

  • Your profile: the auth method on your profile shows how you signed in for the current session, plus a count of any passkeys registered to your identity, for example password · 2 passkey(s). If you have no passkeys, only the sign-in method shows. There is no zero count.
  • The operators view: the operators tab on the Settings page lists every operator with a Passkeys column showing each one’s count.

Both places show counts only. There is no list of individual keys or their details.

Passkeys are created inside specific flows, not from a management screen:

  • Redeeming an operator invitation creates the account’s sign-in passkey. See Operators.
  • Redeeming a CAB invitation creates a member’s signing passkey, which doubles as their sign-in. See Joining the CAB.
  • The CAB setup wizard creates or promotes the owner’s passkey when the owner opts into a voting seat. See Setting up your CAB.

Outside those flows, there is no console control to register an additional passkey, inspect an existing one, or remove one. If you lose the only passkey on a passkey-only account, the owner must invite you again. If a CAB member loses their signing passkey, the CAB must re-admit them.