Passkeys and authenticator apps
Passkeys and authenticator apps both protect your Ravenstash account, but they work differently. You can use either one or keep both available.
Passkeys
Section titled “Passkeys”A passkey lets your device confirm it is you. Depending on the device, you approve with a fingerprint, face, screen lock, PIN, password manager, or security key. The passkey works only with Ravenstash, which makes it safer against fake sign-in pages than a reusable password.
A Ravenstash passkey can:
- sign you in without a Ravenstash password;
- complete the extra check after password, Google, or GitHub sign-in; and
- confirm an important account change while you are signed in.
Add a passkey
Section titled “Add a passkey”- Open Account settings → Security.
- In Passkeys, choose Add passkey.
- Follow your browser or device instructions.
- Keep the suggested name or enter a name that helps you recognize the device.
- If Ravenstash shows recovery codes, copy them or download the PDF and save it somewhere offline before acknowledging the codes.
Adding your first passkey automatically protects password sign-in. You do not need to turn on a separate password setting.
Keep more than one passkey
Section titled “Keep more than one passkey”Two passkeys on independent devices provide better protection against losing one device. Ravenstash requires two passkeys before a passwordless account can rely only on passkeys. An enabled Google or GitHub sign-in can provide the alternative way in.
Ravenstash will not create a duplicate through an authenticator or synced password- manager vault that already contains this account’s Ravenstash passkey. Use the existing passkey or choose a different independent device, security key, or vault. This does not limit you to one provider: multiple independent passkeys are still supported and recommended.
Good combinations include a phone plus a laptop, or a password manager plus a separate security key.
Remove a passkey
Section titled “Remove a passkey”Choose the remove button beside the passkey. Ravenstash blocks removal when it would leave no safe way into the account or would break passwordless recovery.
If a device was lost, remove its passkey after signing in from a device you still control. Then review Devices and sign out any browser or terminal you no longer trust.
Authenticator app
Section titled “Authenticator app”An authenticator app produces a new six-digit Ravenstash code every few seconds. It does not sign in by itself. It is used after password, Google, or GitHub sign-in, or to confirm an important change while you are already signed in.
Set up an authenticator
Section titled “Set up an authenticator”- Open Account settings → Security.
- Open Advanced sign-in settings and choose Add authenticator.
- Scan the displayed code with your authenticator app, or enter the setup key manually.
- Enter the current six-digit code in the six boxes. Ravenstash verifies it after the final digit.
- If this is your first extra-verification method, copy the recovery codes or download the PDF before confirming that you saved them.
When password sign-in is available, the authenticator automatically protects the password path. Linked-account sign-in remains independently configurable under Advanced sign-in settings. For an account that has only linked-account sign-in, adding its first authenticator automatically requires that step after Google or GitHub.
Replace or remove an authenticator
Section titled “Replace or remove an authenticator”Use Replace authenticator when moving to another phone or authenticator app. The current authenticator keeps working until the replacement is verified and the change is completed.
Use Remove authenticator only after checking that another suitable sign-in or verification choice remains. If it is your final extra-verification method, Ravenstash explains which sign-in choices will stop asking for another step and what happens to the current recovery codes.
If the authenticator is lost
Section titled “If the authenticator is lost”Do not start a separate account-recovery process. Sign in normally with your password, Google, or GitHub. On the extra verification screen, choose a passkey or open Try another way → Can’t use any of these? to enter a recovery code. After a recovery code is accepted, choose Replace authenticator.
For safe storage and all recovery paths, read Recovery codes and account recovery.

