Skip to content

Passkeys and authenticator apps

Passkeys and authenticator apps both protect your Ravenstash account, but they work differently. You can use either one or keep both available.

A passkey lets your device confirm it is you. Depending on the device, you approve with a fingerprint, face, screen lock, PIN, password manager, or security key. The passkey works only with Ravenstash, which makes it safer against fake sign-in pages than a reusable password.

A Ravenstash passkey can:

  • sign you in without a Ravenstash password;
  • complete the extra check after password, Google, or GitHub sign-in; and
  • confirm an important account change while you are signed in.
  1. Open Account settings → Security.
  2. In Passkeys, choose Add passkey.
  3. Follow your browser or device instructions.
  4. Keep the suggested name or enter a name that helps you recognize the device.
  5. If Ravenstash shows recovery codes, copy them or download the PDF and save it somewhere offline before acknowledging the codes.

Adding your first passkey automatically protects password sign-in. You do not need to turn on a separate password setting.

Two passkeys on independent devices provide better protection against losing one device. Ravenstash requires two passkeys before a passwordless account can rely only on passkeys. An enabled Google or GitHub sign-in can provide the alternative way in.

Ravenstash will not create a duplicate through an authenticator or synced password- manager vault that already contains this account’s Ravenstash passkey. Use the existing passkey or choose a different independent device, security key, or vault. This does not limit you to one provider: multiple independent passkeys are still supported and recommended.

Good combinations include a phone plus a laptop, or a password manager plus a separate security key.

Choose the remove button beside the passkey. Ravenstash blocks removal when it would leave no safe way into the account or would break passwordless recovery.

If a device was lost, remove its passkey after signing in from a device you still control. Then review Devices and sign out any browser or terminal you no longer trust.

An authenticator app produces a new six-digit Ravenstash code every few seconds. It does not sign in by itself. It is used after password, Google, or GitHub sign-in, or to confirm an important change while you are already signed in.

  1. Open Account settings → Security.
  2. Open Advanced sign-in settings and choose Add authenticator.
  3. Scan the displayed code with your authenticator app, or enter the setup key manually.
  4. Enter the current six-digit code in the six boxes. Ravenstash verifies it after the final digit.
  5. If this is your first extra-verification method, copy the recovery codes or download the PDF before confirming that you saved them.

When password sign-in is available, the authenticator automatically protects the password path. Linked-account sign-in remains independently configurable under Advanced sign-in settings. For an account that has only linked-account sign-in, adding its first authenticator automatically requires that step after Google or GitHub.

Use Replace authenticator when moving to another phone or authenticator app. The current authenticator keeps working until the replacement is verified and the change is completed.

Use Remove authenticator only after checking that another suitable sign-in or verification choice remains. If it is your final extra-verification method, Ravenstash explains which sign-in choices will stop asking for another step and what happens to the current recovery codes.

Do not start a separate account-recovery process. Sign in normally with your password, Google, or GitHub. On the extra verification screen, choose a passkey or open Try another way → Can’t use any of these? to enter a recovery code. After a recovery code is accepted, choose Replace authenticator.

For safe storage and all recovery paths, read Recovery codes and account recovery.