Troubleshooting
Most passkey problems are a handful of causes, and most are resolved without removing anything.
Where to find it
Architect Panel → Security:
- Passkeys — registered credentials, their devices and last use
Architect Panel → Configuration:
- Site Settings — Enable Passkeys, and the prompt setting
Architect Panel → Activity:
- Error Log — technical failures around registration
Ask which device first
Nearly every report resolves faster once you know whether they are on the device that holds a credential. "It is not working" from somebody on a new laptop is a different problem from the same words on their usual one.
They are on a different device
The commonest cause by a distance. A device-bound credential exists on one machine, and a synced one requires being signed in to the same platform account.
The fix is usually to register a credential on the device they are actually using — which is also the moment to check they have a second one.
The browser does not support it
Older browsers, and some managed or restricted environments, do not offer the necessary interface. The symptom is the option not appearing rather than an error.
Check what they are using before assuming a fault, and keep an alternative sign-in route available for people you cannot move.
The device declined
A fingerprint not recognised, a PIN entered wrongly, or biometrics not set up on the device at all. The platform never sees why — it only sees that the device did not confirm.
The answer is on the device: check biometrics or a PIN are configured, then try again.
Registration appears to work but sign-in fails
Worth testing at registration for exactly this reason. If it happens, check the error log — this is the shape of problem that indicates a configuration issue rather than a user one.
They deleted the credential from their device
Users tidy up saved passwords and passkeys without realising what they are removing. The platform still holds the public half and the device no longer has the private one, so sign-in fails with no obvious cause.
Remove the stale credential and re-register.
Do not remove credentials as a first step
The instinct when something is not working is to clear it and start again. That turns a device problem into a lock-out if it was their only credential, and it discards the evidence.
Establish which device, which browser and what the device said, before removing anything.
The signature counter went backwards
Rare, and worth taking seriously — it suggests a cloned authenticator rather than an ordinary fault. Treat it as a security matter rather than a support ticket.
Worked example
A user reports passkeys "stopped working". They are on a replacement laptop, and their credentials are on the old one and their phone. They sign in with the phone, register the new laptop, and end with three credentials — resolved in two minutes and no credential removed.
Recommendations
- Ask which device before anything else.
- Never remove a credential first.
- Keep an alternative route for unsupported browsers.
- Escalate a backwards counter rather than clearing it.