TulzTool management

Sign in with a passkey and "Stay signed in"

Help › Account

Passkeys (sign in without a password)

Sign-in with "Stay signed in"
Sign-in with "Stay signed in"
Passkeys under "My profile"
Passkeys under "My profile"

A passkey is a key pair stored on the device (or in the keychain of Apple, Google, Microsoft, Bitwarden, 1Password …).
It is unlocked with a fingerprint, face or the device PIN. Tulz only stores the public part – it is not a secret.
A passkey cannot be typed, cannot be obtained over the phone and cannot be entered on a fake site: it only works on
the domain it was created for.

Set up: My profile → Passkeys → Set up passkey on this device. Give it a name (e.g. "Luca's iPhone",
"Workshop tablet 2", "YubiKey"), confirm on the device – done. Up to 10 passkeys per user, each can be renamed and deleted.

Sign in: on the sign-in page tap Sign in with passkey. In Chrome, Edge and Safari the passkey also appears directly as a
suggestion in the "Username" field. If a username is entered in the field, security keys without their own storage are offered too.
After a passkey sign-in the device automatically stays signed in (since 2.26.1, like "Stay signed in" – the duration is set in
Settings → Sign-in), even without the tick. If passkeys are used on a shared tablet, switch this off there ("Stay signed in after
passkey sign-in"); then the tick decides again. If a passkey was set up with fingerprint, face or PIN,
Tulz requires this confirmation at every sign-in – merely possessing an unlocked device is not enough.

Requirements: HTTPS (with Plesk via Let's Encrypt in two clicks), the PHP extension openssl, an up-to-date browser.
The algorithms ES256, RS256 and Ed25519 are supported – covering everything from Face ID and Windows Hello to YubiKey.

Domain: passkeys are tied to the domain (Settings → Sign-in → Passkey domain). If left empty, Tulz takes the domain from
the application's address and strips a leading www. – for https://tulz.work or https://www.tulz.work the
passkey domain is therefore tulz.work, and the same passkey works under both addresses and under every subdomain
(app.tulz.work). If Tulz should only apply under a specific subdomain, enter it here. After a real change of domain
the passkeys must be set up again – the password keeps working.

Device lost? The passkey itself is worthless without the unlocked device. Still: *Users → edit → Remove passkeys and
devices* deletes all of the employee's passkeys and signs out all devices. Everyone can also delete their passkeys themselves in their profile.

Apps: in the Android app (WebView) and the desktop program (Electron), passkeys are only available if the system platform
passes them through. In a normal browser and in the home screen app (PWA) they always work.

Error message from a password manager? Password manager add-ons (Bitwarden, Proton Pass, 1Password …) take over passkey requests
in the browser. If the add-on fails – known e.g. for Bitwarden in Firefox for Android – Tulz shows a note about it with the
add-on's technical message in small print below. Remedy: switch off saving passkeys in the add-on or pause the add-on for this site;
the browser or operating system then takes over. The password keeps working in any case.

Stay signed in

The tick on the sign-in page stores an additional cookie: the device stays signed in for 30 days (default) and is no longer
signed out due to inactivity. Intended for your own phone and your own office computer – not for the tablet that everyone
shares in the workshop.

Was this helpful?