# Passkeys

### 1. Sign in to your Hideez server using your email and password

<figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/nApSSy9RIRY6ewfFWmRk/unnamed%20(1)%20(1).jpg" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note**: If you see the message “Your web application is running and waiting for your content,” the server is not ready yet. The process may take from 5 to 10 minutes. Once the server is ready, you will receive an email confirmation.
{% endhint %}

### **2. Create Passkeys:**

{% hint style="info" %}
**Passkeys** are a new way of signing in to your online accounts with a **biometric sensor** or PIN, eliminating the need for **passwords.**
{% endhint %}

* To create a passkey, go to the **Profile** page, then the  **FIDO2 Authenticators** section, and click **Add FIDO2 Authenticator**.

<div><figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/hfccsaLoI7ESORI5IjhL/Screenshot_6%20(1).jpg" alt=""><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/Vuza45MuLwOo5tRtk7DJ/Screenshot_1%20(1).jpg" alt=""><figcaption></figcaption></figure></div>

* Following the on-screen steps, add a FIDO2 Authenticator, choosing between a **Cross-Platform key** (another device, like a phone or tablet) or a **Platform key** (current device).

&#x20;Adding a [**Cross-Platform key:**](https://enterprise.hideez.com/use-cases/passkey/sso-login-to-web-services-fido2-via-passkey-and-hideez-server-as-identity-provider)

<div><figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/BFc1qv3kXAHqZAmFFhxE/Screenshot_14.jpg" alt="" width="466"><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/zzAdOb9Ct0QXhuSBSHuj/Screenshot_26.jpg" alt="" width="425"><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/wEXwE23FPql91iPPxpQY/Screenshot_27.jpg" alt="" width="422"><figcaption></figcaption></figure></div>

Adding a [**Platform key**](https://enterprise.hideez.com/hideez-enterprise-server/administration/platform-authentication-on-the-hes-server)

<div><figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/ouMIczCty0i6qgfmbrMK/Screenshot_15.jpg" alt="" width="467"><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/IF4WKxSK1i5dNg6KzA7L/Screenshot_16.jpg" alt=""><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/P4sVwmY9OAh4fyeVoo8z/Screenshot_18.jpg" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
Note: Multiple devices can be added simultaneously.

&#x20;A **biometric sensor** or **Trusted Platform Module** **(TPM)** module must be present.
{% endhint %}

### 3. Configure Passwordless SS&#x4F;**:**

Hideez Server allows you to enable passwordless Single Sign-On (SSO) based on the SAML and OpenID Connect (OIDC) protocols. These protocols are employed to verify a user’s identity when an employee tries to access web or mobile applications.&#x20;

To configure the Hideez Server as an Identity Provider for passwordless SSO, go to Settings → Parameters, and proceed with [**SAML**](https://enterprise.hideez.com/hideez-enterprise-server/configuring-saml-protocol) or [**OIDC**](https://enterprise.hideez.com/hideez-enterprise-server/configuration-oidc-openid-connect) configuration as described in our user guide.

### **4. Add a New user:**

New users can be added through:

* [**Active Directory (On-Premises, Azure Ad)** ](https://enterprise.hideez.com/hideez-server-integration/microsoft-entra-id/import)
* [**Manually**](https://enterprise.hideez.com/hideez-enterprise-server/employees/how-to-add-an-employee)

Upon receiving an email, users can configure their preferred login methods, such as a [**mobile application**](https://authenticator.hideez.com/user-guide/android-guide/login-with-hideez-authenticator/sso-login/sso-passwordless-login) or passkeys.

<div><figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/pzpkFZF5EztYASON7Upd/Screenshot_11.jpg" alt="" width="375"><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/wagTSJiD0sXCrhsmiST7/image.png" alt="" width="266"><figcaption></figcaption></figure> <figure><img src="https://content.gitbook.com/content/RdTysrljwe610dPFG7tE/blobs/eF8QjiwNYl1ocaZmEVMo/Screenshot_10.jpg" alt="" width="358"><figcaption></figcaption></figure></div>

Additionally, the Hideez Server assumes that passwordless authentication can be employed alongside other methods

* [**Mobile Application**](https://enterprise.hideez.com/quick-start-guides/quick-start-guide-for-subscriptions/hideez-authenticator-guide) allows Passwordless SSO and PC login with Mobile App
* [**Hardware keys**](https://enterprise.hideez.com/quick-start-guides/quick-start-guide-for-subscriptions/hardware-key-guide) allow Passwordless SSO, PC logon & logoff, password-based authentication
