Passkeys and two-factor codes
Passkeys
Section titled “Passkeys”Sites that offer “sign in with a passkey” can create and use passkeys stored in Claspt. The browser extension answers the site; the desktop holds the key, signs after you approve, and never hands the key to the browser.
- Create: when a site offers a passkey, choose Claspt in the extension’s prompt and approve on the desktop.
- Use: click the field icon on the site; approve on the desktop.
- See and remove: Settings › Passkeys lists every passkey with its site, account and dates, and a delete. Removing a passkey in Claspt does not remove it from the website; the tab says so.
Passkeys sync with the rest of the vault, so the same passkey works on every desktop the vault reaches. The phone keeps them safe but cannot use them yet. Chrome, Edge, Brave and Firefox with the extension; not Safari. The browser’s own passkey autofill is not used; you click the icon. ES256, the algorithm every site accepts, is the one supported.
Two-factor codes
Section titled “Two-factor codes”A login can hold its two-factor key and show the live six-digit code beside the password, on the desktop, in the extension and on the phone.
- From a site’s setup page: the extension reads the QR code off the page, shows the code it produces so you can check it against the site, and saves the key to the login in one click. The QR image is decoded inside the extension and dropped.
- By hand: paste the
otpauth://totp/key into the login block.
Keeping the second factor in the same vault as the password is convenient and a weaker separation than a separate device. Claspt does not claim to be more secure than an authenticator app; it puts the code where the login is.