FurlPay Docs
Open App
  • Introduction
  • Quickstart
  • For AI Agents
  • Monorepo
  • API Routes
  • Authenticationnew
  • Webhook Eventsnew
  • Error Codesnew
  • Rate Limitsnew
  • Agentic Payments (x402)
  • Agent Trust & Mandates (TAP)
  • CCTP Cross-Chainnew
  • LI.FI Swapsnew
  • FurlPay Travels (Travel MCP)
  • Solana Actions & Blinks
  • Claude Connectornew
  • AI Assistants
  • Stripe Crypto
  • Persona KYC
  • MiCA Roadmap
  • Security Posturenew
  • MPC & WebAuthn
  • Help Centernew
  • Getting Started
  • KYC Verification
  • Passkeys & Biometrics
  • Privacy & Data Protection
  • Transaction Statuses
  • Gasless Transfers
  • Deposits & Withdrawals
  • Managing Virtual Cards
  • Freezing & Unfreezing Cards
  • Declined Transactions
  • SDK & API Support
  • x402 Monetization Basics
  • Booking Travel
  • Travel Refunds & Cancellations

Resources

  • Changelog
  • System Status
  • OpenAPI Spec
  • Community
  • GitHub
Docs/Help Center/Passkeys & Biometrics

Help Center

Securing Your Account with Passkeys & Biometrics

A passkey is a cryptographic key that lives in your device's secure hardware and is unlocked by your fingerprint or face. There is nothing to remember, nothing to type, and nothing a phishing site can steal.

How it actually works

When you enroll, your phone or laptop generates a key pair inside its secure element (Android Keystore / Apple Secure Enclave). FurlPay stores only the public half. Signing in means your device signs a one-time challenge after your biometric check passes — the private key never leaves the hardware, and the signature only works for furlpay.com, so a look-alike phishing domain gets nothing.

Enrolling

  • Web: Settings → Security → Add passkey, then follow your browser's prompt.
  • Android app: the login screen offers fingerprint sign-in; enrolling also signs you in, since creating the key proves it's you.

Where biometrics gate actions

  • Signing in (one touch, replaces the email code).
  • Unlocking the mobile app after it has been backgrounded.
  • Confirming money movement — sends, swaps, and staking ask again per action.
  • Approving 3-D Secure card challenges — the approval signature is bound to that specific purchase and cannot be replayed for another.
  • Revealing full card details.

If you lose a device

Your account is not locked to the passkey: sign in on a new device with your email code, then remove the old device's passkey in Settings → Security and enroll the new one. If you suspect the lost device is compromised, lock the account from Settings first and open a ticket.

Passkeys and your wallet keys are different things

The passkey authenticates you to FurlPay. It is not your wallet's recovery phrase, and FurlPay never has either one. Never type a recovery phrase anywhere in FurlPay — nothing in the product asks for it.

Deeper technical detail lives in MPC & WebAuthn.

Did this page help?
Edit this page on GitHub

← Previous

KYC Verification

Next →

Privacy & Data Protection