Help Center
Securing Your Account with Passkeys & Biometrics
A passkey is a cryptographic key that lives in your device's secure hardware and is unlocked by your fingerprint or face. There is nothing to remember, nothing to type, and nothing a phishing site can steal.
How it actually works
When you enroll, your phone or laptop generates a key pair inside its secure element (Android Keystore / Apple Secure Enclave). FurlPay stores only the public half. Signing in means your device signs a one-time challenge after your biometric check passes — the private key never leaves the hardware, and the signature only works for furlpay.com, so a look-alike phishing domain gets nothing.
Enrolling
- Web: Settings → Security → Add passkey, then follow your browser's prompt.
- Android app: the login screen offers fingerprint sign-in; enrolling also signs you in, since creating the key proves it's you.
Where biometrics gate actions
- Signing in (one touch, replaces the email code).
- Unlocking the mobile app after it has been backgrounded.
- Confirming money movement — sends, swaps, and staking ask again per action.
- Approving 3-D Secure card challenges — the approval signature is bound to that specific purchase and cannot be replayed for another.
- Revealing full card details.
If you lose a device
Your account is not locked to the passkey: sign in on a new device with your email code, then remove the old device's passkey in Settings → Security and enroll the new one. If you suspect the lost device is compromised, lock the account from Settings first and open a ticket.
Passkeys and your wallet keys are different things
Deeper technical detail lives in MPC & WebAuthn.
