Starting in v2.45, the Hudu Password Manager can create, store, and use passkeys alongside your regular passwords. Passkeys are saved through the Hudu browser extension and work for both company passwords and My Vault. This article walks through creating a passkey, signing in with one, and managing existing passkeys in Hudu.
Visit What are passkeys? Overview and FAQ for background on what passkeys are and why they're more secure than passwords, and Hudu Password Manager for installing and setting up the extension.
Creating a passkey
When you choose to create a passkey on a site that supports them, Hudu Password Manager steps in to save it.
A popup will ask you to:
Save to — choose My Vault or the company the passkey belongs to. This is required.
Attach to an existing login — if Hudu finds a password record that matches the current URL, it will suggest attaching the passkey to that record. This is optional. Attaching keeps a site's passkeys and password together in one record instead of scattering separate entries across the password list.
Folder — optional, and only shown when you're not attaching to an existing login.
Signing in with a saved passkey
When you return to a site and choose to sign in with a passkey, the extension checks your vault and any companies you have access to for a matching passkey. If more than one match is found, such as a personal passkey and a company passkey for the same site, you'll be shown a picker to choose which one to use. Select the appropriate passkey from the list and you'll be signed in, without needing to type a username or password.
Managing a passkey
Every password record that contains a passkey will display that passkey on the records details page. The passkey will show when it was created, when it was last used, and the URL associated with it.
Passkey credentials can't be edited or moved to a different record. If you need to change which record a passkey is attached to, remove it and create a new one instead.
To remove a passkey, edit the password record it is associate with and click "Remove from Record". You'll be asked to confirm, since this can't be undone from the Hudu side.
Removing a passkey in Hudu only deletes Hudu's record of it. It does not remove the passkey from the website or app it was created for. To fully revoke a passkey, remove it from the site or app itself as well.
Once a record has at least one passkey attached, the password field is no longer required. This means you can clear out an old shared password entirely and rely on the attached passkey(s) going forward, while keeping the rest of the record, notes, and history intact.
Passkeys cannot be shared via portal sharing or through share links, since a passkey can't be handed off the way a password or OTP code can.
Passkeys in the password list
Records that only contain a passkey, with no stored password, look different in the password list. Since there's no password to copy or check against breach data, those columns are left blank.
Admin controls
Admins can turn off passkey creation for the entire Hudu instance from account settings. This is useful if your organization isn't ready to roll out passkeys yet. When disabled, users won't be able to register new passkeys through the extension, though any passkeys created before it was turned off will remain in place.
Passkey activity is tracked the same way password activity is. Creating, using, editing, and removing a passkey are all recorded in the record's activity log and in the account-wide activity feed, so admins can see when a passkey was used to sign in.
FAQ
Yes. Passkey creation and sign-in both happen through the Hudu Password Manager extension. There's currently no way to create or use a passkey from the Hudu web app alone.
Yes. Attaching a passkey to an existing login doesn't remove the stored password. You can keep both, or clear the password once you're relying on the passkey instead.
No. Hudu automatically saves the most recently created passkey only.
Not directly. Passkeys are tied to the device or password manager they were created on.
Hudu won't automatically know the passkey was removed elsewhere, since that happens outside of Hudu. The record in Hudu will still show the passkey until you remove it manually, so it's worth cleaning up on both sides when a passkey is retired.
Troubleshooting
If a site's passkey prompt doesn't trigger the Hudu extension, confirm the extension is installed, up to date, and that you're signed in to your Hudu instance. Visit Hudu Password Manager for install and sign-in steps.