Starting in v2.45, the Hudu Password Manager can create, store, and use passkeys alongside your regular passwords. Passkeys are saved through the Hudu browser extension and work for both company passwords and My Vault. This article walks through creating a passkey, signing in with one, and managing existing passkeys in Hudu.
Visit What are passkeys? Overview and FAQ for background on what passkeys are and why they're more secure than passwords, and Hudu Password Manager for installing and setting up the extension.
Creating a passkey
When you choose to create a passkey on a site that supports them, the Hudu extension steps in to save it, the same way it offers to save a new password.
A popup will ask you to:
Save to — choose My Vault or the company the passkey belongs to. This is required.
Attach to an existing login — if Hudu finds a password record that matches the site and username, it will suggest attaching the passkey to that record. This is optional. Attaching keeps a site's passkeys and password together in one record instead of scattering separate entries across the password list.
Name — pre-filled based on the site, and required.
Username — optional.
URL — set automatically from the site and can't be edited.
Folder — optional, and only shown when you're not attaching to an existing login.
Attaching a passkey to an existing login is usually the better choice. If several people each create their own passkey for one shared login, attaching keeps all of those passkeys together on the original record instead of creating a separate record for each person.
Signing in with a saved passkey
When you return to a site and choose to sign in with a passkey, the extension checks your vault and any companies you have access to for a matching passkey. If more than one match is found, such as a personal passkey and a company passkey for the same site, you'll be shown a picker to choose which one to use. Approve the prompt and you'll be signed in, without needing to type a username or password.
Managing a passkey
Every password record with a passkey attached shows a dedicated Passkey section on its details page, listing each passkey's name, when it was created, and when it was last used.
You can edit a passkey's name, username, notes, folder, and tags from this section. The underlying passkey credential itself can't be edited or moved to a different record. If you need to change which record a passkey is attached to, remove it and create a new one instead.
To remove a passkey, use the remove option in the Passkey section. You'll be asked to confirm, since this can't be undone from the Hudu side.
Removing a passkey in Hudu only deletes Hudu's record of it. It does not remove the passkey from the website or app it was created for. To fully revoke a passkey, remove it from the site or app itself as well.
Once a record has at least one passkey attached, the password field is no longer required. This means you can clear out an old shared password entirely and rely on the attached passkey(s) going forward, while keeping the rest of the record, notes, and history intact.
Only clear a record's password if you're confident every person who needs access has their own passkey set up, or has another way in. Passkeys are tied to the device or password manager they were created on, so there's no shared "password" fallback once it's removed.
Passkeys in the password list
Records that only contain a passkey, with no stored password, look different in the password list. Since there's no password to copy or check against breach data, those columns are left blank, and a passkey icon marks the row instead. These passkey-only records also aren't available for portal sharing or share links, since a passkey can't be handed off the way a password or OTP code can.
Admin controls
Admins can turn off passkey creation for the entire Hudu instance from account settings. This is useful if your organization isn't ready to roll out passkeys yet. When disabled, users won't be able to register new passkeys through the extension, though any passkeys created before it was turned off will remain in place.
Passkey activity is tracked the same way password activity is. Creating, using, editing, and removing a passkey are all recorded in the record's activity log and in the account-wide activity feed, so admins can see when a passkey was used to sign in.
FAQ
Yes. Passkey creation and sign-in both happen through the Hudu Password Manager extension. There's currently no way to create or use a passkey from the Hudu web app alone.
Yes. Attaching a passkey to an existing login doesn't remove the stored password. You can keep both, or clear the password once you're relying on the passkey instead.
Yes. Hudu supports multiple passkeys attached to a single password record, so each person can register their own passkey for a shared account rather than everyone using one credential.
Not directly. Passkeys are tied to the device or password manager they were created on. If a teammate needs access, have them register their own passkey for the site rather than trying to hand one off.
Hudu won't automatically know the passkey was removed elsewhere, since that happens outside of Hudu. The record in Hudu will still show the passkey until you remove it manually, so it's worth cleaning up on both sides when a passkey is retired.
Troubleshooting
If a site's passkey prompt doesn't trigger the Hudu extension, confirm the extension is installed, up to date, and that you're signed in to your Hudu instance. Visit Hudu Password Manager for install and sign-in steps.