Veygrit Blog
The basics of signing in securely with Veygrit ID and a passkey
Veygrit ID and a passkey have different roles
Veygrit ID is an automatically issued profile identifier. It does not complete authentication on its own. When the Veygrit ID option is shown, it starts a configured authentication flow, which may be unavailable until that flow is configured.
A passkey is an authentication credential stored by a device or password manager. When the required settings and the device support it, the device can ask for biometrics, a PIN, or a security key. Google and Apple buttons belong to the sign-up flow and are not a universal sign-in method for an existing account.
Check the device and site before you approve
Only approve a passkey prompt that you started yourself. Check the browser address, the device screen lock, and the site you are using. Biometric information is checked by the device; it is not a value to send to Veygrit.
Do not enroll a passkey on a shared computer or a borrowed phone. Support staff and other people should never ask for your device PIN, biometrics, or approval of an unexpected passkey prompt. Close unexpected prompts and open the correct site again.
Use recovery and settings checks when sign-in is unavailable
If a passkey is not shown, a device has changed, or the Veygrit ID flow cannot continue, request a recovery link using the registered email address. This path is for returning to an existing account, not for creating a new account.
Passkey availability depends on the Veygrit authentication configuration, the website domain, Supabase passkey enablement, and device or browser support. Before changing devices, make sure you can receive recovery email and keep an available authentication method until the new setup is confirmed.