Passkeys

Your passkey is your zk.money account. This page explains the two keys it gives you, which passkeys work, how to reach yours from each device, and what to do when something goes wrong.

Your two keys

Your passkey gives zk.money two keys: one for your funds and one for your privacy.

  • Signing key. Approves every payment. It is the passkey's own key, and it never leaves your passkey. Your account accepts only this key, and it is built into your account's address.
  • Secret key. Reads your balance and your payment history. Your passkey makes it with the WebAuthn PRF extension, which gives a secret value that only this passkey can produce. zk.money keeps it in your browser until you sign out; see Trust model for what that means.

Which passkeys work

zk.money works with a passkey saved in:

  • iCloud Keychain (Apple Passwords)
  • Google Password Manager
  • 1Password
  • a YubiKey 5 security key

It refuses other passkey managers, such as Bitwarden, Proton Pass, LastPass or Windows Hello. zk.money has not tested that they give the same secret key on every device, and a secret key that changes would lock you out of your wallet.

A password manager syncs your passkey to your other devices, and that sync is your backup. A security key holds the only copy: lose the key and you lose the wallet.

Reaching your passkey

On a phone, use the passkey saved on that phone, or a security key. Plug the key in, or hold it to the phone, only after the browser asks for it. A key that is already plugged in may not be found.

On a computer, at sign-up, the passkey is made on your phone (scan the QR code) or on a security key. zk.money does not accept a passkey saved on the computer itself at sign-up.

On a computer, at sign-in, the browser offers whatever it can reach:

  • a copy of your passkey on this computer: iCloud Keychain on a Mac, Google Password Manager in a Chrome signed in to the same Google account, or the 1Password browser extension
  • your phone, through the QR code
  • a security key

For zk.money Desktop, see How to run the desktop app.

Problems at sign-up

When zk.money refuses a passkey at sign-up, the passkey has already been saved. See A passkey is left over before you try again.

"That passkey provider isn't supported"

The passkey was saved in a manager zk.money does not accept. Pick one from Which passkeys work and sign up again.

"Use your phone or a security key"

You are on a computer, and the passkey was saved on the computer itself. Sign up again and choose the QR code option, or use a security key.

"This passkey can't be backed up"

The passkey was saved somewhere that keeps it on one device only, so losing that device would lose the wallet. Use a password manager that syncs, or a security key.

"Try a different passkey manager"

Your passkey manager did not give zk.money your secret key. Use another one from Which passkeys work.

"This device can't use that security key"

The security key gave no secret key on this device. Known causes: an iPhone older than iOS 26.4, a YubiKey Bio, or an Android phone with out-of-date Google Play services. Update the device, or use a YubiKey 5 on another device.

"Update this browser to continue"

On a Mac, signing up needs Safari 26 or later, or Firefox 139 or later. Older versions can still sign in. On an iPhone older than iOS 18.4, zk.money shows a warning instead: passkeys had a bug there, so update iOS if sign-up fails.

A passkey is left over

A website cannot reliably delete a passkey, so a refused sign-up usually leaves one behind. It opens nothing and is safe to delete: in your password manager, or with YubiKey Manager for a security key.

Problems at sign-in

The browser does not offer your passkey, or says "Passkey not on this device"

A browser can only offer a passkey it can reach. If yours is on your phone, choose the QR code option and scan it with the phone. Turn on Bluetooth on both devices and keep both online. If no QR code appears, look for "More options" or "Use a different device". Closing the QR window instead makes zk.money say "Passkey not on this device".

On a Mac, Chrome can use iCloud Keychain only if you allow it in System Settings > Privacy & Security > Passkeys Access for Web Browsers.

If no option appears at all, update your browser.

Your Google Password Manager passkey does not appear

A passkey in Google Password Manager belongs to the Google account it was saved under, often the one on your phone. Chrome on a computer offers it only when that Chrome is signed in to the same Google account. If you use a sync passphrase, Chrome needs it first, and it may ask for your Google Password Manager PIN or your Android screen lock the first time. A passkey you just made can take a few minutes to reach the computer. Scanning the QR code with your phone may also need a Chrome signed in to that account.

iCloud Keychain passkeys do not depend on Google.

The 1Password extension gives no secret key

Some versions of the 1Password browser extension answer without your secret key, and zk.money shows "Try a different passkey manager". Update the extension, or choose the QR code option and use the 1Password app on your phone.

Your Mac's passkey does not open your wallet

On macOS 26.0 to 26.3, or 15.6.1 to 15.7.4, a Mac's copy of a passkey made on an iPhone can give the wrong secret key. This is an Apple bug, fixed in macOS 26.4 and 15.7.5. zk.money refuses the wrong secret key, so nothing is lost, and may say "This computer is returning the wrong key". Choose Show passkeys and use your iPhone (scan the QR code) or a security key, or update macOS.

"No wallet for this passkey"

The passkey you used did not open a wallet zk.money can find.

  • You may have picked a different passkey. Choose Show passkeys and pick another, or type your tag on the sign-in screen so zk.money asks for the passkey that tag uses.
  • Until your tag is active, a different browser may not find your wallet. Sign in on the browser you signed up on.

"Passkeys unavailable on this site"

Your passkey belongs to auth.zk.money, which lists the zk.money sites allowed to use it. The browser reads that list before it offers your passkey, on the website and in zk.money Desktop. This message means it could not, most often because the browser is too old. Update your browser. If that does not help, auth.zk.money may be briefly unreachable, so try again later.