Welcome to Sprintax Calculus!

You can use these guides to get started

Aug 13, 2026 - Introducing Passkeys: A New MFA Option

No change to how anyone signs in today

This update does not change the login flow for any current admins or users. Everyone continues signing in exactly as they do today (with email and password or SSO). Passkeys are simply a new, optional MFA method available alongside Authenticator App and SMS. Nothing changes unless someone chooses to set one up.

 

What's New

Starting Thursday, August 13, passkeys will be available as a third Multi-Factor Authentication (MFA) option in Sprintax Identity, alongside the existing Authenticator App and SMS methods.

A passkey is a secure, passwordless way to confirm it's really you. It doesn't replace a password, users will still sign in with their email and password, or SSO, exactly as they do today. A passkey is simply another form of authenticating your account: the user confirms it's them using their device's own security, such as Face ID, Touch ID, Windows Hello, or a PIN.

Sprintax never sees or stores biometric data. Face ID, Touch ID, fingerprints, and PINs are handled entirely by the user's own device, browser, or password manager. Identity Server only stores a public key and basic credential details (such as the passkey's name and creation date) needed to verify it at sign-in.

 

Who is This For

Passkeys will be available to both administrators and users on Calculus. The process for adding and removing a passkey is identical for both. There is no difference in setup based on role.

 

What's Not Changing

  • Sign-in still starts with email and password, or SSO, exactly as today.
  • Authenticator App and SMS remain available and fully supported — no one is required to switch.
  • Adding a passkey is entirely optional. Anyone who doesn't set one up will see no change at all.
  • Existing MFA setups are untouched — nothing is reset or reconfigured as part of this release.
     

How it Works

Setting up a passkey

  • From Account > Security, select Add Passkey.
  • Name the passkey (e.g. “Work laptop”) so it's easy to recognize later.
  • Choose where to save it. Either on the current device (unlocked with fingerprint, face, or PIN) or on a phone/tablet via QR code.
  • Once confirmed, the passkey is ready to use as the verification step at the next sign-in.


     

Removing a passkey

  • From Account > Security, find the passkey in the list.
  • Open the “...” actions menu beside it and choose to delete it.
  • Confirm the deletion. Once removed, that passkey can no longer be used to sign in.

Good practice

As mandatory MFA is being introduced next month, anyone removing any form of MFA should confirm they still have another way to sign in (such as another passkey, an authenticator app, or SMS) before deleting it.

 

Where to Point Admins and Users

A full step-by-step guide covering setup and removal for Authenticator App, SMS, and Passkeys, “How to Set Up Your MFA” is available for anyone who wants a detailed walkthrough. Feel free to share this alongside the release announcement. 

The MFA guide can be found in the same places as before:

Was this article helpful?

0 out of 0 found this helpful