📖 How to add a passkey and use it to log in


What is a passkey?

A passkey is an alternative to typing your NACH username and password. Your device or password manager approves the sign-in using a fingerprint, face recognition, device PIN or a supported security key. The device PIN is not your NACH password. NACH stores the public part of the credential, not your private key or biometric data.

Adding a passkey does not disable password login. If you keep typing your username and password into the usual form, you are still using password login. To use a passkey, choose Sign in with a passkey.

Step 1: Add a passkey once
  1. On a trusted personal device, visit https://www.nachesshub.com and sign in with your existing account.
  2. Open Settings > Passkeys.
  3. Enter your current password. If your account uses two-factor authentication, also provide the current authenticator/SMS code or an unused recovery code as requested. A recent passkey sign-in can authorize changes for five minutes instead.
  4. Enter a recognizable name, such as Personal phone or Home laptop, then select Add a passkey.
  5. Follow the browser/device prompt to save the key and approve with your fingerprint, face, PIN or security key. The available choices depend on your browser and device.
  6. Wait for the confirmation that the passkey was added and appears in your list. Cancelling the device prompt does not finish enrollment.

If your account has no password yet, set one before adding your first passkey. Do not add passkeys to devices or password managers you do not trust.

Step 2: Use it at your next login
  1. Sign out of NACH so you can test a new sign-in. Keep your password and recovery codes available.
  2. On the login page, choose Sign in with a passkey above the username/password form. You can also open the passkey sign-in page directly.
  3. On that page, click Sign in with a passkey to start the device prompt.
  4. Select your saved NACH passkey/account and approve the request on your device.
  5. You are signed in without entering a NACH username, password or separate authenticator/SMS code for that passkey sign-in.

Start with the same device/browser where you added the key. Some passkeys sync through a password manager; others stay on one device or security key. Availability on a different device is not guaranteed. If the browser offers using a nearby phone or a QR code, follow its instructions and approve only a sign-in you initiated.

Automatic passkey suggestions inside the username field are not currently implemented. Use the dedicated passkey button. Keep me signed in is optional and should be used only on your private device.

If you do not see the button or a saved key
  • Use the exact HTTPS address with www: https://www.nachesshub.com. A localhost or different-domain key is not a production NACH key.
  • Use a compatible, up-to-date browser with JavaScript enabled. Unlock your device or password manager when prompted.
  • Check that you saved a key for the intended NACH account and that it is available in the selected device/password manager.
  • If you cancel or the prompt times out, start again. If passkeys are unavailable or disabled for the site, choose Use password login.
  • Passkeys do not bypass NACH email-confirmation or account-lockout rules. Follow the displayed message rather than repeatedly retrying.
Manage keys and keep a recovery path

In Passkeys settings, you can review names and last-used times, add another key, rename a key or remove one. NACH allows up to ten keys per account. Renaming changes only its NACH label, not its name in your device's password manager.

Removing a key revokes that credential on NACH, including copies synced to other devices. Delete the saved copy in your device/password manager separately. An account without a password cannot remove its last passkey; set a password first.

If a device is lost, use another available passkey or sign in with your password and the configured second factor/recovery code, then remove the lost key. Keep backup credentials somewhere you can access without the lost device. If you cannot recover access, contact NACH support without sending private credentials.

Never share passkeys, device PINs or recovery codes with staff. Use organizer or event delegation so everyone signs in to their own account.

General
What is a passkey?

A passkey is an alternative to typing your NACH username and password. Your device or password manager approves the sign-in using a fingerprint, face recognition, device PIN or a supported security key. The device PIN is not your NACH password. NACH stores the public part of the credential, not your private key or biometric data.

Adding a passkey does not disable password login. If you keep typing your username and password into the usual form, you are still using password login. To use a passkey, choose Sign in with a passkey.

Step 1: Add a passkey once
  1. On a trusted personal device, visit https://www.nachesshub.com and sign in with your existing account.
  2. Open Settings > Passkeys.
  3. Enter your current password. If your account uses two-factor authentication, also provide the current authenticator/SMS code or an unused recovery code as requested. A recent passkey sign-in can authorize changes for five minutes instead.
  4. Enter a recognizable name, such as Personal phone or Home laptop, then select Add a passkey.
  5. Follow the browser/device prompt to save the key and approve with your fingerprint, face, PIN or security key. The available choices depend on your browser and device.
  6. Wait for the confirmation that the passkey was added and appears in your list. Cancelling the device prompt does not finish enrollment.

If your account has no password yet, set one before adding your first passkey. Do not add passkeys to devices or password managers you do not trust.

Step 2: Use it at your next login
  1. Sign out of NACH so you can test a new sign-in. Keep your password and recovery codes available.
  2. On the login page, choose Sign in with a passkey above the username/password form. You can also open the passkey sign-in page directly.
  3. On that page, click Sign in with a passkey to start the device prompt.
  4. Select your saved NACH passkey/account and approve the request on your device.
  5. You are signed in without entering a NACH username, password or separate authenticator/SMS code for that passkey sign-in.

Start with the same device/browser where you added the key. Some passkeys sync through a password manager; others stay on one device or security key. Availability on a different device is not guaranteed. If the browser offers using a nearby phone or a QR code, follow its instructions and approve only a sign-in you initiated.

Automatic passkey suggestions inside the username field are not currently implemented. Use the dedicated passkey button. Keep me signed in is optional and should be used only on your private device.

If you do not see the button or a saved key
  • Use the exact HTTPS address with www: https://www.nachesshub.com. A localhost or different-domain key is not a production NACH key.
  • Use a compatible, up-to-date browser with JavaScript enabled. Unlock your device or password manager when prompted.
  • Check that you saved a key for the intended NACH account and that it is available in the selected device/password manager.
  • If you cancel or the prompt times out, start again. If passkeys are unavailable or disabled for the site, choose Use password login.
  • Passkeys do not bypass NACH email-confirmation or account-lockout rules. Follow the displayed message rather than repeatedly retrying.
Manage keys and keep a recovery path

In Passkeys settings, you can review names and last-used times, add another key, rename a key or remove one. NACH allows up to ten keys per account. Renaming changes only its NACH label, not its name in your device's password manager.

Removing a key revokes that credential on NACH, including copies synced to other devices. Delete the saved copy in your device/password manager separately. An account without a password cannot remove its last passkey; set a password first.

If a device is lost, use another available passkey or sign in with your password and the configured second factor/recovery code, then remove the lost key. Keep backup credentials somewhere you can access without the lost device. If you cannot recover access, contact NACH support without sending private credentials.

Never share passkeys, device PINs or recovery codes with staff. Use organizer or event delegation so everyone signs in to their own account.