Signing in with a passkey
Updated 2026-09-13
A passkey signs you in to rifts.to with the unlock you already use on your phone or computer: Face ID, Touch ID, Windows Hello, or a password manager such as 1Password. There's no code to wait for and nothing to type. Passkeys are free with any account.
Create an account with a passkey
After you create a survey, the box that offers to save your admin link has a Create a passkey button. Enter your email, press it, and confirm on your device. That creates your account and saves the survey to it.
Already signed in with a code? Add a passkey from the Passkeys section of your account page.
Sign in with your passkey
On the sign-in page, choose Continue with a passkey. Your device or password manager shows the passkeys it holds for rifts.to. Pick yours and confirm. If none appears, this device doesn't hold your passkey: sign in with the emailed code instead, or use the device where you saved it.
If your email already has an account
Creating a passkey with an email address that already has a rifts.to account doesn't sign you straight in. You're asked for the 6-digit code sent to that address, and once you enter it, the passkey you just created is added to the account. If you don't finish within 20 minutes, that passkey is discarded and you can create it again.
Confirm your recovery email
A passkey lives on your device or in your password manager. If you lose it, a code sent to your email is the only way back in, so confirm that address even if you only ever sign in with a passkey. Until you do, your account page calls it your recovery email and offers to send a code. Notices, like a warning before a survey stops taking answers, only go to a confirmed address.
Confirm it while you're signed in, soon after you create the passkey. If you skip that and later sign in with an emailed code instead, the passkeys added before the address was confirmed are removed, and your account page tells you so. That rule stops someone who typed your email address into rifts.to from keeping a way into your account. Confirming from your own signed-in account page never removes a passkey.
Add or remove passkeys
The Passkeys section of your account page lists each passkey by where it's saved, such as iCloud Keychain or 1Password, with when it was added and last used. Add another for a second device, and remove the ones you no longer use. If your email isn't confirmed yet, removing your last passkey warns you first, because the emailed code would then be your only way in.
If adding one says a passkey is already saved there, that device or password manager already holds one for your account. Add the next one on a different device, or use a security key.
If a passkey doesn't work
- The device doesn't support passkeys. Sign in with the emailed code, or use a device and browser that do.
- You closed the prompt, or it timed out. Nothing was used. Try again, or choose Use the emailed code instead.
- Too many attempts. Wait a few minutes, or sign in with the emailed code.
The emailed code keeps working whether or not you have a passkey. See signing in with a code.
What rifts.to stores
We keep the public key of each passkey, never the private key, which stays on your device or in your password manager. The public key alone can't be used to sign in as you. The privacy policy lists what is stored.