Product
Mail Books Ecommerce Assistant
Pricing Partners Demo Security Q&A Log in Request access

Help › Settings

Confirm a money action with a passkey

Open this in Talisk HQ

Confirm a money action with a passkey

A passkey is the fingerprint, face or device PIN you already use to unlock your phone or laptop. Turn it on in TALISK_HQ and we ask for it before a handful of actions that move money.

This protects your session on your device. It does not change who can open your books. If you work with a bookkeeper, your passkey is yours: it does not ask them for anything, and theirs does not ask you.

What it asks about

Once you have added a passkey, TALISK_HQ asks you to confirm before it will:

  • send an invoice to a client
  • record a payment on an invoice
  • mark an invoice paid from an email
  • approve a bill
  • draft payment reminders
  • apply a category to similar bank charges

Once you confirm, you have about five minutes before it asks again, so a run of reminders does not ask you six times.

Everything else works exactly as before. If you have not added a passkey, nothing changes anywhere.

Turning it on

You need two-step verification switched on first. That is deliberate: it is how you confirm a money action on a device that cannot use a passkey, so it needs to be in place before you rely on one. See Two-factor authentication and your recovery codes.

Then, on the web, go to Settings › Account › Passkeys and choose Add a passkey. On your phone, open More and choose Add this phone.

Your phone is usually the best device to start with, because it has the fingerprint or face unlock built in.

If you cannot use a passkey on a device

Some apps and older browsers cannot use passkeys at all. When that happens TALISK_HQ says so on the spot and offers your authenticator code instead, which works everywhere. Enter the six-digit code from your authenticator app and the action goes through.

Backing out

Press Escape, or choose Cancel. Nothing goes through: you land back where you were with the action not taken, and you can start it again when you are ready.

Removing a passkey

Settings › Account › Passkeys › Remove, or More › Remove on the phone. We ask you to confirm first, using a passkey or your authenticator code. That is on purpose: if someone else had your unlocked laptop, an unprotected Remove button would be the first thing they used.

Turning two-step verification off

While you have a passkey, TALISK_HQ will not let you turn two-step verification off, and it says so. Remove the passkey first, then turn two-step off.

The reason is worth knowing: your authenticator code is the route that works on a device where a passkey does not. Take it away while a passkey is your only way to confirm, and a device that cannot use passkeys could leave you unable to approve a bill or send an invoice at all.

If you are locked out

Ask us for a recovery through the normal two-step recovery process. Approving it clears both your two-step setup and your passkeys, so you can sign in and start again.

Good to know: You need two-step verification switched on before you can add a passkey, and Talisk will not let you turn two-step off again while a passkey is enrolled. Remove the passkey first. The gate protects your SESSION on your device, not your books: your passkey never asks anything of a bookkeeper you have invited, and theirs never asks anything of you. It covers six actions (send an invoice, record a payment, mark an invoice paid from an email, approve a bill, draft reminders, apply a category to similar charges) and nothing else. Some apps and older browsers cannot use passkeys at all; there Talisk says so and takes your authenticator code instead.