mikakimikaki.org

Passkeys and unlocking Vault

A passkey signs you in to mikaki. Opening saved Vault items also requires PRF support from the corresponding passkey. This page explains the difference and the checks to make when an operation fails.

Authenticate with a passkey#

A passkey authenticates through your device or passkey provider instead of a typed password. Depending on the device, you may see a fingerprint, face or PIN prompt. WebAuthn biometric verification happens locally; it does not send your fingerprint or face data to the authenticating website.

Use a registered passkey at Web sign-in on auth.mikaki.org. New registration currently requires an invitation code. See Getting started.

PRF adds a capability for encrypted data#

WebAuthn PRF is an extension that lets the browser obtain an output associated with a passkey. mikaki Vault derives a key from this output to decrypt saved data in your browser. This is separate from verifying a signature for sign-in.

OperationRequired capability
Sign in to an accountAuthenticate with a passkey registered to that account
Open a saved name or noteObtain the required PRF output from the passkey associated with that item
Transfer an item to another passkeyUse PRF with both source and target passkeys on the same account

Successful passkey authentication does not establish PRF support. Adding another passkey to the same account also does not automatically let it open existing items.

When Vault will not open#

  1. Distinguish a sign-in failure from an unlock failure after sign-in. If you are not signed in, check the registered passkey and authentication domain.
  2. Check which passkey the item needs. Use the passkey associated with the saved item, or the selected target of a completed transfer. Signing in with another passkey is insufficient.
  3. Check on the original device, browser and passkey provider where that passkey is usable. If you cancelled authentication, follow the screen's instructions to try again. An unsupported-PRF message means unlocking has not been established for that combination.
  4. Do not overwrite an item that failed to unlock with new empty data. Network errors and save conflicts are separate from passkey compatibility; check the actual error shown.

Distinguish the device, OS, browser, passkey provider and authentication transport. There is no product-name compatibility list guaranteeing Vault support. Virtual passkeys and mocked PRF in automated tests do not qualify real-device sync, biometric prompts, USB or wireless transport.

Before changing devices#

Passkey synchronization, registering an additional mikaki passkey and transferring a Vault item are different operations. Signing in on a synchronized device does not establish that it can decrypt saved data. Reopen the item on the destination before giving up the original device or passkey.

Current Vault transfer works item by item. Transferring the name does not automatically transfer the note. Recovery after losing every unlock method is not guaranteed, and email alone cannot reissue the decryption key. Read Using Vault for transfer and export limitations.

Specifications and verification scope#

W3C describes the general mechanism in the WebAuthn PRF specification and biometric verification section. For mikaki's implementation and real-device evidence, see implementation status, the device compatibility record and passkey transfer design.