Acquainto
← All guides

Guide

Set up a passkey or two-factor authentication

Sign-in security, in Your account, has two ways to add a credential beyond your password: a passkey (a fingerprint, face, or your device’s PIN — no code to type or remember) and an authenticator app (1Password, Authy, Google Authenticator, iOS Passwords, or anything else that generates 6-digit codes). A passkey is the faster of the two to set up and the one we recommend first, but both work, and you can have more than one of each.

Add a passkey

  1. On Your account, under Sign-in security, click Add a passkey.
  2. Your browser or device asks you to confirm with a fingerprint, your face, or a PIN — whatever it already uses to unlock itself. This is the entire ceremony; there is no code to type.
  3. Give it a name — “MacBook Pro”, “iPhone” — so you can tell it apart from any others later, and save it.
  4. If this is the first credential of any kind on your account, your recovery codes appear. Save them before you leave the screen — see below for why.

A passkey confirmed with a fingerprint, face, or PIN signs you in on its own — no password step at all. A security key with no PIN set still works, but only as a second factor alongside your password, the same slot an authenticator-app code fills; there is no separate setup step for that case, it is simply what happens if the device cannot confirm it was really you.

A passkey created on one device stays on that device, unless your operating system or password manager syncs it for you (iCloud Keychain and Google Password Manager both do this automatically). Sign-in security marks a passkey that will not sync as “Only works on this device” — worth a second one from another device if you see that.

Add an authenticator app instead, or as well

  1. On Your account, under Sign-in security, find Authenticator app and click Set up.
  2. A QR code appears — point your authenticator app’s camera at it and skip to step 3. If you’d rather not scan it, the setup key underneath works the same way: add it to your authenticator app by hand — every app takes a typed key.
  3. Your app starts showing a 6-digit code that changes every 30 seconds. Type the current one into Code from your app and click Turn on.
  4. If this is the first credential of any kind on your account, your recovery codes appear. Save them before you leave the screen — see below for why.

The app lists the account as Acquainto, with your account name beside it if you have one set, so several Acquainto logins stay tellable apart.

Nothing is switched on until step 3 succeeds. If you start the setup and close the tab, nothing has changed and you can click Set up again for a fresh key.

Save your recovery codes

You get ten, each looking like A1B2C-3D4E5-F6A7B-8C9D0, issued the moment your account confirms its first credential of either kind — a passkey or an authenticator app, whichever you set up first. This is the only time they are shown. There is no screen that reads them back to you later, by design — if there were, anyone who reached your open device could collect them.

Each one works once, in place of a passkey or an authenticator-app code. Put them somewhere you can reach without your device: a password manager on your computer, or printed and filed. A screenshot in your phone’s photos is the one place that does not help, because losing the phone is the case they exist for.

Typing them is forgiving — case, spaces and dashes are all ignored, so a1b2c 3d4e5 f6a7b 8c9d0 is the same code.

Sign-in security shows how many you have left, and turns the count red at two or fewer. Generate new codes issues a fresh set of ten and asks for your password first. Regenerating cancels every previous code, used and unused alike — so replace your saved copy at the same time, or the sheet you kept is worthless.

Signing in from then on

If you have a passkey and your browser recognizes it, you may not need to type anything: signing in offers your passkey as soon as you focus the email field, and confirming it with a fingerprint, face, or PIN signs you straight in. There is also a Sign in with a passkey button below the form if your browser does not offer it automatically.

Otherwise, you enter your password as usual, then a second screen asks for a second credential — either Use your passkey instead, or a Code typed from your app. Type the 6-digit code, or one of your recovery codes. Signing in with Google asks for a second factor too, the same way — the credential is on your account, not on any one way of reaching it.

A few things worth knowing before they surprise you.

If you lose your device

Sign in with one of your recovery codes, using whichever second-factor prompt you land on — the codes work at either. Then, on Your account, remove the lost passkey or turn off the authenticator app — both ask for your password — and set up a fresh one on your new device. There is no way to move an existing passkey or authenticator-app setup to a new device on its own; removing it and setting up again is the route, and it takes a minute.

If you have lost the device and have no recovery codes left, you cannot get back in on your own. We cannot see your codes, your passkey, or your authenticator setup key, so there is no switch we can throw from a chat window either. You will need to email us — and because this is a sign-in problem, the in-app form cannot carry it. Get help from a person has the address, and it is also the Contact link at the foot of our public pages, which is the one that works when you cannot get in at all. Expect to be asked to prove the account is yours.

That paragraph is the reason saving your recovery codes matters. Everything else here is recoverable; this one case is not.

What it does not cover

Signing in with a passkey or an authenticator app is per person. Everyone on your account sets it up for themselves, and there is currently no account-wide setting that requires it of your whole team — setting it up for yourself does not change how a colleague signs in, and does not tell you whether they have.

It does not touch the people answering your eflows. Respondents never sign in at all, so nothing about this changes what they see.

Removing your last passkey or turning off your last authenticator app, on Your account, needs your password and takes effect immediately: once you have no credential left, your account goes back to password-only and your recovery codes are destroyed. Setting one up again later issues a new set of codes.

Using Acquainto already? The same guides are in the product under Help & support, with the ones that only make sense signed in.