Skip to main content

How to Secure GitHub with a Passkey

Sign In to GitHub Without a Password or 2FA

Web

From GitHub's Password and authentication settings, add a passkey, choose a security key instead of your device's built-in biometrics, then connect your Seedkeeper PRO to register it.

Overview

GitHub supports passkeys as a way to sign in safely and easily, without needing a password and a separate 2FA step - your Seedkeeper PRO covers both at once. That single step is also phishing-resistant, which a password plus a one-time code is not - see Passkey vs OTP.

Why choose the security key option?

The default your browser offers - Face ID, Touch ID, Windows Hello, or a synced credential manager - creates a perfectly valid passkey.

Choosing your Seedkeeper PRO instead changes three things:

  • The key exists in one place only. A synced passkey is copied across every device on your cloud account, and that account is usually protected by a password. A hardware passkey is generated inside a certified secure element and physically cannot leave it.
  • Nobody else is in the chain. No provider account, no cloud, no vendor login standing between you and your own credentials.
  • It travels. The same card or ring works on your phone, your laptop, and a machine that isn't yours - a work computer, a shared workstation - leaving nothing behind.

See "Not All Passkeys Are Stored the Same Way" for the full comparison.

Step-by-Step Instructions

Step 1: Go to Settings

In the upper-right corner of any GitHub page, click your profile picture, then click Settings.

Step 2: Go to Password and authentication

In the "Access" section of the sidebar, click Password and authentication.

Step 3: Add a passkey

Under Passkeys, click Add a passkey.

Step 4: Authenticate

If prompted, authenticate with your password or another existing method.

Step 5: Confirm

Under Configure passwordless authentication, review the prompt, then click Add passkey.

Step 6: Choose a security key instead of your device

You'll be offered your device's biometrics or a synced credential manager by default. Look for an option like Use another device or Security key instead, so you can register your Seedkeeper PRO.

Step 7: Connect your Seedkeeper PRO

Insert your Seedkeeper PRO, or tap it against an NFC reader.

Step 8: Enter your PIN

Provide your passkey PIN to complete the registration.

Step 9: Confirm

Review the confirmation that your passkey was registered, then click Done.

You can now sign in to GitHub using your Seedkeeper PRO instead of your password and 2FA.

Signing in to GitHub with a passkey

Removing a Passkey

Go to SettingsPassword and authentication, click the icon next to the passkey you want to remove, review the confirmation, then click Delete.

Keep at least one backup registered

If your Seedkeeper PRO is device-bound (not synced to a cloud provider), losing it means losing that passkey for good. GitHub recommends registering passkeys on at least two devices - see Passkey Backup Strategy.

Official GitHub Resources

FAQ

Does a passkey replace my GitHub 2FA?

Yes - signing in with a passkey covers both password and 2FA in one step.

Can I upgrade an existing security key to a passkey?

Yes, if you already registered your Seedkeeper PRO as a 2FA security key, GitHub may offer an upgrade option in the same Add a passkey flow. See Managing your passkeys for details.

Can I add more than one Seedkeeper PRO as a backup?

Yes, and it's recommended - see Passkey Backup Strategy.

Why register a Seedkeeper PRO instead of my phone's built-in passkey?

Because the key never leaves the device and is not copied anywhere. A synced passkey lives in a provider's cloud and is only as safe as your account with them; a Seedkeeper PRO passkey is generated inside an EAL6+ secure element and physically cannot be extracted. It also works on computers that aren't yours, which a phone-bound passkey does not. See Not All Passkeys Are Stored the Same Way.