Skip to content

Passkeys, sign-in links & more

Besides the password and single sign-on, DataSquares offers faster ways to sign in on the web and in the Android app. Each is on for every organization until an administrator switches it off.

Method Where Counts as two factors?
Passkey — fingerprint, face or device PIN Web and Android Yes — no authenticator code follows
Emailed link or code Web and Android No — the authenticator code is still asked for
Google (existing members only) Web and Android No — the authenticator code is still asked for
Approve from the phone — scan a code with the app Web (the app approves) Yes
Remember this device after the authenticator code Web and Android Skips only the code, for 30 days

A passkey is a sign-in key your phone, computer or password manager keeps for you. Signing in asks for your fingerprint, face or device PIN — nothing to type, nothing to phish. DataSquares passkeys belong to datasquares.ai, so one passkey works on the web and in the Android app.

  1. Sign in the usual way, then open Settings → Security → Ways to sign in and choose Add a passkey. (DataSquares also suggests it after you sign in — at most twice.)
  2. Confirm with your fingerprint, face or device PIN. If you signed in more than ten minutes ago, you are asked for your password (or an authenticator code) first.
  3. Next time, pick your passkey from the email field’s suggestions, or choose Sign in with a passkey.
  • Manage passkeys under Settings → Security: each shows where it was added, when it was last used, and Synced when your provider keeps it on several devices. Rename or remove any of them there.
  • Every new passkey is emailed to you. If you didn’t add it, remove it and change your password.
  • Two factors in one. A passkey needs the device (something you have) and your fingerprint, face or PIN (something you are or know), so no authenticator code follows it.

Enter your email and choose Email me a sign-in link. If the address has an account, an email arrives with a Sign in button and a 6-digit code:

  • Tap the button on the device you want to sign in on, or type the code where you asked for it.
  • Both work once, for 10 minutes; asking again retires the earlier ones, and five wrong codes retire the email.
  • The page always answers the same way, so it never reveals whether an address has an account.
  • An emailed link proves only the mailbox: if your account uses an authenticator app, you are still asked for its code.

Existing members can continue with their Google account. The first time, the Google account is linked to the DataSquares account with the same address — but only where Google owns the address (a Gmail address, or a Google Workspace account on your company’s domain), and you are emailed about it. Otherwise, sign in another way and link Google under Settings → Security. Google sign-in never creates an account; ask your administrator for an invitation.

On a computer, choose Sign in with your phone. A QR code and a two-digit number appear:

  1. Scan the QR code with the camera of a phone where the DataSquares app is signed in. The app opens and shows which browser is asking, and from which network address.
  2. Type the number shown on the computer, and approve. The app may ask for the phone’s own lock first.
  3. The computer signs in as you — once. You are emailed about it.
  • The request lasts 60 seconds.
  • A wrong number declines the request for good; show a new code instead.
  • Only the signed-in app can approve — not a browser, and not an API key.
  • The QR code carries no secret; a photo of the screen cannot sign anyone in.
  • Approve only a sign-in you are doing yourself, right now. Nobody from DataSquares will ever ask you to scan a code to “verify” your account.

On the two-factor step, tick Remember this device for 30 days (in the app: Remember this phone). For 30 days that browser or phone skips the authenticator code — only the code: the password, link or Google step still happens.

  • Your remembered devices are listed under Settings → Security; Forget one, or Forget all.
  • Changing or resetting your password, or turning two-factor off, forgets them all.
  • A recovery code never remembers the device.
  • Tick it only on a device you alone use.

Under Administration → Settings → Authentication → Ways to sign in, switch each method on or off for the whole organization: passkeys, emailed sign-in link, Sign in with Google, sign in with the phone, and remembering devices. Each change is written to the Audit Log as company.security_policy.

Every sign-in’s method is recorded on its user.login audit event (method: password, passkey, magic_link, google or handoff, and mfa: how the second factor was met). New passkeys (user.passkey_added), linked Google accounts (user.google_linked), remembered devices (user.trusted_device_added) and phone approvals (user.handoff_approved) have their own events.