Skip to main content

Biometrics, passkeys, and facial enrollment

UbID uses two different biometric mechanisms:

  • Fingerprint/passkey access uses WebAuthn and the device authenticator. Depending on the platform, the prompt can use fingerprint, Face ID, Touch ID, Windows Hello, device PIN, a nearby device, or a hardware security key.
  • FaceTec enrollment creates a separate 3D facial-verification record used when an UbID policy requires identity proofing or reverification.

One does not replace the other.

Enable fingerprint or a passkey in the Identity Console

Prerequisites are an active session, a valid local identity key, a compatible browser, and a secure HTTPS connection.

  1. Open the Identity Console.
  2. Go to Security and select Digital footprint or the fingerprint/passkey manager shown by the deployment.
  3. Verify that the correct user ID is displayed and that the local key is available.
  4. Select Activate fingerprint/passkey.
  5. Follow the browser or operating-system prompt. Use the biometric, device PIN, or security key requested by that authenticator.
  6. Wait for UbID to confirm that the credential was verified and saved.
  7. Sign out and test Sign in with fingerprint/passkey before depending on it.

WebAuthn activation is disabled if the page is not using HTTPS, the browser does not support WebAuthn, or the local public-key metadata cannot be recovered.

Add or manage passkeys in the Vault

  1. Open Settings in the Vault.
  2. Under Manage other passkeys, choose Add passkey.
  3. Give the passkey a recognizable nickname, such as the device name.
  4. Complete the authenticator interaction. Some devices request a second interaction to finish PRF-based encryption setup.
  5. Confirm that the new passkey appears in the list and is marked as able to encrypt when required.

From this screen you can rename, upgrade, or delete a passkey. Keep at least one tested access or recovery method before deleting one.

Enroll your face with FaceTec

  1. In the Identity Console, open Verification & Biometrics and select FaceTec 3D enrollment.
  2. Confirm the displayed user ID and check whether the status is Pending or Enrolled.
  3. Select Start enrollment.
  4. Allow camera access when prompted.
  5. Center your face, remove obstructions if instructed, and follow the on-screen movement and lighting guidance.
  6. Wait until UbID reports that enrollment completed successfully.
  7. Use Refresh status and verify that the result is Enrolled.

If the session closes without confirmation, do not assume enrollment succeeded. Refresh the status before trying again.

Privacy and support guidance

  • A passkey record contains public authentication material; it does not send the local private identity key during login.
  • Facial enrollment is policy-controlled and distinct from the device biometric used to unlock a passkey.
  • Never record or distribute FaceTec session data or biometric diagnostic output through ordinary support channels.
  • If camera permission was denied, enable it in the browser site settings and restart the flow.