Still unable to log in to Bitwarden web vault using passkey

This is a special case resulting on the one hand from Bitwarden’s need to use either a master password derived key or a PRF derived key to decrypt vault, and on the other hand from the lack of support for PRF by Firefox browsers.

To experience true passwordless login using passkeys, either log in to a service that (unlike Bitwarden) doesn’t require encryption, or alternatively, log in to the Bitwarden Web Vault app from a browser that does support PRF (i.e., Chromium based browsers).

Storing exclusively in the vault makes little sense, but storing it both on your emergency sheet and in the vault makes complete sense to me. This makes is much easier to backup one’s vault, which is something that should be encouraged. And, it makes it easier to login to the web vault if you are already logged in locally.

There is a huge difference in risk between a login prompt that is publicly accessible and one that requires physical presence in front of the device.

Passkeys are designed to ensure that your secret (the “private key”) never leaves your computer, defending against a phishing website capturing the secret. A local login is very different in that the password never leaves your computer in the first place.

I completely understand how passkeys work, I’m just saying the marketting of them does not match the reality of them in this use case. I’m all for passkeys, especially given the way the general public handles their password management.

To your other point, I am definitely on the vault backup train. As a self-host user and a person that is constantly messing with my server/web vault setup, there’s little risk of losing my vault if I happen to trash the server, which I do from time to time.