If your Passkey syncs successfully but signing fails, it's almost always due to device permissions or browser settings. Before suspecting a broken wallet, check these two things: make sure the current website domain matches exactly the domain where you stored the Passkey, and then check whether the browser has permission to access your phone or computer's security chip.
Step 1: Verify the RP ID (Relying Party ID)
Passkey and the website domain at creation are bound together – this is called the RP ID. A Passkey stored on web.token.im won't work on test.token.im or other subdomains. imToken Web also clearly states that Passkeys are bound to the official domain to prevent phishing.
How to check: Look at the full domain in your browser's address bar. Is it exactly the same as when you created the account? Check for extra
www, a missing letter, or if you're using an IP address.Done when: The domain in the address bar matches exactly the one where you stored the Passkey, including the subdomain.
Step 2: Check the Passkey Provider Permission for Cloud Sync
After Passkey syncs to a new device, the system needs to know which app or password manager you allow to provide the key.
Case A: iPhone users
How to check: Open "Settings" → "General" → "Autofill & Passwords", make sure "Autofill Passwords" is on and "iCloud Passwords & Keychain" is checked. If it's off, the system won't retrieve Passkeys from iCloud Keychain.
Done when: "Autofill Passwords" is on and "iCloud Passwords & Keychain" is selected.
Case B: Android users
How to check: Open "Settings" → search for "password" or "Passkey" (paths vary by brand; it may be under "Google" → "Password Manager" or "System & updates"). Confirm that your Google account or the default password manager is enabled as the Passkey provider.
Done when: System settings explicitly show that your current account can serve as a Passkey provider.
High‑risk note: Some Android models (such as certain Huawei, Xiaomi, vivo, OPPO devices) do not support Passkey and may not be able to sign or create accounts properly on imToken Web. If you use one of these models, consider switching to a supported device or using a PC browser (Chrome, Edge, Safari).
Step 3: Check Browser Permissions and Compatibility
Browser security mechanisms can also block websites from calling Passkeys.
How to check:
Update your browser: Make sure you're using the latest version of Safari, Chrome, or Edge. Older versions may have incomplete Passkey support.
Clear cache and cookies: Some temporary data can interfere with the authentication process. Clear site data for
web.token.imand retry.Check for incognito/private mode: Some browsers' private modes disable WebAuthn APIs like Passkey. Exit private mode and try again.
Done when: Browser is up to date, site data cleared, and you retry signing in normal mode.
Step 4: Confirm User Verification Requirements
This is the most overlooked pitfall. Some websites require biometric verification (Face ID/fingerprint) when signing. But if you disabled the permission for "Password Autofill" to use Face ID or fingerprint, the system will silently fail, possibly without any prompt.
How to check (iPhone): Open "Settings" → "Face ID & Passcode" → "Use Face ID For", and make sure "Password Autofill" is on. If off, no face verification will pop up, and signing will fail silently.
Done when: The biometric switch for "Password Autofill" is enabled.
Common Failure Reasons
Domain has an extra
www: If you stored the Passkey ontoken.im, it won't work onwww.token.im. This is due to strict RP ID matching, not a bug.Bluetooth off or no internet during cross‑device signing: If you use a phone to scan a QR code for signing on a PC, both devices need Bluetooth enabled and internet access, otherwise you'll get a "device cannot connect" error.
After Completing the Checks
How to verify: After checking all permissions, try a transaction or authorization on imToken Web again. See if the system shows a Face ID, fingerprint, or PIN verification window. If the verification window appears, the channel is open; if you still get errors or no response, go through the steps again one by one.


