Passkeys: A faster, more secure way to access your benefits Skip to content

Article

Passwords are out. Passkeys are in.

7 min read

Woman in a yellow shirt smiles as she looks at her smartphone.

Passkeys: A faster, more secure way to access your benefits across mobile and desktop

Passwords and one-time codes can be hard to remember — and easy for fraudsters to steal.1 Today’s cyberthreats call for smarter protection that works with your everyday life.

That’s why HealthEquity is rolling out passkey authentication for account access. Passkeys replace traditional login methods — no passwords, no one-time codes. Only simple passkey authentication for account access.

Passkeys are built into your device and let you sign in the same way you unlock your phone: using your Face ID, fingerprint, or device PIN.2 They are safe, fast, and phishing-resistant to keep your funds, personal info, and health data protected from fraud.

Check out our quick video about passkey.

Note: Videos are representative. The experience may vary slightly based on your benefits. If you use EZ Receipts, you’ll see the EZ Receipts brand throughout setup.

You’ll be prompted to set up your passkey when it’s time.

When passkey is enabled on your account, you’ll receive an email with set up instructions. The next time you log in — on mobile or desktop — you’ll be prompted to complete set up.

No action is needed until you’re prompted.

The phased rollout of passkey login began in Fall 2025 and will continue through 2026. All members who use both the EZ Receipts app3 (for Reimbursement Accounts and Commuter accounts), the HealthEquity Mobile app for (Health Savings Accounts) and web portals will be passkey enabled.

How to get ready for passkey

You’ll receive an email and see a prompt at login when it’s time to set up your passkey. To help make your setup smooth, here’s how to get ready:

1. Make sure you have a valid phone number in your profile

Log in now to your online account (on desktop) to add or update your mobile or landline phone number. A verified phone number is required to set up passkey.4

Important: Identity verification with a phone number is easiest. If you are unable to verify with a phone number, you may be prompted to take a selfie and compare it with a government-issued ID.5

If you haven’t set up your account(s) yet, visit our login help page to get started.

2. Download our mobile apps

If you haven’t already, download HealthEquity Mobile or EZ Receipts Mobile — or both, depending on which portal you typically use to log into your account.

You’ll need a unique passkey for each app. If your plan uses both apps, please download both now.

Note: Your EZ Receipts account must be activated online before using the EZ Receipts Mobile app.

3. Turn On app notifications

Enabling notifications in your HealthEquity and/or EZ Receipts Mobile app will help ensure you see passkey prompts during setup.


Mobile passkey authentication

When prompted by the “passkey required” email, you’ll use the HealthEquity Mobile app or the EZ Receipts Mobile app (or both depending on your plan) and web portals to set up your passkey and access your accounts — on mobile and web.

Follow 3 easy steps:

  1. Log in on a trusted device: Enter your credentials as usual. Then follow prompts to set up a passkey.
  2. Verify your identity: Choose to receive a one-time verification code via text message or voice call. If you are unable to verify with a phone number and your login credentials, you may be prompted to take a selfie and compare it with a government-issued ID.5
  3. Create your passkey on mobile app or web: Select your Face ID, fingerprint, or your device PIN as your passkey. Next time you log in, you will enter your username, followed by your passkey — no password required.

Why passkey is better: secure login that safeguards your funds, personal info, and healthcare data

Once you’ve set up a passkey, your login experience includes:

  • No passwords or one-time codes
  • Built-in security using your fingerprint, Face ID, or device PIN
  • Easy login across mobile and desktop

Passkeys are built on the FIDO2 and WebAuthn authentication standards — open, industry‑backed technologies adopted by global financial institutions and implemented across platforms from Apple, Google, and Microsoft.6

You get stronger protection without added steps; just fast, secure access to your benefits.

Security works best when we work together. Fraud prevention is a team effort. Monitor your account regularly and report any unusual activity as soon as you see it.7

For more information, please visit our Fraud and Security page.


Frequently Asked Questions

How do I set up a passkey?

When passkeys are enabled for your account, you’ll be prompted to set one up the next time you log in. You’ll need to complete setup to access your account – but it’s quick and secure.

Here’s what to expect:

  1. Download the mobile app.
    Download the HealthEquity Mobile app or the EZ Receipts Mobile app (or both, depending on your plan) to get started. If you’re using EZ Receipts, be sure to register with EZ Receipts online before using the app.

  2. Enter your username and password.
    Start by entering your username and password. We’ll check to verify it’s you and protect your information.

  3. Verify Your Identity.
    Select a verification method (text or voice call) to receive a one-time passcode, then enter the code to confirm your identity. If phone verification doesn’t work, we’ll verify you by comparing a selfie with a government-issued ID.

  4. Create Your Passkey.
    Your device will prompt you to create a passkey using your fingerprint, Face ID, or device PIN.

  5. Log in next time is easy.
    Once set up, your passkey will be saved for future logins — fast, secure, and password-free. Enter your username, select your passkey, you’re in!

Check out our mobile passkey how-to video.

Check out our desktop passkey how-to video.


Do I have to set up a passkey?

Once passkey login is available for your account, you’ll need to use it to access your benefits — on mobile or desktop. If you use SSO from your organization, a passkey is not required for SSO login. But direct use of HealthEquity’s mobile and web logins, including EZ Receipts, will require passkey.


When will I be required to use the mobile app and passkey to access my account?

As of Fall 2025, passkey login has been fully rolled out and is now required for members with Health Savings Accounts (HSAs) and Reimbursement Accounts (RAs) who use the HealthEquity Mobile app and web experience.

Passkey rollout for members using the EZ Receipts Mobile app, as well as those using both HealthEquity mobile and EZ Receipts, will occur in 2026.

When prompted at log in, you’ll complete passkey setup using the HealthEquity Mobile app, the EZ Receipts Mobile app and web portals — depending on your benefits. No action is needed until you’re prompted.


Why is identity verification necessary?

Your security is important to us. We want to ensure it is you accessing your account to set up passkey.


What is verification with a selfie and government-issued ID?

If verifying with a phone number doesn’t work, we’ll guide you through the selfie ID verification process — so we know it’s really you. The process will compare a selfie from your mobile phone camera with your government-issued ID.

Just a few minutes and you’re on your way to setting up a secure, phishing-resistant passkey — no passwords required from here on out. Your privacy is important to us. We will protect your personal information. See our Privacy Policy.

Check out our selfie and government ID mobile demo.
Check out our selfie and government ID desktop demo.


Will my devices and browsers support passkeys?

Most modern smartphones, tablets, and computers support passkeys.

  • Mobile: iOS 16+ (Safari), Android 10+ (Chrome)
  • Desktop: Windows 10+ (Edge/Chrome), macOS Ventura+ (Safari/Chrome), ChromeOS 109+
  • Browsers: Safari 16+, Chrome 109+, Edge 109+, Firefox 122+

If your iPhone or Android phone is running a recent operating system version (iOS 16+ or Android 10+) and has screen lock/biometric authentication enabled, it should support passkeys.


How do I know what software version my phone is on?

Find the software version on your iPhone, iPad or iPod touch through Apple Support.
Check and update your Android version with Android Help.


What if my device doesn’t support passkeys?

Most smartphones support passkeys. If yours doesn’t, you can still set up a passkey on a supported laptop, desktop or tablet computer. HealthEquity offers multiple authentication options to ensure accessibility. See the HealthEquity Digital Accessibility Statement. However, managing benefits on mobile is faster and easier than logging in online, start by downloading our mobile apps (based on your plan), which provide the easiest and most secure access.


Need help setting up your passkey?

Check out our Login Help page and Help Center to get started.

Still need help? Call 1-844-373-6979 to get passkey and login support.

HealthEquity does not provide legal, tax or financial advice. Always consult a professional when making life-changing decisions.

1Fido Alliance, “Passkey security.”

2Passkey set up is also available online using a desktop, laptop or tablet computer. A valid phone number is required to register a passkey. SSO login does not require passkey, but direct use of mobile or web login does require passkey. HealthEquity offers multiple authentication options to ensure accessibility and compliance with applicable laws. See our HealthEquity Digital Accessibility Statement. See our Biometric Data Policy. HealthEquity cares about your personal data.

3Accounts must be registered with EZ Receipts online before using the app.

4Voice over internet protocol (VoIP) numbers will not verify.

5Your privacy is important to us. We will protect your personal information. See our Privacy Policy.

6Digital Digest, “Passkeys Adoption Takes Password-Free Security Mainstream,” October 2025.

7For HSAs, accountholders must report any unauthorized activity within 60 days of statement posting.

For employer-sponsored plans (e.g., FSAs, HRAs), HealthEquity serves as a directed TPA. Different responsibilities may apply. Please consult your plan documents.

Review your HSA transactions online regularly, and your HSA statement monthly. Tell us immediately if your card is lost or stolen, or you see unauthorized transactions, by calling 1-866-346-5800.

You must notify us no more than 60 days from the time the HSA statement is made available.

Why 60 days? Fraud prevention is a collective effort. Recovery of funds is not guaranteed. The sooner you notify us, the more likely that funds can be recovered on your behalf.

As noted in your HSA Custodial Agreement, failure to report unauthorized transactions within 60 days means you have accepted the transactions, they might not be eligible for reversal, and you could be responsible for the transactions.

For more information, please visit our Fraud and Security page.

COBRA/Direct Bill Employer login

Please refer to your Client Welcome email for the URL of your specific COBRA/Direct Bill Employer login page.