Help center

Help center

All collectionsSettings and accessYour accountRegister a biometric signing credential

Register a biometric signing credential

Register the biometric credential and signing password you use to sign workflow transitions, read its certificate, and rename, download or delete it.

Register the biometric credential and signing password you use to sign workflow transitions, read its certificate, and rename, download or delete it.

A signing credential is what you sign with when a workflow transition requires an electronic signature. It combines three things: a biometric check on your device (fingerprint, face recognition or a security key), a signing password that you choose, and a personal certificate that ComplyTrain issues from your organisation's certificate authority. Everyone can register signing credentials, and each person manages only their own.

A signing credential is separate from the passkey you may use to sign in. Registering one does not create the other; see Secure your sign-in with MFA and passkeys.

Open your credentials

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

Select your name at the top of any page and choose Signing Credentials. You can also open Settings, Security, Credentials.

About Biometric Credentials explains the purpose of the page. Your Biometric Credentials lists what you have registered, with a count such as 1 credential registered. With none registered, the page shows No Credentials Registered: you need at least one to sign workflow transitions. Security Best Practices at the bottom repeats the habits that keep signing reliable.

Check your browser and device

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

Registration needs a browser that supports WebAuthn, such as a current version of Chrome, Firefox, Safari or Edge. In a browser without it, the page shows Browser Not Supported and Register New Credential is not offered.

The authenticator must also support the WebAuthn PRF extension, which ComplyTrain uses to protect your signing key. Built-in authenticators such as Touch ID and Windows Hello, and FIDO2 security keys that support PRF, can be used. When your computer has a built-in authenticator, the registration form shows Platform authenticator detected (Touch ID / Face ID / Windows Hello).

A credential belongs to the device or security key it was created on. Register one on each device you sign from.

Register a credential

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

  1. Choose Register New Credential.

  2. In Device Name, keep or change the suggested name, for example "MacBook Pro Touch ID". It identifies the device in your list and in your certificate.

  3. In Signing Password, enter a password of at least 8 characters. You will type it every time you sign with this credential.

  4. Choose Register Credential. Authenticating... appears.

  5. Complete the biometric prompts from your browser or device. Your device may ask twice: once to create the credential and once to confirm it.

  6. Wait for Credential Registered!, which shows the device name and the status Active. Choose Done, or wait for the dialog to close itself.

Field

What it does

Limits

Device Name

Names the credential in your list and in the certificate issued for it.

Required. Up to 100 characters.

Signing Password

A second factor for signing, used with the biometric check. It protects the signing key, so ComplyTrain cannot recover it for you.

Required. At least 8 characters.

If registration fails, Registration Failed explains why and lists Common solutions:. The usual causes are a cancelled or timed-out prompt, a device on which this authenticator is already registered, a biometric method that is switched off on the device, or an authenticator without PRF support. Choose Try Again to go back to the form.

Your signing password belongs to this credential only. To use a different signing password, register a new credential with it and delete the old one.

Read the certificate

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

Select a credential to expand it. Its summary line shows the name, when it was created, the type WebAuthn / FIDO2, the certificate's health and Last used:, or Never for a credential you have not signed with yet.

The certificate's health is one of these:

Status

Meaning

Valid

The certificate can be used for signing.

Expiring Soon

The certificate expires within 30 days. Valid Until shows the days left.

Expired

The certificate is past its Valid Until date. Register a new credential to keep signing.

Revoked

The certificate has been withdrawn. The technical details show when and why.

PKI Certificate shows Serial Number, Common Name (your email address), Valid From, Valid Until, Key Algorithm, Key Size, Signature Algorithm and Usage Count, the number of signatures made with it. A certificate is valid for one year from registration, but never beyond the expiry of your organisation's certificate authority.

Show Technical Details adds the Subject Distinguished Name (your email address, the device name and your organisation), the Issuer Distinguished Name, the Certificate Fingerprint (SHA-256), the Certificate Status (Active, Revoked or Inactive) and the time of the Last Signature.

Device Information shows the Browser, Platform, Registered and Last Used times and the Transport the authenticator used. Its own Show Technical Details adds the User Agent, the WebAuthn Credential ID and the Authenticator GUID.

Rename or download a credential

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

To rename a credential, expand it and choose the pencil button (Rename credential) beside Credential Name. Type the new name, up to 100 characters, and choose the tick button (Save) or press Enter. The cross button (Cancel) or Esc leaves the name unchanged. The new name is used in your list and in the signing dialog. The certificate keeps the device name it was issued with.

To download the certificate, choose Download PEM in PKI Certificate. ComplyTrain saves a .pem file named after the credential and the start of its serial number. The file holds only the public certificate, never your signing key. Give it to an auditor or another system that needs to check signatures made with this credential.

Delete a credential

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

  1. Expand the credential and choose Delete Credential.

  2. Check Delete Credential?, which shows the Device Name, when it was Registered and how many Signatures it has made.

  3. Read What happens when you delete?: the device can no longer sign transitions, signatures already made remain valid, and you must register again to use the device later.

  4. Choose Delete Credential. Credential Deleted confirms it. Choose Done.

You can delete any credential, including your last one. Without a credential you cannot sign until you register a new one.

Where the credential is used

Product location: /document-vault/vaults/{vaultId}/documents/{documentId} (fallback: /document-vault). Open the document in Documents. Choose a workflow action that requires a signature.

You use your signing credential whenever a Document Vault workflow transition requires an electronic signature. That includes documents that other modules file in a vault and route through a signing workflow, such as a signed copy of a QMS process run record and management review minutes.

When you choose such a transition, ComplyTrain opens Choose Signing Credential and checks which of your credentials are available on the device in front of you. Credentials registered on other devices are marked Other Device, and credentials whose certificate is expiring or expired say so. Choose an available credential and Continue with Selected Credential. Then enter your Signing Password and, where the transition asks for one, a Signature Reason, choose Sign Transition and complete the biometric prompt.

If none of your credentials are on this device, the dialog offers Register a credential on this device. If you have none at all, Biometric Credentials Required links to this page. See Sign a document workflow action for the whole signing task.

Example: sign approvals from two devices

Product location: /settings/security/credentials. Select your name at the top of the page and choose Signing Credentials. Or open Security, then Credentials, in Settings.

Suppose Mikkel, a quality manager, approves procedures on his office laptop and sometimes on a tablet at the production site. On the laptop he registers "Office laptop Touch ID" with a signing password. On the tablet he opens Signing Credentials and registers "Site tablet Face ID" with its own signing password. Both appear in his list with the status Valid.

When he approves a procedure on the tablet, Choose Signing Credential marks the laptop credential Other Device and offers the tablet credential. After the tablet breaks, he deletes "Site tablet Face ID" from his laptop. The signatures he already made with it remain valid, and the laptop credential keeps working.

Did this answer your question?
😞
😐
😁