RutoWallet Docs
TopicsAccount Security

Account Security

Learn how passwordless login, email codes, authenticators, passkeys, trusted devices, and sensitive-action verification protect RutoWallet accounts.

RutoWallet uses passwordless account access. Users do not create or enter a RutoWallet account password.

Email Sign-In

For direct email sign-in, the user enters their registered email address and verifies the single-use code sent to that address. This email-code step is always completed before any enabled authenticator or passkey challenge; a passkey cannot replace it.

Google sign-in may be available on supported clients. Additional RutoWallet security verification can still be required after Google sign-in.

Authenticator and Passkey Verification

Users must enable an authenticator before adding a passkey from an authenticated RutoWallet session. A passkey is created and protected by the user's device or password manager.

An enrolled passkey remains active only while authenticator-based two-factor authentication is enabled. Disabling the authenticator suspends the passkey in the database without deleting its credential; completing authenticator setup again automatically reactivates it. When both methods are enabled, the user chooses which method to use after the initial sign-in proof.

After email-code or OAuth sign-in, an account with another active session used within the last 30 minutes may also choose Confirm from another device. The active device receives the requesting device and IP details and can accept or decline the short-lived sign-in request.

Passkeys may also be offered instead of an authenticator code in other flows that require two-factor verification, after the user has enrolled a passkey.

Sensitive Actions

Depending on the action and risk checks, RutoWallet may require a six-digit transaction passcode, an email verification code, an authenticator code, a passkey, identity verification, or another security check. The verification shown in the app is the one that applies to that action.

A wallet withdrawal may require a fresh email verification code. Sending money and other supported actions may require the transaction passcode or another configured security challenge.

New and Trusted Devices

RutoWallet records device and session security information. Direct email login already verifies email ownership, so RutoWallet does not send a redundant second email code only because a device is new. Once required verification succeeds, the device may be treated as trusted, subject to later risk checks, session expiry, revocation, or account changes.

What RutoWallet Stores for Passkeys

RutoWallet stores the public credential information needed to recognize and verify an enrolled passkey, including a credential identifier, public key, device label, usage counters where available, and relevant timestamps. The passkey private key remains protected by the user's device or password manager.

RutoWallet does not receive or store the user's fingerprint image, face template, device PIN, screen-lock secret, or passkey private key. Biometric or device-unlock checks are performed locally by the user's device.

Protecting Your Account

  • Keep access to the registered email account secure.
  • Do not share email codes, authenticator codes, transaction passcodes, or recovery information.
  • Enroll passkeys only on devices or password managers you control.
  • Remove security methods or trusted sessions you no longer recognize.
  • Contact support immediately if you suspect unauthorized access.

Last updated September 6, 2026