Last reviewed: 2026-08-17 · Report a change
Try it in your browser: Test this device for passkey support · Try the passkey ceremony with a throwaway demo
How a passkey works
When you create a passkey, your device and the service create a matched key pair. The public key is stored by the service. The private key remains with your passkey provider, such as the credential manager built into a device or a trusted password manager. During sign-in, the service sends a challenge. Your device signs that challenge, and the service verifies the answer with the public key.
The private key is not typed and is not sent to the website. The device unlock gesture only authorizes local use of the credential. A fingerprint or face image is not uploaded as the passkey. This separation is why passkeys can be both easier to use and harder to steal than a memorized password.
Why passkeys resist phishing
A passkey is created for a specific website identity. A lookalike domain cannot ask the authenticator to produce valid proof for the real domain. NIST describes this property as verifier name binding, and FIDO calls passkeys phishing-resistant. The browser and authenticator enforce the domain relationship instead of asking the user to notice every subtle spelling difference.
That does not make every account workflow safe. Attackers may still target recovery, trick users into approving account changes, or steal an already authenticated session. You should still verify unexpected messages, keep devices updated, review sessions, and protect the account used to sync passkeys.
Synced and device-bound passkeys
A synced passkey can be available on several devices through a passkey provider. This is convenient when replacing a phone or using a laptop and phone together. The provider protects the synced credential with its own account security and recovery controls. A device-bound passkey stays on one authenticator, such as a hardware security key, and may be preferred when strict separation is important.
The right choice depends on the account and recovery plan. Consumers often benefit from reputable synced passkeys because losing one device does not automatically mean losing access. High-risk administrators may use device-bound security keys and register more than one key. In either case, avoid having a single physical device as the only route back into the account.
Creating and using a passkey
Open the service from a trusted bookmark and visit its security settings. If passkeys are supported, the service may offer Create passkey, Add passkey, or Security key. Follow the operating system prompt and give the credential a recognizable name if asked. The name helps you remove an old phone or key later.
At the next sign-in, choose the passkey option and approve the device prompt. If the passkey is on a nearby phone, the browser may show a QR code used to establish a secure proximity flow. Scan such a code only when you initiated the sign-in on a trusted computer and the browser clearly identifies the expected service.
Passkey recovery and device changes
Before removing an old device, confirm the passkey is available on the replacement or add another passkey. Review the provider's sync and recovery model. Keep the provider account itself protected with strong authentication because it may hold credentials for many services.
If a service says no passkey is available, try the official alternative sign-in or recovery route. Do not install a browser extension or call a phone number from a pop-up that promises to restore a passkey. Recovery procedures vary by service, so login.com links to official help rather than inventing a universal recovery sequence.
Practical checklist
How to put this into practice
- Open the service's official website and go to account security settings.
- Confirm that passkeys are listed as a supported sign-in method.
- Choose Create or Add passkey and approve the device prompt.
- Name the device or key clearly if the service offers that option.
- Register a second recovery method before removing any old credential.
- Test the passkey in a fresh browser session and review the device list.
At a glance
Compare the options
| Feature | Passkey | Password |
|---|---|---|
| Secret typed into websites | No | Yes |
| Bound to the real domain | Yes | No |
| Can be reused across sites | No | Often, though unsafe |
| User experience | Device unlock | Recall and type a string |
| Recovery dependency | Provider and service plan | Reset email or service plan |
Decision guidance
Choosing the right approach
A passkey is a strong default when the service, browser, operating system, and recovery plan all support it. For an everyday account, a reputable synced passkey can make device replacement easier. For a high-risk administrator, separate hardware security keys may offer clearer custody. The right answer is not simply “sync” or “device-bound”; it is the model you understand and can recover without one fragile device.
Before replacing a password, check three boundaries: where the passkey is stored, which account can restore that provider, and what the service does when no passkey is available. Add a second passkey or another approved method, sign out, and test a fresh sign-in. Only then remove an older credential. A smooth setup prompt is not evidence that recovery has also been prepared.
Passkeys reduce fake-site credential relay because the authenticator checks the website identity. They do not prevent a stolen authenticated session, malicious recovery change, or consent granted to a hostile application. Keep reviewing sessions, connected apps, recovery contacts, and device access even after passwordless sign-in works.
Operational test
Rehearse the moments when security usually fails
Start with an ordinary device change. Imagine the phone or computer used for this control is unavailable today, not after a carefully planned migration. Identify which trusted device, independent authenticator, recovery code, provider account, or administrator would restore access. Then verify that route without deleting the working method. For What is a passkey? A clear guide to passwordless login, the practical starting action remains: Open the service's official website and go to account security settings. A recovery plan is only useful when the contact information is current and the required material can be reached without first unlocking the same account.
Next rehearse a suspected compromise. Do not answer the suspicious message or use its link to investigate. Open the known service independently, review recent sessions and security changes, and preserve evidence before removing anything. Rotate a reused password, revoke unfamiliar applications, and replace any exposed backup secret. If a second factor produced an unexpected prompt, deny it and assume the primary password may already be known. A strong authenticator helps prevent entry, but it does not clean up a stolen browser session, changed recovery address, malicious forwarding rule, or newly authorized application.
Finally, test the managed-account case. Workplaces, schools, families, and enterprise plans can place sign-in policy with an administrator or external identity provider instead of the service itself. Learn who can reset the control, what proof that person requires, and how an urgent request is authenticated. Never weaken the whole organization to solve one member's lockout. Record the official help route and an internal contact before a problem occurs, and separate administrative recovery from unsolicited support messages. This turns the comparison above—from Secret typed into websites onward—into a maintainable choice rather than a one-time setup.
Common questions
What is a passkey? A clear guide to passwordless login FAQ
Is a passkey my fingerprint?
No. A fingerprint or face scan can unlock the credential locally, but biometric data is not the passkey sent to the service.
Can a passkey be copied?
Synced passkeys can be securely made available through a provider. The service receives only cryptographic proof, not the private key.
Do passkeys replace 2FA?
A passkey can be a strong single authenticator and may satisfy multifactor requirements when locally unlocked with another factor. Service policies vary.
What happens if I lose my phone?
Use another synced device, a backup passkey, or the service's official recovery method. Prepare this route before the device is lost.
Should I delete my password immediately?
Keep the service's supported recovery path intact until you have tested the passkey and registered a safe backup.
Apply the idea
Representative service guides
Primary guidance
Sources and further reading
Product interfaces and available methods change. Re-check each service's official help before changing a security setting, and prepare recovery before removing an older authenticator.