Passwords are hard to remember and easy to steal. Passkeys offer a simpler sign-in method that uses cryptographic credentials stored on your phone, computer, or security key. Instead of typing a reusable secret, you approve the sign-in with the same screen lock you already use, such as a fingerprint, face scan, or device PIN.
What a passkey actually is
A passkey is based on public-key cryptography. When you create one, the service stores a public key while your device or credential provider protects the corresponding private key. The private key is not sent to the website during sign-in. Your device proves that it possesses the credential without revealing it.
This design makes passkeys resistant to common phishing attacks. A fake website cannot simply capture a passkey and reuse it elsewhere because the credential is bound to the legitimate site. CISA identifies FIDO/WebAuthn authentication as a widely available phishing-resistant option.
Passkeys versus passwords and codes
A password can be copied from a data breach, guessed, reused, or entered into a convincing phishing page. A one-time code adds protection, but a person can still be tricked into sharing it in real time. A passkey removes the shared password from the exchange and lets the browser or operating system verify the site before the credential works.
Passkeys do not make every account problem disappear. An attacker who controls an unlocked device or compromises a cloud account that synchronizes credentials may still create risk. Recovery settings, device security, and account alerts therefore remain important.
Check your devices before setup
Update the operating system and browser on the phone or computer you plan to use. Turn on a strong screen lock and add a secure recovery method to the Apple, Google, Microsoft, or password-manager account that may synchronize the credential. Remove old devices you no longer control from that provider’s account page.
If the account supports passkeys, you will usually find the option under Security, Sign-in methods, or Password and authentication. The wording varies. Begin with an important service you use regularly, but avoid changing several accounts at once until you understand how recovery works.
How to create your first passkey
- Sign in to the real service using your normal method and navigate directly to its security settings.
- Select the option to create or add a passkey.
- Confirm where the credential will be stored, such as the current device, a credential manager, or a hardware security key.
- Approve the setup with your fingerprint, face scan, or device PIN.
- Give the passkey a clear device name if the service offers labels.
- Sign out and test the new method before changing any backup options.
Never create a passkey after following an unexpected link in an email or text. Open the official app or type the known website address yourself. DaiLova’s guide to spotting fake online stores explains several URL and payment warning signs that also help when evaluating unfamiliar sign-in pages.
Using a passkey on another device
Some passkeys synchronize through a credential provider, making them available on your other signed-in devices. In other cases, a website may display a QR code so you can approve the sign-in from a nearby phone. Bluetooth proximity may help confirm that the phone is physically near the computer.
Read the prompt carefully. A legitimate cross-device flow should identify the service you are accessing and should not ask you to send a QR code, PIN, or screenshot to another person. If a caller claims to be support and asks you to approve a passkey prompt, stop and contact the company through a verified channel.
Keep more than one safe recovery path
Before removing a password, verify what happens if your phone is lost, damaged, or replaced. Depending on the service, recovery might use another synchronized device, a second passkey, a hardware security key, recovery codes, or a verified identity process. Store recovery codes offline in a secure place rather than in an unprotected note or screenshot.
For a high-value account, consider registering a second passkey on another device or hardware key that you control. Do not register a shared workplace or household device unless you fully understand who can unlock it. Review registered passkeys periodically and remove entries for devices you sold, returned, or lost.
Should you delete the password?
Some services allow passwordless accounts, while others retain the password as a fallback. If a weak, reused password remains active, it may still be an attack path. Replace it with a unique strong password and enable the strongest available multifactor protection until the service clearly supports safe password removal.
A password manager remains useful because many sites have not adopted passkeys and because some managers can store both passwords and passkeys. The goal is not to switch every account overnight. Prioritize email, financial, cloud-storage, and social accounts, then work through the rest during a regular digital security checkup.
Passkey safety checklist
- Use a strong device screen lock and keep software updated.
- Create passkeys only from the official app or site settings.
- Protect the account that synchronizes your credentials.
- Maintain a tested backup or recovery method.
- Register a second credential for critical accounts when supported.
- Remove passkeys associated with devices you no longer own.
- Treat unexpected approval prompts as suspicious.
The practical takeaway
Passkeys reduce two of the biggest weaknesses in everyday authentication: reusable passwords and phishing pages that steal them. Start with one well-supported account, test sign-in and recovery, then expand gradually. The safest setup combines phishing-resistant credentials with well-protected devices and recovery options you have verified yourself.