What a passkey actually is
A passkey is a way to sign into an account using your phone, computer, or security key instead of typing a password. When you create a passkey, you're storing a unique digital credential on a device you own and control. The website or app you're signing into never sees or stores your passkey itself — it only stores a mathematical match that proves you have it.
The practical difference: instead of remembering "MyDog2019!" and typing it every time, you unlock your phone with your face, fingerprint, or PIN, and that unlocks your account automatically. No password to remember, no password to steal from a database breach.
Passkeys work because they use public key cryptography, the same math that banks and governments use. You get two linked keys — one stays on your device (the private key), and one goes to the website (the public key). Only your private key can prove you're you, and you never send it anywhere.
Key Takeaways
- A passkey replaces your password with a credential stored on your phone or computer that you unlock with your face, fingerprint, or PIN.
- You create a passkey directly in the account settings of a website or app that supports them — usually under Security or Sign-In Options.
- Your passkey is tied to the specific device you create it on, but most services let you create multiple passkeys across different devices.
- If you lose the device your passkey is on, you will need a backup passkey or a recovery method the service set up when you created the first one.
- Passkeys work only on websites and apps that have built support for them, which is still a small fraction of the internet.
Where to find the passkey option on your account
The location varies by service, but the path is usually: Settings or Account Settings → Security or Sign-In Options → Passkeys or Passwordless Sign-In. Some services call it "Create a Passkey," others call it "Add a Passkey" or "Set Up Biometric Sign-In."
Major services that support passkeys include Google, Apple, Microsoft, Amazon, GitHub, and Dashlane. Smaller sites are adding support gradually. If you don't see a passkey option on a site you use, it probably doesn't support them yet — you can check by searching "[service name] passkey support" or looking in their help documentation under authentication or sign-in methods.
When you find the option, the service will ask you to confirm your identity first (usually by entering your current password or a code sent to your email). This is a safety check to make sure someone who isn't you isn't creating a passkey on your account.
The step-by-step process for creating one
After you've confirmed your identity, the service will ask you to create the passkey on the device you're currently using. The exact steps depend on your device, but the flow is the same:
- The website or app shows you a prompt to create a passkey.
- You choose which device to create it on (your phone, laptop, or security key).
- Your device asks you to unlock it — using your face, fingerprint, or PIN depending on what you set up.
- The passkey is created and stored on that device. The website stores only the public half of the credential.
- The service confirms the passkey is ready and shows you a backup or recovery option.
The whole process usually takes less than a minute. You don't type anything or create anything yourself — the device and the website do the work together.
What happens when you sign in with a passkey
Once you've created a passkey, signing in is faster than using a password. You go to the website or app, and instead of a password field, you see a button that says "Sign in with passkey" or "Use passkey." You click it, and your device asks you to unlock it (face, fingerprint, or PIN). That's it — you're signed in.
If you're signing in on a different device than the one your passkey is on, the service usually lets you use your phone as a remote unlock. For example, if your passkey is on your iPhone but you're signing into a website on your laptop, the laptop will show a QR code. You scan it with your iPhone, unlock your phone, and the sign-in completes on the laptop.
This remote unlock feature means you don't have to carry your passkey device with you to sign in from other computers, though you do need your phone nearby.
Creating passkeys on multiple devices
Most services let you create more than one passkey. This is useful because it means you're not locked out if you lose or break one device. You might create a passkey on your phone, another on your laptop, and a third on a physical security key you keep in a safe place.
To add a second passkey, go back to the same Security or Sign-In Options page and look for "Add another passkey" or "Create a new passkey." You'll confirm your identity again, then create the passkey on the new device. Each passkey is independent — losing one doesn't affect the others.
If you have passkeys on multiple devices, you can sign in using whichever device is most convenient at that moment. The website doesn't care which passkey you use, only that one of them proves you're you.
What to do if you lose access to your passkey
If you lose the device your passkey is on, you need a backup way to get back into your account. When you created your first passkey, the service should have shown you recovery options — usually a recovery code (a long string of characters you write down and store safely) or a backup passkey on a different device.
If you saved a recovery code, you can use it to sign in and create a new passkey on a different device. If you have a passkey on another device, you can sign in with that one and then create a new passkey to replace the lost one. If you have neither, you'll need to use the service's account recovery process, which usually involves confirming your identity through email or phone number.
This is why creating passkeys on at least two devices, or saving a recovery code, is worth doing the first time. It takes five minutes and prevents a locked-out account later.
Passkeys versus passwords: what actually changes
The main security difference is that passkeys are impossible to guess, steal through a phishing email, or compromise in a password database breach. A password is a string of characters you choose and remember — someone can trick you into typing it into a fake website, or a company can store it poorly and lose it. A passkey is a cryptographic credential that only works on the real website you created it for, and it never leaves your device.
The main convenience difference is that you don't have to remember anything. You unlock your device the way you already do (face, fingerprint, or PIN), and you're signed in. No password manager needed, though you can still use one for sites that don't support passkeys.
The trade-off is that passkeys are newer and not yet supported everywhere. If you use a service that doesn't support passkeys, you still need a password. And if you're very attached to remembering your own passwords, passkeys take that choice away — the device generates and stores the credential for you.
Frequently Asked Questions
Can I use the same passkey on multiple websites?
No. Each passkey is created specifically for one website or service. The math behind passkeys ties them to the exact domain you created them on, so a passkey for Google won't work on Amazon. This is actually a security feature — it prevents a hacked website from using your passkey to sign into other sites.
What if I switch phones or computers?
You'll need to create a new passkey on the new device. You can do this by signing in with a password (if the service still lets you), a recovery code, or a passkey on another device you own. Once you're signed in, create a new passkey on the new device and delete the old one from your account settings.
Is a passkey safer than a password manager?
Passkeys are safer in one specific way: they can't be phished. A password manager stores passwords that you can still be tricked into typing into a fake website. A passkey only works on the real website it was created for. Both are far safer than remembering passwords yourself, but passkeys remove one category of risk entirely.
Do I need a security key to use passkeys?
No. You can create passkeys on your phone or computer using your face, fingerprint, or PIN. A physical security key is optional and useful mainly if you want a backup passkey stored somewhere completely separate from your everyday devices.
What happens if the company that made my device goes out of business?
Your passkey stays on your device and keeps working. The device itself doesn't depend on the company's servers to function. If you want to move to a different device, you'd create a new passkey on the new device using a recovery code or a passkey on another device you own.