What a passkey is and why you'd use one

A passkey is a way to sign into an account using your phone instead of typing a password. When you create a passkey, your phone stores a unique digital key that proves who you are. You unlock it with your fingerprint, face scan, or PIN — whatever your phone already uses to unlock itself.

The main reason to use a passkey: you do not have to remember or type a password. Your phone handles the proof of identity automatically. If a website gets hacked, the hackers cannot steal your passkey because it never leaves your phone and is not stored on the website's servers the way a password is.

Not every website or app supports passkeys yet. Banks, Google, Microsoft, Apple, and major social platforms have added them. Smaller services are slower to adopt. You can still use passwords for accounts that do not offer passkeys.

Key Takeaways

  • Passkeys are stored on your phone and unlocked with your fingerprint or face, so you never type a password into a website.
  • You create a passkey directly in the account settings of a website or app that supports them — look for a "Security" or "Sign-in options" section.
  • Your phone will ask you to confirm your identity with your fingerprint, face, or PIN before the passkey is created.
  • If you lose your phone, you can still sign in using a backup method the website provides, usually a recovery code or a second phone.

Where to find the passkey option on a website or app

The location varies by service, but the pattern is the same. Sign into your account on the website or in the app, then look for account settings. This is often under your profile picture or name in the top corner, or in a menu labeled "Settings," "Account," or "Security."

Once you are in settings, search for a section called "Sign-in options," "Security," "Authentication," or "Passkeys." Some services put it under "Password and sign-in" or "How you sign in." If you cannot find it, use the search function within settings — most websites have one — and search for "passkey."

When you find the passkey section, you will see a button or link that says "Add a passkey," "Create a passkey," or "Set up passkey." Click or tap it to start.

The steps to create a passkey on Android

Once you tap the button to create a passkey, the website or app will ask you to confirm your identity. This is a security check — it makes sure you are actually the account owner. You will be asked to use your fingerprint, face scan, or PIN, depending on what your phone is set up with.

Place your finger on the sensor or look at your phone's camera, or enter your PIN if that is your unlock method. This happens on your phone, not on the website. The website never sees your fingerprint or face — it only sees that you confirmed your identity.

After you confirm, your phone creates the passkey and stores it. The website will show a confirmation message saying the passkey was created. You are done. The next time you sign into that account on your phone, you can choose to use the passkey instead of typing your password.

Using your passkey to sign in

When you visit the website or open the app and reach the sign-in screen, you will see options for how to sign in. One option will be your passkey — it might say "Sign in with passkey," "Use passkey," or show your phone's name.

Tap that option. Your phone will ask you to confirm your identity again using your fingerprint, face, or PIN. Once you do, you are signed in. No typing required.

If you are signing in on a different device — a computer or tablet — the process is slightly different. The website will show a QR code or ask you to scan something. You scan it with your Android phone, confirm your identity on the phone, and the other device signs you in. Your passkey stays on your phone the whole time.

What happens if you lose your phone or get a new one

If your phone is lost or stolen, you can still sign into your accounts. When you reach the sign-in screen, choose the option to sign in a different way — usually "Can't use your passkey?" or "Sign in another way." The website will offer a backup method, such as a recovery code you saved when you created the passkey, or a second phone number or email address.

If you get a new Android phone, you can move your passkeys to it. When you sign into your Google account on the new phone, Google automatically syncs your passkeys from your old phone to the new one. For passkeys stored in other apps or services, check that service's help section — some sync automatically, and some require you to create a new passkey on the new phone.

This is why it matters to save any recovery codes the website offers when you create a passkey. Write them down or store them in a password manager. If you cannot access your phone and cannot remember your recovery code, you may have to prove your identity to the website in other ways — usually by answering security questions or confirming your identity through email or phone.

Passkeys on Android versus passwords

A password is something you know and type. A passkey is something your phone knows and proves. The difference matters for security. If a website storing passwords gets hacked, the hackers get your password. If a website storing passkeys gets hacked, they get nothing — the passkey is not there. It is only on your phone.

Passwords can be guessed or cracked if they are weak. Passkeys cannot be guessed because they are long, random digital keys that your phone creates. You cannot accidentally use a weak passkey.

The trade-off: passkeys only work on devices you own. If you sign in on a friend's computer, you cannot use a passkey — you would need to use a password or another sign-in method. Passwords work anywhere. For accounts you access only on your own phone or computer, passkeys are simpler and safer. For accounts you access from many different devices, you might keep a password as a backup.

Frequently Asked Questions

Can I use the same passkey for multiple accounts?

No. Each account gets its own passkey. Your phone creates a different passkey for each website or app. This is intentional — it prevents one hacked website from giving a hacker access to all your accounts.

What if my phone does not have a fingerprint sensor?

You can still create a passkey. Your phone will use face recognition or your PIN instead. The process is the same — when you create the passkey or sign in, your phone asks you to confirm your identity however it is set up to unlock.

Do I have to delete my password if I create a passkey?

No. You can keep both. Most websites let you have a passkey and a password at the same time. You can sign in with whichever one you want. Some people keep the password as a backup in case they lose access to their phone.

Can someone else use my passkey if they have my phone?

Only if they can unlock your phone. A passkey requires your fingerprint, face, or PIN to use — the same thing that unlocks your phone. If someone steals your phone but cannot unlock it, they cannot use your passkeys.

What if a website I use does not support passkeys yet?

Keep using your password. Passkeys are new, and many websites have not added them. You can create a passkey on some accounts and use passwords on others. There is no rush to switch everything at once.