What a passkey is and how it works

A passkey is a way to sign into an account without typing a password. Instead, your phone or computer proves who you are using something built into the device itself — usually your fingerprint, face scan, or a PIN you already use to unlock it.

When you create a passkey for a website or app, that site stores a digital record that says "this device belongs to this person." The next time you sign in, you don't send a password across the internet. Instead, your device unlocks itself (using your fingerprint or face), and that unlocking proves to the website that it's really you. The password never leaves your device, and the website never sees it.

Passkeys work because they use a type of security called public key cryptography. Think of it like a lock and key: the website holds the lock, your device holds the key, and only your key can open that particular lock. Your device keeps the key private — it never shares it, even with the website.

Key Takeaways

  • A passkey replaces a password by using your phone or computer's built-in security (fingerprint, face, or PIN) to prove who you are.
  • You create a passkey directly on the website or app that offers it, usually in account settings under security or sign-in options.
  • Passkeys are safer than passwords because they cannot be stolen, guessed, or tricked by fake websites — only your device can unlock them.
  • If you lose the device that holds your passkey, you can create a new one on a different device, but you will need a backup way to sign in first.
  • Not every website offers passkeys yet, but major platforms like Google, Apple, Microsoft, and Amazon have added them in the past two years.

Where to find the passkey option on common sites

Most websites that offer passkeys put the option in your account settings, usually under a heading like "Security," "Sign-in options," or "Password and authentication." The exact path varies, but the pattern is similar across platforms.

On Google, go to myaccount.google.com, select "Security" in the left menu, scroll to "How you sign in to Google," and look for "Passkeys." On Microsoft, visit account.microsoft.com, choose "Security," then "Advanced security options," and select "Passkey." On Apple, go to appleid.apple.com, click "Security," then "Sign-in and security," and choose "Passkeys." Amazon's option is in "Account & Lists," then "Your Account," then "Login & security," then "Passkeys."

If you do not see a passkey option on a site you use, it may not offer them yet. You can check whether a website supports passkeys by visiting passkeys.dev, which lists major platforms that have added them. If your bank, email provider, or social media account is not listed, they may add the feature later.

The step-by-step process for creating one

Once you find the passkey option, the process is straightforward and takes about two minutes. First, click the button to create a new passkey. The website will ask you to confirm your identity — usually by entering your current password or a code sent to your email or phone. This step proves you own the account before the site lets you add a new sign-in method.

Next, your device will ask you to unlock it using whatever method you normally use: your fingerprint, face, or PIN. This is the moment your device creates the passkey. You are not typing anything new — you are using the security your phone or computer already has. After you unlock your device, the passkey is created and stored on that device.

The website will then show you a confirmation message saying the passkey is active. Some sites will ask if you want to remove your password at this point. You can usually keep your password as a backup, or delete it if you are confident in your passkey setup. If you are new to passkeys, keeping your password for a few weeks while you test the passkey is a reasonable choice.

What happens when you sign in with a passkey

The next time you visit that website or app, instead of a password field, you will see a button that says "Sign in with passkey" or "Use passkey." Click it, and your device will ask you to unlock it — the same way you unlock your phone every day. Once you do, you are signed in. No typing, no copying codes from an authenticator app, no waiting for an email.

If you are signing in on the same device where you created the passkey, the process takes about five seconds. If you are signing in on a different device — say, a work computer instead of your phone — the website will show you a QR code. You scan that code with your phone (the one that holds the passkey), unlock your phone, and the sign-in completes on the work computer. You never type a password on the work computer, and the passkey never leaves your phone.

Why passkeys are harder to compromise than passwords

Passwords fail in predictable ways. People reuse them across multiple sites, write them down, or choose ones that are straightforward to guess. Hackers can steal a list of passwords from one website and try them on others. Fake websites can trick you into typing your password into the wrong place. None of these attacks work against passkeys.

A passkey is mathematically tied to the specific website it was created for. If you create a passkey for your bank, that passkey will not work on a fake banking website, even if the fake site looks identical. Your device checks that it is talking to the real bank before it will unlock the passkey. This is called phishing resistance — it stops the most common way people lose access to their accounts.

Passkeys also cannot be guessed or brute-forced the way passwords can. A password is a string of characters that someone might eventually type correctly by trial and error. A passkey is a cryptographic key — it is mathematically impossible to guess. The only way to use someone else's passkey is to physically have their device and unlock it, which is a much harder attack than stealing a password from a database.

What to do if you lose the device with your passkey

If your phone is stolen or you lose the device where you created a passkey, you can still sign back into your account — but you will need a backup method first. This is why most websites ask you to keep your password or set up a recovery email or phone number before you delete your password.

To regain access, sign in using your password or recovery method, then create a new passkey on a different device. The old passkey on the lost device becomes useless because you can delete it from your account settings. You do not need to do anything to the lost device itself — once you remove the passkey from your account, it cannot be used to sign in anymore, even if someone finds the device.

This is why security experts recommend keeping at least two devices with passkeys for accounts that matter to you — your phone and a tablet, or your phone and your computer. If you lose one, you still have a passkey on the other. You can create the same passkey on multiple devices by going through the creation process on each one.

Passkeys versus other sign-in methods

Passkeys are newer than passwords, authenticator apps, and text message codes, so it is worth understanding how they compare. A password is something you know; an authenticator app is something you have; a passkey combines both — it is something you have (your device) plus something you are (your fingerprint or face). This makes passkeys the strongest of the three for most people.

Text message codes (sometimes called SMS two-factor authentication) are weaker than passkeys because phone numbers can be transferred to a new SIM card if someone tricks your phone company. Authenticator apps like Google Authenticator or Authy are stronger than text codes but still require you to type a code manually. Passkeys are faster and more find because they use your device's built-in security and cannot be intercepted or redirected.

If a website offers passkeys, it is usually the best choice. If it does not, an authenticator app is better than a text code, and a text code is better than nothing. You do not have to choose one method — most sites let you set up multiple ways to sign in, so you can use a passkey as your main method and keep a password or authenticator app as a backup.

Frequently Asked Questions

Can I use the same passkey on multiple devices?

No, each passkey is tied to the device where you created it. You can create the same passkey on your phone, tablet, and computer by going through the creation process on each device. Then you can sign in using whichever device is nearest. If one device is lost or broken, the passkey on the other devices still works.

What if a website I use does not offer passkeys yet?

You can keep using your password for now. Passkeys are still new, and many websites are adding them gradually. Check back in a few months, or look for a "Security" or "Sign-in options" section in your account settings to see if the option has been added. In the meantime, use a strong, unique password and an authenticator app if the site offers it.

Do I need to delete my password once I create a passkey?

No. Most people keep their password as a backup for at least a few weeks while they get used to signing in with a passkey. Once you are confident the passkey works, you can delete the password if you want. Keeping both is also fine — it gives you more options if something goes wrong.

What if I forget my PIN or my fingerprint does not work?

Your device will usually let you try again, or you can unlock it using a backup method (like a pattern or a different fingerprint). If you cannot unlock your device at all, you have a bigger problem than the passkey — you are locked out of your phone. In that case, you would need to reset your device, which means you would lose the passkey. This is why keeping a backup sign-in method (like a password) is important.

Are passkeys safe if I use the same device for work and personal accounts?

Yes. Each passkey is specific to the account it was created for, so a passkey for your work email cannot be used to sign into your personal email. Your device keeps them separate. However, if someone gains access to your unlocked device, they could use any passkey on it. This is why keeping your device locked when you are not using it matters, just as it does now.