Cybersecurity · Explainer

Passkeys explained: why passwords are finally fading

Passkeys explained: how they work, why they're phishing-resistant, where they're stored, and how to set them up on your Apple, Google and Microsoft accounts.

Hand holding a smartphone with a bright white screen against total darkness

Key takeaways

  • A passkey is a pair of cryptographic keys: the private key stays on your device or in your password manager, and the website stores only the public key.
  • Passkeys are phishing-resistant because your device will only use them on the real website or app they were created for.
  • Most consumer passkeys sync through Apple, Google, Microsoft or a password manager, while hardware security keys hold device-bound passkeys that never leave the key.
  • Adding a passkey usually doesn't remove your password or SMS backup, so those fallbacks can remain a weak point.
  • Start with your email account, then add passkeys to banking, shopping and social accounts as they become available.

A passkey is a sign-in credential that replaces your password with something your device already protects: your face, your fingerprint or your screen-lock PIN. Because the secret never leaves your device and only works on the real website it was made for, passkeys are phishing-resistant in a way passwords and text-message codes are not. Here’s how they work, where they still fall short, and how to start using them on your Apple, Google and Microsoft accounts today.

What a passkey actually is

Under the hood, a passkey is a pair of cryptographic keys built on open standards from the FIDO Alliance and the W3C. When you create a passkey for a site, your device makes two linked keys:

  • A private key that stays with you, on your phone, computer, password manager or hardware security key.
  • A public key that the website stores. It can check a signature made by your private key, but it can’t be used to sign in on its own.

When you sign in, the site sends a one-time challenge. Your device asks you to unlock it, the private key signs the challenge, and the site checks that signature with the public key. Nothing reusable is typed, sent or stored on the server.

Two details surprise most people. First, your fingerprint or face scan isn’t sent to the website. It simply unlocks the key on your device, and Google notes that your biometric data stays on the device. Second, a passkey usually counts as more than one factor by itself: you need the device (something you have) plus your face, fingerprint or PIN. That’s why Google says a passkey skips the separate 2-Step Verification step on accounts that use it.

If terms like “authenticator” or “multifactor” are new to you, our tech glossary covers the basics.

Why passkeys are phishing-resistant

Phishing works because people can be tricked into typing a password or a six-digit code into a fake login page. Passkeys take that opportunity away. Each passkey is tied to the exact website or app it was created for, and your browser or operating system enforces that link. As Microsoft explains, a passkey created for one domain can only be used with that domain. If a lookalike site asks for your passkey, your device simply won’t offer it.

That’s why the U.S. Cybersecurity and Infrastructure Security Agency, in its phishing-resistant MFA fact sheet, calls phishing-resistant MFA the “gold standard” and names FIDO/WebAuthn, the technology behind passkeys, as the only widely available form of it. NIST’s current digital identity guidelines, SP 800-63B, define phishing resistance in terms of cryptographically binding a sign-in to the real site, which is exactly what passkeys do.

Notice the wording: phishing-resistant, not phishing-proof. Attackers can still go after your account recovery options, trick you into approving something on your own device, or steal a session after you’ve signed in. Passkeys close the biggest door, not every door.

Passkeys also help when a company gets breached. The site only holds your public key, so a stolen database doesn’t hand attackers anything they can replay to log in, unlike a leaked password you reused on five other sites.

Passkeys vs. passwords vs. SMS codes

Passwords SMS codes (as a second step) Passkeys
What you do Type a secret you remember Type a code texted to your phone Unlock your device with face, fingerprint or PIN
Can a fake site capture it? Yes Yes, if you type it in Designed not to: it only works on the real site
Useful to attackers after a site breach? Often, especially if reused Not on their own No, the site stores only a public key
Other common attacks Guessing, reuse, credential stuffing SIM swaps, SS7 interception Attacks on your device lock or account recovery
Needs cell signal? No Yes No
Supported where? Almost everywhere Wherever offered A growing list of sites and apps

CISA ranks SMS and voice codes as the weakest form of multifactor authentication and says they should be a last resort. Still, any second step is better than a password alone, so don’t turn off text codes until you have something stronger in place.

Synced vs. device-bound passkeys

Most passkeys people create today are synced passkeys. They live with a passkey provider, such as Apple’s iCloud Keychain, Google Password Manager, Microsoft Password Manager or a third-party password manager, and they’re copied to your other signed-in devices. Apple and Google both say these passkeys are end-to-end encrypted, so the provider can’t read them. The big advantage is resilience: lose your phone and your passkeys aren’t gone, because signing in to the same account on a new device, and confirming your old screen lock or password manager PIN if asked, brings them back.

Device-bound passkeys never leave one piece of hardware. The classic example is a FIDO2 hardware security key that plugs into a USB port or taps over NFC. passkeys.dev describes these as credentials bound to a single authenticator. They’re the stricter option: NIST says syncable authenticators shall not be used at its highest assurance level (AAL3), because a key that syncs has to be exportable. For everyday accounts, synced passkeys are the practical choice. People at higher risk, such as journalists or anyone managing company money, may want security keys for their most important accounts.

You also don’t need your passkey on every device. With cross-device sign-in, a laptop that doesn’t have your passkey, like a library computer, shows a QR code. You scan it with your phone, approve the sign-in there, and the passkey never leaves your phone. The two devices check that they’re physically close, which stops a remote attacker from using the same trick.

Switching providers used to be painful, but the FIDO Alliance has published Credential Exchange specifications designed to move passkeys securely between password managers. Support is still rolling out, so check with your manager before assuming a one-click move.

The weak spots passkeys don’t fix

  • Fallbacks stay open. Adding a passkey usually doesn’t remove your password. Google says adding one doesn’t change or remove your existing sign-in methods, and even a passwordless Microsoft account can still use SMS codes. An attacker who can’t phish your passkey may go after the password or your phone number instead.
  • Your device lock becomes the front door. Google warns that once a passkey is on a device, anyone who can unlock that device can get into your account. Use a strong PIN or passcode, and don’t create passkeys on shared devices.
  • Account recovery matters more. If you lose access to your Apple Account, Google Account or password manager, you can lose the synced passkeys inside it. Keep that account’s recovery options up to date.
  • Not every site supports passkeys yet. You’ll live with a mix of passkeys and passwords for a while, so a good password manager is still worth having.

How to switch: a practical step-by-step

Menu names change with software updates, so treat these steps as a map rather than a script. If something looks different, search your account’s help pages for “passkey.”

1. Get your devices ready

  • Update your phone, computer and browser. Google lists Android 9, iOS 16, Windows 10 and macOS Ventura as minimums for its passkeys.
  • Set a screen lock (PIN, passcode, fingerprint or face unlock). Passkeys depend on it.

2. Apple: iPhone, iPad and Mac

  • Turn on iCloud Keychain and two-factor authentication for your Apple Account. Apple requires both for passkeys.
  • When a website or app offers to save a passkey, usually in its account or security settings, tap Continue and confirm with Face ID, Touch ID or your passcode.
  • View or delete saved passkeys in the Passwords app (iOS 18, macOS Sequoia and later) under Passkeys.

3. Google Account

  • Sign in to your Google Account, open Security & sign-in, go to Passkeys and security keys, and choose Create a passkey. You can also go straight to myaccount.google.com/signinoptions/passkeys.
  • Creating a passkey turns on a passkey-first sign-in. If you’d rather be asked for your password, switch off Skip password when possible under “How you sign in to Google.”
  • Lost a device? Remove its passkey from the same Passkeys and security keys page.

4. Microsoft account

  • Sign in to your Microsoft account’s Advanced security options page (account.live.com/proofs/manage).
  • Choose Add a new way to sign in or verify, then Face, Fingerprint, PIN, or Security Key, and follow the prompts. Microsoft lets you save it to Windows Hello, a phone, a security key or a synced password manager.
  • Optional: turn on Passwordless account to delete your password entirely. Microsoft requires the Microsoft Authenticator app or Outlook for Android first. Brand-new Microsoft accounts have been passwordless by default since May 2025.

5. Password managers

  • Most major password managers can now create and store passkeys and sync them across platforms, which helps if you mix, say, an iPhone with a Windows PC.
  • On iPhone, choose which apps can fill in passkeys under Settings > General > AutoFill & Passwords. Apple allows up to three passwords apps.
  • On Android 14 and later, look in Settings for the passwords and passkeys section to pick your provider. The exact name varies by phone maker.

6. Close the back doors

  • Once passkeys work, review each account’s fallback options. Remove old phone numbers, prefer an authenticator app over SMS where you can, and store recovery codes somewhere safe.
  • Add a second passkey or a security key for your most important accounts (email, bank and password manager), so one lost device can’t lock you out.

Start with email. Whoever controls your inbox can reset most of your other passwords.

The bottom line

Passkeys are the biggest practical security upgrade most people can make right now, and they’re easier to use than the passwords they replace. They’re phishing-resistant, they leave nothing useful behind in a data breach, and for most people they sync quietly in the background. Just remember that your old password and SMS fallbacks don’t disappear on their own, so tidy those up once your passkeys are working.

For more ways to lock down your accounts and devices, browse our cybersecurity coverage and the full list of guides. Upgrading your home network too? Our Wi-Fi 7 vs Wi-Fi 6E comparison explains whether a new router is worth it.

For more account-safety guides, visit RedAndWhiteMagz.com.

Frequently asked questions

Are passkeys safer than passwords?

For most people, yes. A passkey only works on the site it was created for, so it can't be typed into a fake login page, and the website stores only a public key that is useless to thieves on its own. Your security still depends on your device lock and on the account recovery options you leave in place.

What happens to my passkeys if I lose my phone?

If your passkeys sync through iCloud Keychain, Google Password Manager or another password manager, signing in to that account on a new device brings them back, though you may need your old screen lock or password manager PIN. You should also remove the lost device's passkeys from your account settings. Passkeys stored only on a hardware security key are not backed up, so register a spare key.

Can I use a passkey on a computer that isn't mine?

Yes. On the other computer, choose the option to use a passkey from another device or phone, scan the QR code with your phone, and approve the sign-in there. The passkey stays on your phone, and the two devices check that they are near each other before the sign-in goes through.

Do I still need a password after setting up a passkey?

Usually, for now. Most services keep your password as a backup, and some older apps and devices still require one. Some accounts, including Microsoft accounts, let you remove the password entirely once other sign-in methods are set up.

Sources

First published . Spotted an error? Read our editorial policy and tell us.

Contact RedAndWhiteMagz.com

Have a tech question or a story tip?

Spotted a new gadget, a scam making the rounds or a mistake in one of our guides? Tell us. We read every message and reply as quickly as we can.

Close-up of a black mechanical keyboard with glowing red backlit keys in a dark room