Decision point
What Is a Passkey? matters when it changes who can sign in, recover access or approve a sensitive action. Start with those consequences before changing settings.
For What Is a Passkey?, this is a passkey decision page. Its goal is to understand where the credential is stored, how it syncs and how recovery works. Test a second device and recovery route before removing a familiar sign-in method.
Plain-English explanation
Learn how passkeys use public-key cryptography, device authentication and phishing-resistant sign-in. A secure setup must consider both everyday sign-in and what happens when a device is lost, replaced or compromised.
How it improves security
A passkey uses a cryptographic key pair. The service keeps a public key while the private key remains protected by your device or credential provider. Phishing-resistant methods help because the credential is bound to the real service rather than typed into any page that looks convincing.
What is stored where?
A passkey is based on a cryptographic key pair. The service stores a public key, while the private key stays protected by a device, security key or credential provider. Signing in proves possession of the private key without sending that key to the website.
Why phishing is harder
A passkey is created for a specific service and normally will not authenticate a lookalike domain. This removes the reusable secret that users often type into convincing phishing pages.
Synced and device-bound credentials
Some passkeys sync through a platform account so they are available on multiple devices. Others remain on a hardware security key or one device. Users should understand backup, export and recovery behavior before depending on a single credential.
Biometrics are local unlock methods
Face or fingerprint verification usually unlocks the private credential on the device; the biometric template is not sent to the website. A device PIN or password can often be used as an alternative local unlock method.
Method comparison
| Method | Phishing resistance | Recovery concern |
|---|---|---|
| Password only | Low | Reset email or phone may control access |
| SMS code | Limited | Phone-number loss or takeover |
| Authenticator app | Moderate | Device transfer and backup codes |
| Security key or passkey | High when implemented correctly | Device and credential-provider recovery |
Before enabling it
- Update the operating system and browser.
- Protect devices with a strong screen lock.
- Confirm account recovery email and phone details.
- Add more than one trusted device or backup method where supported.
- Store recovery codes separately from the primary device.
Frequently asked questions
Does this replace a password?
Some passkey-enabled accounts can reduce or remove password use, while others keep a password as a fallback.
What happens if I lose my phone?
Which method is strongest?
Authoritative guidance
For implementation details, consult the service’s official help center and current NIST authentication guidance.
Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.
Apply What Is a Passkey? to a real account
For What Is a Passkey?, write down the account owner, recovery email, trusted devices and the action that would cause the greatest damage. Then use the guidance above to reduce that specific risk. A generic “secure” status is less useful than knowing who can recover the account and how unauthorized access would be detected.
Verification before you finish
- Confirm the change from a trusted device.
- Test the new sign-in or recovery method.
- Check that an old session or fallback has not been left active unintentionally.
- Store recovery information away from the primary device.
- Record the next review owner if the account is shared or business-critical.