Skip to main content
FixMyTech

What Passkeys Are and Whether to Switch

By

Published

8 min read

Share

Short answer

A passkey is a cryptographic key pair where your device keeps the private half and the site stores only the public half. You sign in with your face, fingerprint or device PIN. Nothing reusable is transmitted, so a passkey cannot be phished or leaked in a breach — but add one as an extra method first and keep your password until you are confident of the recovery route.

On this page

Passkeys are usually introduced as “passwords, but easier”, which undersells what changed. The meaningful difference is that there is no shared secret at all. The site never holds anything that would let someone sign in as you, so a breach of its database leaks nothing usable and a fake login page has nothing to collect.

That is a genuine structural improvement over every password-based scheme, including a password with a six-digit code attached. It also introduces a new way to lose an account, which is the part the marketing skips.

How it works, briefly

When you create a passkey, your device generates a pair of mathematically linked keys.

  • The private key stays on your device, protected by its secure hardware. It is released only when you authenticate locally — face, fingerprint, or PIN.
  • The public key goes to the website. It can verify a signature but cannot produce one, so it is useless to anyone who steals it.

When you sign in, the site sends a random challenge. Your device signs it with the private key and returns the signature. The site checks it against the public key it already holds.

Three consequences, and they are the whole argument:

Nothing reusable crosses the network. Each signature answers one challenge and is worthless afterwards.

A breach of the site leaks public keys. There is no password hash to crack because there is no password.

Phishing fails by construction. The passkey is bound to the real domain, and your device checks that domain before signing. A lookalike site gets no response at all, regardless of how convincing it looks or how willing you are to be fooled. This is the property a six-digit code can never have, because a human can always be persuaded to type one into the wrong box.

The biometric is worth being clear about: it unlocks the key locally and is never sent anywhere. Websites do not receive your fingerprint.

Where the passkey actually lives

This determines everything about recovery, and it is the question to ask before you create one.

Where it lives Syncs? If the device is lost
iCloud Keychain Across your Apple devices Restores on a new signed-in device
Google Password Manager Across Android and Chrome Restores on sign-in
A third-party password manager Across everything it runs on Restores with the vault
Windows Hello, device-bound No Gone
A hardware security key No Gone unless you have a second key

The top three rows are what most people get by default, and they are why “lose your phone, lose your account” is usually not true for passkeys. Your passkeys are backed by the platform account, which has its own recovery.

The bottom two rows are deliberate. A device-bound passkey cannot be copied anywhere, which is stronger and less forgiving. Anyone choosing that should register a second key — the same reasoning as a spare house key, and the standard advice from everyone who sells them.

Setting one up

Most services put this under Security or Sign-in settings as Add a passkey or Set up passkey. The flow is short: confirm with your existing login, approve with biometrics, done.

Do it in this order:

  1. Add the passkey as an additional method, keeping your password and existing second factor.
  2. Test it on a second device before you trust it. Sign out on a laptop and sign in with the passkey via the phone QR flow.
  3. Confirm where it synced. Check it appears in iCloud Keychain, Google Password Manager, or your manager’s list. A passkey you cannot find is a passkey you cannot recover.
  4. Keep the recovery codes for the account regardless. Passkeys do not replace them, and where to store recovery codes still applies.
  5. Only then consider removing the password, if the service even allows it.

Google, Apple, Microsoft, Amazon, PayPal and most major platforms support passkeys now. Banks and smaller services are patchier, so expect to carry both systems for some years yet.

Using one on a computer that is not yours

Choose Use a passkey from another device or similar, and a QR code appears. Scan it with your phone’s camera and approve.

The two devices confirm proximity over Bluetooth, which matters more than it sounds: a remote attacker cannot display a QR code on their own screen and have you approve it from your sofa. Proximity is a deliberate part of the design, and it is why this flow is awkward on purpose.

The honest problems

Ecosystem friction. A passkey in iCloud Keychain is awkward on an Android phone, and the reverse is equally true. The QR flow bridges it and is more fiddly than typing a password. Anyone genuinely using both platforms is better served by a third-party manager that holds passkeys across everything.

Shared accounts break. A passkey assumes one person with their own biometrics. A household streaming account used by four people fits badly, and sharing credentials with family is still a password-shaped problem for now.

Inconsistent implementations. Some sites treat a passkey as a full replacement, some as a second factor, some as a convenience shortcut that still leaves the password fully active. If the password remains valid, your account is only as secure as that password, which is worth checking before assuming you have upgraded anything.

Portability is still maturing. The standard allows moving passkeys between providers. Actual support has lagged, so plan on some lock-in to whichever ecosystem holds yours.

Realistic expectations

For a Google or Microsoft account on a phone you use daily, a passkey is straightforwardly better: faster to use, impossible to phish, and recoverable through the platform account you already rely on. Add one.

What it does not do is remove the need to think about recovery. It changes the question from “what if someone guesses my password” to “what if I lose access to the account my passkeys sync through”, which is a better question with a narrower answer, but it is not no question. Keep the recovery codes, keep a second device able to sign in, and check what is signed into your accounts occasionally regardless of which method you use.

Frequently asked questions

Do passkeys work if I lose my phone?
Usually yes, because passkeys created on an iPhone sync through iCloud Keychain and those on Android sync through Google Password Manager, so a new device signed into the same account gets them back. A passkey stored only on a hardware key or a device with sync disabled is lost with it.
Can a website steal my fingerprint through a passkey?
No. The biometric never leaves the device and the site never receives it. Your fingerprint or face only unlocks the private key locally, and what the site gets is a signature proving the key was used.
Can I use a passkey on someone else's computer?
Yes. Choose the option to use a phone, scan the QR code that appears, and approve on your phone. The two devices verify proximity over Bluetooth, which is what prevents someone in another country displaying a QR code and getting you to approve it.
Are passkeys tied to Apple or Google permanently?
Not inherently. The standard supports export and transfer between providers, and third-party password managers store passkeys too. Support for moving them between ecosystems has been uneven in practice, so check before relying on it.
Should I delete my password once I have a passkey?
Not immediately. Most services keep the password as a fallback anyway, and removing it before you have confirmed a working recovery route is how people lock themselves out. Run both for a while, then remove the password if the service lets you.

All Accounts guides