What Are Passkeys? How to Set Them Up and Ditch Passwords
Passwords are hard to remember, easy to steal, and painful to reset. That is why big companies like Apple, Google, and Microsoft are pushing something better: passkeys. Instead of typing a secret, you unlock your account with your fingerprint, face, or device PIN. It feels simple, and it is much safer than a typical password.

In this guide, I explain what passkeys are in plain language, how they work, how to set them up on your phone and computer, and what happens if you lose your device. By the end, you will know whether passkeys are right for you and how to start using them today.
Key Takeaways
- A passkey is a digital login credential stored on your device, unlocked with your fingerprint, face, or PIN.
- Passkeys resist phishing, because they only work on the real website they were created for.
- Nothing secret is stored on the website’s server, so a data breach cannot leak your passkey the way it leaks passwords.
- Passkeys sync through Apple, Google, Microsoft, or a password manager, so you do not lose them when you change phones.
- Keep a backup sign-in method and a recovery plan for your main email account.
What Are Passkeys?
A passkey is a replacement for a password. When you create one, your device makes two linked digital keys. The public key goes to the website. The private key stays safely on your device and never leaves it. When you log in, the website sends a challenge, your device proves it holds the matching private key, and you approve with a fingerprint, face scan, or PIN.
The technology is based on open standards from the FIDO Alliance and the World Wide Web Consortium, often called FIDO2 and WebAuthn. You can read the official overview on the FIDO Alliance passkeys page. The key point for everyday users is simple: there is no secret text for you to type, so there is nothing for a criminal to trick you into giving away.
How Passkeys Work in Simple Steps
- You choose to create a passkey on a website or app that supports it.
- Your device creates a private key and a public key.
- The public key is stored by the website. The private key stays on your device.
- Next time you sign in, you confirm with a fingerprint, face, or PIN.
- Your device signs a one-time challenge, and the website lets you in.
Because the private key never travels across the internet, a hacker who steals the website’s database gets only public keys, which are useless on their own.
Passkeys vs Passwords
Passwords have three big weaknesses: people reuse them, people choose weak ones, and criminals steal them with fake login pages. Passkeys fix all three.
Phishing Protection
A fake bank website can trick you into typing a password. It cannot trick a passkey, because your device checks the real website address before it responds. If the address is wrong, the passkey simply does not work.
No Reuse
Each passkey is unique to one website. You cannot accidentally use the same one everywhere, which stops the chain reaction where one leaked password unlocks many accounts.
Faster Sign-In
Instead of typing a long password, then waiting for a text message code, you tap and approve. Many people find passkeys quicker than passwords with two-step verification, and they often keep the same level of security or better.
How to Set Up Passkeys
On iPhone or Mac
Apple stores passkeys in iCloud Keychain. Make sure iCloud Keychain is turned on in your Apple account settings. When you visit a supported site, choose the option to create a passkey, then confirm with Face ID, Touch ID, or your device passcode. Your passkeys sync across your Apple devices. If you use the newest Apple software, our guide on iOS 27 problems and fixes can help if anything misbehaves after updating.
On Android or Chrome
Google Password Manager saves passkeys and syncs them to your Google account. Go to your Google account security page, find the passkeys section, and follow the steps to create one. On other sites, choose the passkey option when prompted, then confirm with your fingerprint or screen lock.
On Windows
Windows Hello supports passkeys using your face, fingerprint, or PIN. When a website asks to create a passkey, pick Windows Hello as the place to save it. You can manage saved passkeys in the Windows settings under accounts.
With a Password Manager
Several popular password managers now store passkeys too. This is helpful if you use devices from different brands, because your passkeys are available on all of them. Choose a manager you trust, protect it with a strong master password, and turn on its own two-step verification.
Which Accounts Should You Switch First?
You do not have to convert everything in one day. Start with the accounts that matter most:
- Your main email account, since it can reset every other password.
- Banking, payment, and shopping accounts.
- Your Apple, Google, or Microsoft account.
- Social media and messaging accounts.
- Work tools that hold customer or company data.
Adding a passkey does not usually delete your old password right away. You can test the new login first, then decide later whether to remove the password.
What If You Lose Your Phone?
This is the most common worry, and it has a simple answer. Because passkeys sync through your account, a new phone signed into the same Apple, Google, or password manager account can restore them. Even so, prepare a backup plan:
- Set up account recovery options for your main email and cloud account.
- Keep recovery codes in a safe place, such as a printed copy in a drawer.
- Add a second sign-in method, such as a hardware security key, for your most important accounts.
- Remove lost devices from your account settings as soon as possible.
Are Passkeys Really Safe?
Yes, they are considered much safer than passwords for most people. They are resistant to phishing, cannot be guessed, and are not stored on the website in a usable form. They do not remove every risk, though. If someone steals your unlocked phone and knows your device PIN, they may be able to use your passkeys. Protect your device with a strong screen lock, keep it updated, and use biometrics when possible.
Passkeys also do not stop scams that trick you into handing over control in other ways, such as fake support calls or cloned voices. To learn how those attacks work, read our guide on AI voice cloning scams and how to protect yourself.
Common Problems and Fixes
The Site Does Not Offer Passkeys
Support is growing but not universal. Keep using a strong, unique password with two-step verification on those sites, and check again later.
You Use Devices From Different Brands
Use a cross-platform password manager, or scan a QR code with your phone when signing in on a different device. Most systems support this method.
A Shared Computer
Do not save passkeys on public or shared computers. Choose the option to use your phone instead, which keeps the key on your own device.
A 20-Minute Plan to Start Using Passkeys Today
You do not need a weekend to get started. Set aside twenty minutes and follow this simple plan. First, update your phone, computer, and browser, since older versions may not support the latest features. Second, turn on your screen lock and make sure biometrics are enabled. Third, sign in to your main email account and look for the security section. If you see an option to create a passkey, follow the steps and confirm with your fingerprint or face.
Fourth, repeat the process for two or three other important accounts, such as your bank, your shopping account, and your social media. Fifth, write down or print your recovery codes and store them somewhere safe and offline. Finally, test the new sign-in by logging out and logging back in with the passkey. If it works, you have just made your accounts harder to steal, and you can add more accounts each week.
Tips for Families and Small Teams
Passkeys are also useful outside your own accounts. Parents can help older relatives switch to passkeys on their phones, which removes the need to remember complicated passwords and makes fake login pages much less dangerous. For small teams, passkeys reduce the number of password reset requests and lower the risk that one careless click exposes company data.
If your team shares accounts, use a business password manager that supports passkeys and shared vaults, rather than sending secrets in chat. Give each person their own login where possible, so you can see who did what and remove access instantly when someone leaves the team.
Passkeys FAQ
Are passkeys the same as biometrics?
No. Your fingerprint or face only unlocks the passkey on your device. The biometric data itself is not sent to the website.
Can I use passkeys on more than one device?
Yes. Synced passkeys are available on all devices signed into the same account or password manager.
Do passkeys replace two-step verification?
A passkey already combines something you have, your device, with something you are or know, your biometric or PIN. Many services treat it as a strong sign-in on its own.
What if a website does not support them?
Keep using a unique, long password stored in a password manager, plus two-step verification, until passkeys are available.
Do I need a new phone to use passkeys?
No. Most phones and computers from the last few years support them. Just keep your operating system and browser updated.
Final Thoughts on Passkeys
Passkeys are one of the biggest practical security upgrades available to everyday users. They are faster than passwords, safer against phishing, and easier to live with. Start with your email and your most important accounts, keep a backup plan, and protect your device with a strong screen lock. Within a few weeks, you may find that you rarely type a password at all, and you will feel calmer knowing your accounts are harder to steal.






