More sites now offer to "create a passkey" when you sign in, and most password managers now offer to save one. This guide explains what a passkey actually is, why it resists the attacks that make passwords risky, how passkeys work with the password manager you already use, how to move them if you switch, and what to do with the old passwords that are still attached to your accounts.
What a passkey is
A passkey is a sign-in credential built on the FIDO2 standards, which include WebAuthn, the browser interface for creating and using them. The FIDO Alliance describes it as a credential "stored on your phone or computer, or in a hardware security key" that lets you sign in "with the same process that they use to unlock their device (biometrics, PIN, or pattern)."
Under the hood it is a pair of cryptographic keys. Apple explains that when you register, your device generates a key pair unique to that account. The public key is stored by the website and "is not a secret". The private key stays with you, and "the server never learns what the private key is." When you sign in, the site sends a challenge, your device signs it with the private key after you unlock it, and the site checks the signature with the public key.
Two practical consequences follow. First, your fingerprint or face never leaves your device: Google states that biometric data used for passkeys "stays on your device and is never shared with Google." Second, there is nothing on the server worth stealing. A breached database of public keys does not let anyone sign in as you.
Why passkeys resist phishing
Passwords fail in predictable ways: people reuse them, sites leak them, and fake login pages collect them. Passkeys are built to avoid each of these. The FIDO Alliance lists phishing resistance as a core design goal and says a passkey "should be guaranteed to be unique per app/website/service." In practice, a passkey created for your bank is tied to the bank's real web address, so a lookalike site cannot request it, and you cannot be tricked into typing it because there is nothing to type.
The FIDO Alliance goes further and says a passkey on its own is more secure than "password + OTP" or "password + phone approval". That is why some services treat a passkey sign-in as already satisfying two-step verification: Google, for example, says a passkey "bypasses the second authentication step, since this verifies that you own the device."
Synced passkeys and device-bound passkeys
There are two kinds, and the difference matters when choosing where to keep them.
- Synced passkeys are copied, end-to-end encrypted, across all your devices that use the same passkey provider. Lose your phone and the passkey is still on your laptop and in the provider's encrypted backup. This is what most people use.
- Device-bound passkeys never leave one piece of hardware, typically a FIDO2 security key. The FIDO Alliance describes these as offering "the highest security assurance" and suggests a security key can also act as a recovery credential if you lose access to all your synced devices.
The FIDO Alliance uses the term passkey provider for whatever stores and syncs your passkeys. That can be built into your operating system or browser, such as iCloud Keychain or Google Password Manager, or a third-party app such as 1Password or Dashlane.
Built-in or password manager: where to keep them
If every device you own comes from one ecosystem, the built-in option is the simplest. Apple says passkeys in iCloud Keychain sync across your Apple devices, are end-to-end encrypted with keys Apple does not know, and can be recovered "even if the user loses all their devices" through iCloud Keychain escrow, which allows only ten passcode attempts before the escrow record is destroyed.
A third-party password manager makes more sense if you mix platforms, for example an iPhone with a Windows PC, or if you share some logins with family members who use different devices. The same app fills passwords and passkeys everywhere it runs, so you have one place to look.
There are exceptions to check. Six Colors reported that the passkey for an Apple Account itself is generated on an Apple device in a way that third-party managers cannot store, so that one stays with Apple whatever you choose for everything else. And Google warns that once you create a passkey on a device, "anyone who can unlock your device can access your Google Account", so only create passkeys on devices you personally own and use, never on a shared computer.
Signing in on a device that does not have your passkey
You do not need to copy a passkey to every computer you touch. FIDO's cross-device sign-in lets you use the passkey on your phone to sign in on a nearby computer. The computer shows a QR code, you scan it with your phone, and Bluetooth is used to confirm the phone is physically close. The FIDO Alliance notes that the sign-in's security does not rely on Bluetooth itself, which only proves proximity. Google's help page describes the same flow: choose "Use your passkey" on the computer, scan the QR code and unlock your phone, with Bluetooth switched on.
Moving passkeys between password managers
For a long time this was the weak point. Passwords could be exported as a CSV file, which is itself a risk: Apple's own export instructions warn that exported passwords "are not encrypted and are visible to anyone who has access to the file." Passkeys usually could not be exported at all, so switching managers meant creating new passkeys site by site.
The FIDO Alliance has addressed this with two specifications: the Credential Exchange Format (CXF), which defines how credentials are described, and the Credential Exchange Protocol (CXP), which moves them between apps with end-to-end encryption. When the drafts were published, 1Password wrote that it was committed to supporting the new format and exchange protocol.
Support is arriving app by app. Six Colors reported that Apple's Passwords app on iOS 26, iPadOS 26 and macOS 26 Tahoe offers "Export Data to Another App", which transfers items directly instead of writing a CSV file, and that Bitwarden and Dashlane added support to receive them. MakeUseOf reported that Android now supports the protocol through Google Play services on Android 14 or later, with the transfer started from the app you are moving to, and that desktop support is further behind than mobile. Check your current and target apps' help pages for the latest status before you plan a move.
What to do with your old passwords
This is the part most guides skip. Adding a passkey usually does not remove your password. Google says plainly that adding a passkey "doesn't change or remove any authentication or recovery factors currently on your account." So the old password is still a way into the account, and it can still be phished or leaked.
- Keep the password, but make it a strong, unique one stored in your manager. If it was ever reused, change it now. You will rarely need it, but it is still a door.
- Leave two-step verification switched on for password sign-ins, so that a leaked password alone is not enough.
- Remove the password only where the service supports it and you have a fallback. Microsoft lets you turn a personal account into a passwordless account, after which you sign in with methods such as Windows Hello, the Microsoft Authenticator app, a security key or SMS codes. Microsoft also notes that some older apps and services still need a password, including IMAP and POP email and some Windows features such as Remote Desktop.
- Check work and school accounts separately. Google notes that some Google Workspace administrators do not allow passkey-only sign-in, in which case the passkey works as a second factor or recovery option instead.
- Keep recovery options current. A recovery email, phone number or recovery contact matters more, not less, once you stop typing a password.
A sensible way to start
- Decide where your passkeys will live: your platform's built-in manager if you use one ecosystem, or a cross-platform password manager if you mix devices.
- Make sure every device has a screen lock. On Apple devices, iCloud Keychain needs to be on; Google lists this as a requirement for creating passkeys there.
- Start with your most important accounts: email first, because it resets everything else, then banking, shopping and social accounts.
- When a site offers a passkey, accept it and confirm that your chosen manager, not a different one, saves it. Browsers and phones may offer their own built-in option first.
- Update each account's stored password to a unique one at the same time, and leave two-step verification on.
- Consider a hardware security key as a backup for your email account, especially if your synced passkeys all depend on one provider.
Common questions
Can a website see my fingerprint or face?
No. The biometric check happens on your device and only unlocks the private key. Google states that biometric data used for passkeys stays on your device and is never shared with it.
What happens if I lose my phone?
With synced passkeys, your other devices and your provider's encrypted backup still have them. Sign in to your provider on a new device to restore them. With device-bound passkeys on a single security key, register a second key as a spare.
Do I still need a password manager?
For most people, yes. Many sites do not yet support passkeys, the ones that do usually keep a password too, and a password manager is now also a passkey manager. It keeps both in one place.
Can I have more than one passkey for the same account?
Many services allow it. Google, for example, lets you create passkeys on multiple devices and on hardware security keys, which is a simple way to keep a backup.