Love for Technology ← All articles
Security & Privacy
passkeys password security

What Is a Passkey? How It Works and How to Set One Up

27 September 2026 ·
iPhone showing the Save a passkey prompt with Face ID next to a laptop Google sign-in page

If you've signed in to Google, Amazon or your Microsoft account lately, you've probably seen a pop-up asking you to "create a passkey". Most people tap "Not now" and move on, because nobody really explains what it is. That's a shame, because passkeys are the biggest improvement to online security in years, and they're actually easier to use than passwords.

In this guide I'll explain what a passkey is in plain English, why it's safer than a password, what happens if you lose your phone, and exactly how to set one up on the accounts that matter most.

What is a passkey?

A passkey is a way to sign in to a website or app without typing a password. Instead, you confirm it's you the same way you unlock your phone or laptop: with your fingerprint, your face, or your device PIN.

Behind the scenes, a passkey is a small digital key that your device creates for one specific website. You never see it, you never have to remember it, and you can't accidentally give it away. It was developed by the FIDO Alliance, a group that includes Apple, Google and Microsoft, which is why it works across iPhone, Android, Windows and Mac.

🔑 Password

  • You have to remember it
  • Can be guessed or reused
  • Can be typed into a fake site
  • Stolen in data breaches

✅ Passkey

  • Nothing to remember
  • Unique for every site
  • Won't work on fake sites
  • Useless to hackers if the site is breached

How a passkey works (without the jargon)

Every passkey uses a pair of cryptographic keys that belong together, a bit like a padlock and its key.

  • The public half (the padlock) is handed to the website. It's fine if anyone sees it, because on its own it can't open anything.
  • The private half (the key) is protected by your device or passkey manager. With a device-bound passkey it stays on that device; a synced passkey can be backed up in encrypted form by its provider. The website never receives the private key.

When you sign in, the website sends your device a one-time challenge. Your device asks for your fingerprint, face or PIN, then uses the private half to "sign" that challenge. The website checks the signature against the padlock it already has. If they match, you're in. Your fingerprint or face never goes anywhere: it only unlocks the key on your own device.

Diagram showing how a passkey sign-in works between a phone and a website

Why passkeys are safer than passwords

They can't be phished

Phishing is when a fake email or text leads you to a site that looks exactly like your bank or Google, and you type your password into it. With a passkey, that trick simply fails. Each passkey is tied to the real website's address, so your device won't even offer it on a look-alike site like "g00gle-login.com".

Data breaches don't expose them

When a website stores passkeys, it keeps the public key, not the private key used to sign in. A breach of that website's credential database therefore does not hand attackers the private key. This protection is about the website's copy: synced passkeys also rely on the security of the account and provider that stores their encrypted backup.

No reuse, no weak passwords

Most account takeovers happen because people reuse the same password on several sites. Every passkey is unique and randomly created, so there's nothing weak to guess and nothing to reuse.

In short: a passkey protects you from the three most common ways accounts get stolen: phishing, data breaches and reused passwords.

Where your passkeys are stored

This is the part that worries most people: "If the key lives on my phone, what happens if I lose it?" It depends on where the passkey was saved. Some passkeys are synced by a password manager and can be restored on another device; others are device-bound and stay on one device or security key.

Where it's savedWorks onGood for
iCloud KeychainiPhone, iPad, MacPeople who mainly use Apple devices
Google Password ManagerAndroid, Chrome on any computerAndroid users and Chrome fans
Windows HelloYour Windows PCSigning in on one specific computer
Password managers (Bitwarden, 1Password, etc.)Almost everythingMixed setups, like an iPhone with a Windows PC

If you use a mix of Apple, Android, Windows and Mac devices, check which passkey provider each device and browser supports. A cross-platform password manager may make synced passkeys easier to reach, while a device-bound passkey may require a QR-code sign-in from your phone or a separate passkey on each device.

Keep a backup way in. Before you rely on passkeys for an important account, make sure you still have a recovery email or phone number set up. That way, losing a device is an inconvenience, not a lock-out.

How to set up a passkey on Google, Apple and Microsoft

Setting one up takes less than a minute per account. Menu names change from time to time, but the path is usually very close to what's below.

Google account

  1. Go to myaccount.google.com and sign in.
  2. Open Security (on some screens it's called Security & sign-in) and choose Passkeys and security keys.
  3. Tap Create a passkey, then Continue.
  4. Confirm with your fingerprint, face or screen lock. Done.
Google account Passkeys and security keys page with the Create a passkey button

iPhone and Apple devices

On Apple devices there's no separate "turn on passkeys" switch. As long as iCloud Keychain is on, your iPhone will offer to save a passkey whenever a site or app supports it.

  1. Open Settings, tap your name, then iCloud and make sure Passwords (iCloud Keychain) is switched on.
  2. Sign in to a site that supports passkeys, like Amazon or PayPal, and look for an option such as Create a passkey in its security settings.
  3. When the "Save a passkey?" sheet appears, tap Continue and confirm with Face ID or Touch ID.
  4. You'll find all your saved passkeys later in the Passwords app.

Microsoft account

  1. Go to account.microsoft.com and open Security.
  2. Choose the option to manage how you sign in, then Add a new way to sign in or verify.
  3. Pick Face, fingerprint, PIN or security key.
  4. Follow the Windows Hello or phone prompt to save it.
Windows Hello prompt asking to save a passkey for the Microsoft account
Which accounts first? Start with the ones that would hurt most if stolen: your main email (Google or Microsoft), your Apple Account, Amazon, PayPal and your bank if it supports passkeys. Your email matters most, because it's the key to resetting everything else.

Signing in on another device

What if you're on a friend's laptop or a work computer that doesn't have your passkey? You can still sign in using your phone:

  1. On the computer, choose Use a passkey and then an option like Use a phone or tablet.
  2. A QR code appears. Scan it with your phone's camera.
  3. Confirm with your fingerprint or face on the phone. Bluetooth checks that the phone is physically nearby, which stops someone from doing this remotely.

You're signed in, and nothing is left behind on the other computer. Just remember to sign out when you're done.

What passkeys feel like in everyday use

The first setup usually means choosing where the passkey will be saved, then confirming with a fingerprint, face scan or device PIN. After that, signing in on the same device is often just a prompt and a confirmation—no password to type or one-time code to copy.

The experience depends on the devices and passkey manager involved. If the passkey syncs through the same provider used on your other devices, it may appear there after you sign in to that provider. If it is tied to one device, you may need to use your phone to approve a QR-code sign-in or create another passkey on the second device.

Some websites may still ask for an extra verification code, especially when you use a new browser or device. That does not necessarily mean the passkey failed; the site may require an additional account check. Keep recovery details current and retain another sign-in method until you know how the service handles account recovery.

In short, passkeys can make routine sign-ins quicker, but the smoothest setup depends on how well your devices and credential manager work together. Before removing a password or backup method, test signing in from your usual devices and confirm that you can recover access if one is lost.

FAQ

Is a passkey safer than a password?
Passkeys are resistant to phishing, and a website stores only the public key, not the private key used to sign in. Synced passkeys are encrypted by the passkey provider, so account and provider security matter too.
What happens to my passkeys if I lose my phone?
If the passkey was synced, you can usually restore it by signing in to the same password manager on a new device. A device-bound passkey may not transfer, so keep another passkey or recovery method for important accounts.
Can I use a passkey on someone else's computer?
Yes. Choose to sign in with a phone or another device, scan the QR code with your phone and confirm with your fingerprint or face. Nothing is saved on the other computer.
Do I still need my password after creating a passkey?
For now, most sites keep your password as a backup. Make sure it's strong and unique, and turn on two-factor authentication, until the site lets you remove it.
Does the website get my fingerprint or face scan?
No. Your fingerprint or face only unlocks the passkey on your own device. The website never receives any biometric data.
0%
Share this article

💬 Comments

Loading comments…