Passkeys explained: how passwordless sign-in works and how to recover
Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Create a passkey on your email account first, keep at least two ways to sign in to it, and remove text message recovery where the site allows once you have a safer backup.
A passkey replaces your password with a pair of cryptographic keys. The private key stays in your phone, computer, password manager or security key, and you unlock it with your face, fingerprint or screen lock. The website only stores the public key, so a breach of that site gives criminals nothing they can reuse.
Passkeys also only work on the real website they were created for, which is why a fake login page cannot capture one. The questions that matter in practice are where your passkeys live, what happens when you lose a device, and how to make sure you can always get back in. This guide answers all three.
How passkeys work
When you create a passkey, your device makes a key pair for that one website. To sign in, the site sends a challenge, your device signs it with the private key after you unlock it, and the site checks the signature with the public key. The FIDO Alliance, which sets the standard, says your fingerprint or face data never leaves your device.
Passkeys come in two kinds. Synced passkeys are copied between your devices through a cloud service, so a new phone gets them automatically. Device-bound passkeys never leave one device, such as a hardware security key.
Because a passkey is tied to the website's address, typing your details into a look-alike site simply does not work. That is the main security gain over passwords and one-time codes.
Where your passkeys are stored and how they sync
Apple devices: passkeys sync through iCloud Keychain, which Apple says is end-to-end encrypted with keys Apple does not know, and can be recovered even if you lose all your devices.
Google Password Manager: passkeys sync across Android and Chrome. Since September 2024 Google has used a Google Password Manager PIN to keep them end-to-end encrypted. On a new device you need that PIN or the screen lock of a previous Android device.
Microsoft: new Microsoft accounts have been passwordless by default since May 2025, and existing users can remove their password. Windows can store passkeys with Windows Hello and use passkeys from your phone.
Password managers such as 1Password, Bitwarden, Dashlane and Proton Pass store passkeys and sync them across Apple, Android and Windows, which helps households that mix platforms.
Hardware security keys hold device-bound passkeys that cannot be copied off the key.
Set up your first passkeys
Start with your main email account, because it resets everything else. In a Google Account, open Security and look for Passkeys and security keys. In a Microsoft account, open Security and the sign-in options.
When asked where to save it, choose one main home, either your phone's built-in manager or your password manager, so passkeys are not scattered.
Sign out and sign back in with the passkey to check it works.
Repeat for your password manager, bank, PayPal, Amazon and social accounts. Look for Passkeys in each account's security settings.
For your most important accounts, add a second passkey in a different place, such as a security key or a second device.
Save each account's backup or recovery codes somewhere offline.
Signing in on a computer that is not yours
Choose the option to use a passkey from a phone or tablet. The computer shows a QR code, you scan it with your phone and approve with your face or fingerprint. The phone must be physically near the computer, checked over Bluetooth, which stops a criminal elsewhere from relaying the request.
Do not save a new passkey on a shared or work computer that other people use. Sign out when you finish.
If you lose your phone
Synced passkeys on Apple or Google come back when you sign in to the same Apple Account or Google Account on a replacement device. Keep your account password, recovery contact or recovery key, and Google Password Manager PIN up to date for this moment.
Passkeys in a password manager return when you sign in to the manager on a new device. Store its emergency kit or recovery code offline.
From another device, remove the lost phone from your Apple Account or Google Account device list.
If the lost device held your only passkey for an account, use that account's backup codes or its recovery process, then create a new passkey.
An account is only as strong as its weakest recovery option. If a site still lets anyone regain access with a text message code, a SIM swap can get around your passkey.
What passkeys do not fix
Malware on your computer that steals your logged-in session after you sign in. Keep devices updated and avoid pirated software.
Sites that keep your old password active. Remove the password where the site lets you, as Microsoft does.
Someone who has your unlocked phone or knows its PIN. Use a strong screen lock.
Switching ecosystems. The FIDO Alliance has published Credential Exchange specifications to move passkeys securely between managers, but support is still arriving, so plan to create new passkeys when you switch.
Frequently asked questions
Are passkeys safer than a password plus two-factor authentication?
Yes, against phishing and breaches. A password and a one-time code can both be typed into a fake site. A passkey cannot be used on the wrong site and there is no shared secret to steal from the company.
Can Apple or Google see my passkeys?
Both say synced passkeys are end-to-end encrypted, so the companies cannot read them. Your protection then depends on your account password, screen lock and recovery settings.
What happens if I switch from iPhone to Android?
Passkeys in iCloud Keychain do not automatically move to Google. Use a cross-platform password manager, or sign in on the new phone and create new passkeys, before retiring the old one.
Do I still need a password manager?
Most people do. Many sites still use passwords, and a password manager can hold both passwords and passkeys in one place that works across all your devices.
Can someone in my family use my passkeys?
Anyone who can unlock your device with its PIN can use the passkeys on it. Do not share your phone PIN, and give family members their own accounts.