Find out whether this device can use passkeys, where yours would be stored, and which accounts to switch first.
The device check asks your browser three yes or no questions and nothing else. Your answers stay in this browser. Nothing is sent to our server.
A passkey replaces a password with a key pair made for one website. Your device keeps the private half and unlocks it with your face, fingerprint or screen PIN; the website only ever holds the public half. There is nothing to type, nothing to reuse and nothing a fake login page can collect, which is why passkeys stop the phishing that passwords cannot.
Switching is easy on the right device and confusing on the wrong one. Passkeys saved on an iPhone do not appear on a Windows computer by default, and losing your only device can lock you out if you skipped a backup. This check looks at the browser you are using now, asks which devices and password manager you have, and gives you an order to switch that will not leave you stranded.
Most account takeovers start with a password: one reused from an old breach, or one typed into a fake login page. A passkey removes both routes. It is made for one website, so it cannot be reused elsewhere, and your device will only use it on the real site, so a lookalike page gets nothing.
The big platforms have moved. Apple syncs passkeys through iCloud Keychain, which it describes as end-to-end encrypted with keys it does not know. Google lets you save passkeys to Google Password Manager from Windows, macOS, Linux and Android, unlocked on a new device with a Google Password Manager PIN or your Android screen lock. Microsoft made brand new Microsoft accounts passwordless by default on 1 May 2025.
The common mistake is creating passkeys on one device with no second way back in. If that phone is lost or reset and the passkey was not synced, you are back to account recovery. Synced passkeys, a second device, an authenticator app or a hardware security key all solve this, and the plan makes you choose one before you rely on a passkey.
For sign-in, yes. A passkey is made for one website, so a breach elsewhere cannot expose it, and your device only uses it on the real site, so a fake login page cannot collect it. The FIDO Alliance, which sets the standard, says your fingerprint or face data never leaves your device.
If your passkeys were synced, they are on your other devices and come back when you sign in to a new phone with your Apple Account or Google Password Manager. If they were stored on that phone only, you will need another sign-in method on each account. That is why the plan asks you to set up a second way in before relying on a passkey.
Yes. Choose the option to use a passkey from a phone or tablet. The computer shows a QR code, you scan it with the iPhone and approve with Face ID. The phone has to be close by, checked over Bluetooth, which stops someone elsewhere relaying the request. To have the same passkeys on both without scanning, store them in a password manager that runs on both.
No. Your fingerprint or face only unlocks the private key on your own device. The website receives a signature that proves you hold the key, never the biometric itself.
Only if the site lets you, and only after the passkey works on at least two of your devices or you have another recovery method. Until then keep the password, but make it long and unique so it is not the weak point.
Your main email account, because it can reset the passwords of everything else. Then your password manager or Apple, Google or Microsoft account, then shopping, payment and social accounts. Banks vary, so check your bank's security settings.
Some computers have no fingerprint reader, camera for face sign-in, or Windows Hello PIN set up. You can turn on Windows Hello in Settings, or keep your passkeys on your phone and approve sign-ins by scanning the QR code.