Passkey Readiness Check: Can You Switch to Passkeys?

Find out whether this device can use passkeys, where yours would be stored, and which accounts to switch first.

The device check asks your browser three yes or no questions and nothing else. Your answers stay in this browser. Nothing is sent to our server.

A passkey replaces a password with a key pair made for one website. Your device keeps the private half and unlocks it with your face, fingerprint or screen PIN; the website only ever holds the public half. There is nothing to type, nothing to reuse and nothing a fake login page can collect, which is why passkeys stop the phishing that passwords cannot.

Switching is easy on the right device and confusing on the wrong one. Passkeys saved on an iPhone do not appear on a Windows computer by default, and losing your only device can lock you out if you skipped a backup. This check looks at the browser you are using now, asks which devices and password manager you have, and gives you an order to switch that will not leave you stranded.

How it works

  1. Your browser is asked whether it supports the Web Authentication standard that passkeys are built on. This is the PublicKeyCredential interface, which every current major browser includes.
  2. It is then asked whether this device has a built-in authenticator that can verify you, such as Touch ID, Face ID, Windows Hello or an Android screen lock. Without one, you can still use a passkey stored on your phone by scanning a QR code.
  3. It is asked whether sign-in boxes can offer passkeys in autofill, which decides whether you will see passkeys suggested as you type or need to press a separate button.
  4. You tick the devices you use and the password manager you rely on. The mix decides where your passkeys will live and whether they will follow you from phone to computer.
  5. If a recent breach check showed leaked passwords, the plan puts changing those first, because adding a passkey does not close an old password route.
  6. The plan lists the accounts to switch in order and the backup you need before you rely on any passkey. Nothing you choose leaves the page.

Reading your results

  • Ready: the browser supports passkeys and this device can unlock them with a fingerprint, face or PIN. You can create passkeys on this device today.
  • Mostly ready: the browser supports passkeys but this device has no built-in authenticator. Store passkeys on your phone instead and sign in here by scanning the QR code the site shows.
  • Not yet: the browser does not support passkeys. Update it, or use a current version of Chrome, Edge, Firefox or Safari, then run the check again.
  • Where your passkeys live: the password manager that will hold them, how it syncs and what you need to unlock it on a new device.
  • Switch order: your main email first because it can reset everything else, then a backup sign-in method, then accounts where you spend money.

How this fits into the real world

Most account takeovers start with a password: one reused from an old breach, or one typed into a fake login page. A passkey removes both routes. It is made for one website, so it cannot be reused elsewhere, and your device will only use it on the real site, so a lookalike page gets nothing.

The big platforms have moved. Apple syncs passkeys through iCloud Keychain, which it describes as end-to-end encrypted with keys it does not know. Google lets you save passkeys to Google Password Manager from Windows, macOS, Linux and Android, unlocked on a new device with a Google Password Manager PIN or your Android screen lock. Microsoft made brand new Microsoft accounts passwordless by default on 1 May 2025.

The common mistake is creating passkeys on one device with no second way back in. If that phone is lost or reset and the passkey was not synced, you are back to account recovery. Synced passkeys, a second device, an authenticator app or a hardware security key all solve this, and the plan makes you choose one before you rely on a passkey.

Who this is for

  • Anyone a site has asked to 'create a passkey' who is not sure what happens next.
  • People with a mix of Apple and Windows or Android devices who want passkeys to work on all of them.
  • Anyone whose breach check showed leaked passwords and who wants a stronger sign-in for their email.
  • Families setting up a parent's phone so they cannot be phished out of their email or banking login.

What this tool cannot tell you

  • It checks the browser and device you are using now. Run it again on your other devices, because support depends on each one.
  • It cannot see which of your accounts offer passkeys. Sites add support all the time; look under Security or Sign-in settings on each account.
  • A passkey protects sign-in only. It does not stop malware already on your device, a company breach of your other data, or a scammer talking you into moving money.
  • Where a site keeps your password as a fallback, that password can still be phished or leaked. Keep it long and unique until you can remove it.

Frequently asked questions

Are passkeys safer than passwords?

For sign-in, yes. A passkey is made for one website, so a breach elsewhere cannot expose it, and your device only uses it on the real site, so a fake login page cannot collect it. The FIDO Alliance, which sets the standard, says your fingerprint or face data never leaves your device.

What happens if I lose my phone?

If your passkeys were synced, they are on your other devices and come back when you sign in to a new phone with your Apple Account or Google Password Manager. If they were stored on that phone only, you will need another sign-in method on each account. That is why the plan asks you to set up a second way in before relying on a passkey.

Can I use a passkey from my iPhone on a Windows computer?

Yes. Choose the option to use a passkey from a phone or tablet. The computer shows a QR code, you scan it with the iPhone and approve with Face ID. The phone has to be close by, checked over Bluetooth, which stops someone elsewhere relaying the request. To have the same passkeys on both without scanning, store them in a password manager that runs on both.

Does a website get my fingerprint or face?

No. Your fingerprint or face only unlocks the private key on your own device. The website receives a signature that proves you hold the key, never the biometric itself.

Should I delete my password after adding a passkey?

Only if the site lets you, and only after the passkey works on at least two of your devices or you have another recovery method. Until then keep the password, but make it long and unique so it is not the weak point.

Which accounts should get a passkey first?

Your main email account, because it can reset the passwords of everything else. Then your password manager or Apple, Google or Microsoft account, then shopping, payment and social accounts. Banks vary, so check your bank's security settings.

Why does the check say my device cannot unlock passkeys?

Some computers have no fingerprint reader, camera for face sign-in, or Windows Hello PIN set up. You can turn on Windows Hello in Settings, or keep your passkeys on your phone and approve sign-ins by scanning the QR code.

Related tools

Guides that go with this tool