Why Now Daily.

Published

Passkeys Explained: How Passwordless Sign-In Works

A passkey uses a site-specific public/private key pair instead of a reusable password. The service stores the public key, while a device or credential provider protects the private key and releases a signed response after local verification such as a PIN or biometric.

Timeline

  1. At enrollment: The device creates a credential scoped to that website or app; the service receives the public key and the provider protects the private key.
  2. At sign-in: The service sends a challenge, the user unlocks the passkey locally, and the authenticator returns a signed response for verification.
  3. Before changing devices: Confirm which provider stores or syncs the passkey and verify the account's recovery methods or additional registered credentials.

A passkey is a FIDO credential that can replace a password for a supported website or app. During setup, an authenticator creates an asymmetric key pair scoped to that relying party. The service stores the public key; the private key remains under control of the user's authenticator or credential provider. At sign-in, the service sends a fresh challenge and verifies a cryptographic signature. There is no reusable shared password for the service to compare or for a user to type. [1][2]

The user normally authorizes the passkey with the same method used to unlock the device or credential manager, such as a fingerprint, face scan, device PIN or password. That local check is not sent to the website as biometric data. Google, for example, states that fingerprint and face data remain on the device. The authenticator confirms user verification and signs the challenge with the private key; the service validates that response using its stored public key. [1][3][4]

Passkeys resist common phishing because each credential is bound to a particular relying party and browser origin. A look-alike site cannot ask the authenticator to use a credential scoped to the genuine site. Public-key storage also means a server breach does not expose a password-equivalent secret that can simply be replayed elsewhere. That does not make an account invulnerable: compromised recovery channels, unlocked devices, malicious account changes and social engineering can still create risk. [1][2]

A synced passkey is copied, in protected form, among devices signed into the same credential provider; a device-bound passkey stays on one authenticator, such as a particular device or security key. FIDO distinguishes these models. Sync behavior depends on the selected provider and account configuration. Apple documents end-to-end encrypted iCloud Keychain syncing, while other ecosystems have their own controls. Creating a passkey on one phone therefore does not guarantee it appears in every browser or unrelated platform. [1][4]

Cross-device authentication can let a phone approve sign-in on a nearby computer even when the computer does not store the passkey. The site displays a QR code, the phone scans it and the FIDO protocol uses proximity checks before the phone's authenticator completes the request. This is a sign-in bridge, not a reason to scan unsolicited QR codes. Start from the genuine service, read the prompts and cancel if the domain, account or requested action is unexpected. [1][5]

Recovery is partly outside the passkey standard and varies by provider and service. A synced provider may restore encrypted credentials after its account-recovery checks; a device-bound credential may require another registered passkey or the site's fallback process. Before replacing or wiping a device, check where each important passkey is stored, add a second credential when the service permits and update recovery contacts. Do not delete a password or recovery method until the service confirms a safe alternative path. [1][4]

To adopt passkeys safely, secure the device and credential-provider account with a strong screen lock, current software and protected recovery information. Review the service's account page after enrollment, name unfamiliar credentials clearly and remove credentials from devices no longer controlled. A passkey improves the core sign-in exchange through origin-bound public-key cryptography, but the complete account also depends on device security, sync and recovery policy. Consult current provider and service instructions before migration because availability and workflows continue to change. [1][2][3][4]

Sources

  1. FIDO Alliance — Passkeys
  2. W3C — Web Authentication Level 3
  3. Google Account Help — Sign In With a Passkey Instead of a Password
  4. Apple Support — About the Security of Passkeys
  5. FIDO Alliance — Passkey Cross-Device Authentication

Related stories