What Is a Passkey, and Is It Safer Than a Password?
A passkey is a FIDO-based cryptographic credential tied to a particular service; it replaces a typed password with approval on a trusted device and is designed to resist phishing and credential reuse.
Timeline
- Enrollment: The service registers a public key while the matching private key remains with the user's authenticator or credential manager.
- Sign-in: The legitimate service sends a challenge that the device approves after local user verification such as a PIN or biometric.
- Device change: A synced passkey may appear on a new trusted device; otherwise a backup authenticator or the service's recovery flow is needed.
A passkey is a digital credential used to sign in without typing a password. It is based on FIDO standards and uses public-key cryptography. When a passkey is created, the service stores a public key while the corresponding private key remains protected by a phone, computer, hardware security key or credential manager. The private key is not sent to the service during sign-in. [1][2][3]
Signing in normally feels like unlocking a device. The service sends a cryptographic challenge, the device asks for its usual PIN, fingerprint or face check, and the authenticator signs the challenge. The biometric stays on the device; the remote service receives proof that the check succeeded. Depending on the implementation, that possession-plus-verification process can itself satisfy multifactor authentication. [1][2][4]
Passkeys resist ordinary phishing because the credential is bound to the legitimate website or app. A look-alike site cannot ask a person to reveal or type the private key, and the authenticator will not use the credential for a different domain. Each service also gets a unique key pair, eliminating password reuse and making a stolen password database less useful for breaking into other accounts. [1][2][4]
Some passkeys synchronize through a platform or third-party credential manager, while other FIDO credentials stay on one device or hardware key. Synchronization makes a new device easier to use, but it makes the security and recovery of the credential-manager account important. Users should protect that account strongly, keep devices updated and understand whether their chosen provider supports their operating systems and browsers. [1][2][4]
A passkey does not mean a fingerprint or face image is uploaded to every website. Local biometrics are one way the device can authorize use of the private key; a device PIN can often serve the same purpose. The website receives a cryptographic response rather than the biometric. Device security still matters, because someone who can unlock a device may be able to use credentials stored on it. [1][2][3]
Before removing older sign-in methods, create a recovery plan. Add more than one trusted authenticator where the service permits it, secure the email or platform account used for recovery, store any recovery codes safely and learn how to revoke a credential from the account after a device is lost. A weak fallback password or easily hijacked recovery path can reduce the benefit of a strong passkey login. [2][4]
Use passkeys when a trusted service offers them and keep a strong, unique password plus two-step verification where it does not. Confirm that a passkey prompt belongs to the service you intended to visit, review the account's credential list periodically and remove devices you no longer control. Passkeys sharply reduce common remote credential attacks, but they still rely on secure devices, careful recovery and a legitimate implementation. [1][2][3][4]
Sources
- FIDO Alliance — Passkeys
- UK NCSC — Passkeys: What You Need to Know
- NIST — How Do I Create a Good Password?
- UK NCSC — Comparing Traditional and FIDO2 Credentials