A passkey is a login credential that replaces your password with a pair of cryptographic keys. One key stays locked on your phone, computer or security key; the other is held by the website. When you sign in, you unlock your device with a fingerprint, face scan or screen-lock PIN, and the device proves who you are without sending any secret over the internet. Because a passkey only works on the site it was created for, it cannot be typed into a fake website. That is the main reason security agencies and the big platforms are pushing them.
What’s wrong with passwords
Passwords have one basic flaw: they are a shared secret. You know it, the website stores a version of it, and anyone who learns it can use it. That creates three recurring problems.
- People reuse them. A password leaked from one site gets tried on many others.
- Sites leak them. When a company’s database is breached, stored password data can be stolen and cracked.
- People can be tricked into handing them over. A convincing fake login page collects the password, and often the one-time code as well.
The scale of attack is large. Microsoft said it saw about 7,000 password attacks per second in 2024, more than double the rate a year earlier.
Even official guidance on passwords has changed. The US National Institute of Standards and Technology’s digital identity guidelines, SP 800-63B-4 (final version published July 2025), now say services should not force periodic password changes or demand mixtures of character types. Instead they should check new passwords against lists of common and compromised ones, and require at least 15 characters when a password is the only factor. Those rules make passwords less painful. They don’t fix the shared-secret problem.
Public-key cryptography, without the maths
Passkeys rest on an idea from the 1970s called public-key cryptography. You generate two mathematically linked keys:
- a private key, which you keep secret, and
- a public key, which you can give to anyone.
Something “signed” with the private key can be checked by anyone holding the public key. But knowing the public key does not let you work out the private key. In the words of the FIDO Alliance’s Passkey Central, it is “not computationally feasible to extract the private key from the public key”.
A rough analogy: the website holds a uniquely shaped padlock (the public key), and only your device holds the key that can produce a matching impression (the private key). The website can check the impression against its padlock, but owning the padlock doesn’t let anyone cut the key.
The practical result is that the website never stores anything worth stealing for login purposes. If its database leaks, attackers get public keys, which cannot be used to sign in as you.
What a passkey is
The FIDO Alliance, the industry body that wrote the standards, defines a passkey as a credential based on FIDO standards that can be stored on your phone or computer, or on a hardware security key, and lets you sign in “with the same process that they use to unlock their device”.
Three details matter:
- One passkey per account per site. A unique passkey is created for each domain and account, so nothing is reused across services.
- Your fingerprint or face is not sent anywhere. The biometric check only unlocks the private key on your device. Google says the biometric data stays on your device and is never shared with Google.
- It is built on open standards. The browser side is the W3C’s Web Authentication (WebAuthn) specification. Its Level 3 version became a full W3C Recommendation on 25 August 2026. W3C describes it as an API for creating public-key credentials that are “scoped” to specific websites and used only with the user’s consent.
How passkey sign-in works, step by step
Creating the passkey (once per account):
- You sign in to a site the usual way and choose “create a passkey”, or the site offers one.
- Your device asks you to confirm with your fingerprint, face or screen lock.
- The device creates a new key pair for that site and account. The private key stays in your device or password manager.
- Only the public key is sent to the site, which stores it against your account.
Signing in (every time after):
- The site sends your device a random “challenge”, a one-off piece of data.
- Your device checks that the request comes from the website the passkey was created for.
- You unlock with your fingerprint, face or PIN.
- The device signs the challenge with the private key and sends back the signature.
- The site checks the signature with your stored public key and lets you in.
This is the flow described by the FIDO Alliance. Nothing reusable crosses the network: the challenge is different every time, and the private key never leaves your device or password manager.
Synced vs device-bound passkeys
There are two kinds, and the difference decides what happens if you lose a device.
| Synced passkey | Device-bound passkey | |
|---|---|---|
| Where it lives | A password manager that syncs across your devices, such as iCloud Keychain or Google Password Manager | One physical device only, such as a hardware security key |
| Lose your phone? | Still available on your other devices or after restoring your account | Gone; you need another sign-in method or a backup key |
| Convenience | High: create once, use on phone, laptop and tablet | Lower: you carry the device or keep a spare |
| Typical use | Everyday consumer accounts | High-security work accounts, admins, journalists, officials |
Source: FIDO Alliance.
Both Apple and Google encrypt synced passkeys end to end. Apple says iCloud Keychain uses end-to-end encryption with keys Apple does not know. Google added a Google Password Manager PIN in September 2024 so that passkeys stay end-to-end encrypted when synced across Windows, macOS, Linux and Android.
The trade-off shows up in the rulebooks. NIST’s SP 800-63B-4 accepts syncable authenticators up to its middle assurance level (AAL2) but says they “SHALL NOT be used at AAL3”, the highest level, because the key can be copied to other devices. For most people, a synced passkey is far stronger than what they use today. For the most sensitive accounts, a device-bound key is the stricter option.
What happens if you lose your phone
This is the first question most people ask, and the answer depends on the type of passkey.
- Synced passkeys come back when you sign in to the same Apple or Google account on a new device. Apple describes an iCloud Keychain recovery process that requires your Apple account credentials, a code sent by SMS and a device passcode, with a limit of 10 attempts before the escrowed record is destroyed. You can also add an account recovery contact. On Google, a new device needs your Google Password Manager PIN or an Android screen lock to unlock synced passkeys.
- Device-bound passkeys cannot be recovered. That’s why people who use hardware keys usually register two and keep one somewhere safe.
- Remove the lost device’s access. Google advises signing in from another device and removing that passkey under “Passkeys and security keys” in your account settings.
Also, each website runs its own account recovery. Many still fall back to an SMS code or email link if you can’t use your passkey, so your account is only as strong as that fallback.
Why passkeys resist phishing
Phishing works because people can be persuaded to type a secret into the wrong place. Fake bank pages, “KYC update” links and lookalike login screens all rely on it. In India the same trick drives many payment scams, which we explain in how UPI frauds work.
A passkey cannot be typed at all. Your device checks which website is asking and will only use the passkey for the site it was created on. As FIDO puts it, a passkey is “only presented to the site it was registered with”. A lookalike domain gets nothing.
NIST draws the line clearly. Its guidelines say any method where you manually enter a code “SHALL NOT be considered phishing-resistant”, because a typed code is not bound to the real session. An attacker’s fake page can collect it and pass it on to the real site while it is still valid. The US Cybersecurity and Infrastructure Security Agency (CISA) calls FIDO/WebAuthn the only widely available phishing-resistant authentication. Our comparison of two-factor methods covers where SMS codes, authenticator apps and push approvals sit relative to passkeys.
One caveat: passkeys protect the login step. They don’t stop someone from persuading you to approve a payment or install a screen-sharing app after you are signed in.
Where passkeys work today
Support is now built into the major operating systems and browsers. Google lists the minimum versions for its passkeys as Android 9, iOS 16, Windows 10, macOS Ventura and ChromeOS 109, with Chrome, Safari and Edge 109+ and Firefox 122+. You can also use a phone to sign in on a nearby computer: the computer shows a QR code, you scan it with your phone (Bluetooth must be on), and you confirm on the phone.
The large account providers have moved first. Microsoft made new Microsoft accounts “passwordless by default” from May 2025. It also reported that passkey sign-ins succeed about 98% of the time, against 32% for passwords, and are eight times faster than a password plus a second factor. That is Microsoft’s own data.
On the wider picture, the FIDO Alliance estimated in May 2026 that about 5 billion passkeys are in use worldwide. In its April 2026 survey of 11,000 consumers in ten countries, including India, 75% said they had enabled a passkey on at least one account. Both figures come from an industry body that promotes passkeys, so read them as indicative rather than independent.
The limitations
Passkeys are a clear improvement, but they are not finished.
- Patchy support. Many websites and apps still don’t offer passkeys. Where they do, the passkey often sits alongside a password rather than replacing it.
- Weak fallbacks. If a site still lets you reset access with an SMS code, an attacker can target that route instead. CISA notes that some services default to SMS during account recovery.
- Ecosystem lock-in. Synced passkeys historically stayed inside one ecosystem. Moving them is getting easier: the FIDO Alliance has been developing credential exchange standards, and Apple announced passkey import and export between credential manager apps in its 2025 (version 26) operating systems. Cross-platform transfer is still maturing.
- Shared and borrowed devices. A passkey on a family phone is usable by anyone who can unlock that phone. Your screen lock becomes the front door.
- Your platform account matters more. If your synced passkeys live in your Apple or Google account, protecting that account (strong screen lock, recovery contacts, a second factor) becomes more important.
- Confusing prompts. “Use a passkey”, “use your phone”, “use a security key” and QR codes can look alike to a first-time user. This is improving but still causes drop-offs.
Passwords vs OTP vs passkeys
| Password | Password + SMS/app OTP | Passkey | |
|---|---|---|---|
| What you provide | Something you know | Something you know + a code | Device unlock (biometric or PIN) |
| Secret stored by the site | Yes (hashed password) | Yes, plus your phone number or OTP seed | No; only a public key |
| Can be phished on a fake site | Yes | Yes; codes can be relayed in real time | No; bound to the real site |
| Useful to attackers after a site breach | Often | Partly | No |
| Hit by SIM swap | No | Yes, if SMS | No |
| Effort per sign-in | Type and remember | Type, wait, type again | One tap or glance |
| Recovery if you forget or lose | Reset link | Reset plus new phone/app | Sync from your account, or a backup key |
Sources: NIST SP 800-63B-4, CISA, FIDO Alliance.
How to start using passkeys
- Secure the account that will hold them. For most people that is the Apple or Google account on their phone. Use a strong screen lock and set up recovery options.
- Start with your email account. Email is the reset route for almost everything else. Google, Microsoft and Apple accounts all support passkeys.
- Accept the prompt when a site offers one. Or look in the site’s security settings for “passkeys” or “sign-in options”.
- Keep a second way in. Register a passkey on a second device, or keep backup codes somewhere safe.
- Tidy up the fallbacks. Where a site lets you, remove old SMS-based recovery or replace it with something stronger, as long as you still have a reliable way back in.
- For high-risk accounts, consider hardware keys. Register two device-bound security keys and store one separately.
The point: A passkey replaces a secret you type with a cryptographic key that never leaves your device and only works on the real website. That stops phishing and makes database leaks far less useful to attackers. The weak spots now are account recovery and sites that still fall back to passwords or SMS. Protect the platform account that holds your passkeys and keep a second way in.
Sources
- Passkeys — FIDO Alliance
- How passkeys work — Passkey Central, FIDO Alliance
- FIDO Alliance reports accelerating global passkey adoption on World Passkey Day 2026 — FIDO Alliance, May 2026
- Web Authentication Level 3 is now a W3C Recommendation — W3C, August 2026
- SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management — NIST, July 2025 (publication record)
- Passkeys security — Apple Platform Security
- Sign in with a passkey instead of a password — Google Account Help
- More users can now save passkeys in Google Password Manager — Google, September 2024
- Pushing passkeys forward — Microsoft Security blog, May 2025
- Implementing phishing-resistant MFA — CISA, October 2022
- Mobile communications best practice guidance — CISA
- Apple introduces cross-platform passkey import/export features — Mobile ID World via FIDO Alliance, June 2025