Passkeys
How to Add a Backup Method Before Enabling Passkeys
Passkeys can improve sign-in security, but recovery planning still matters. This guide explains how to prepare backup methods, recovery emails, phones, and codes before switching important accounts.
Set recovery before you depend on passkeys
Before enabling passkeys, make sure you have a current recovery email, recovery phone, trusted device, backup codes, and another sign-in method where the provider supports it. Passkeys can reduce password risk, but losing access to the only device or recovery path can create account lockout.
Do not remove existing recovery methods until you understand how the provider handles lost devices and passkey recovery. Each platform has different rules.
For important accounts, read the official provider instructions before changing sign-in methods.
Why backup methods still matter
Passkeys are designed to reduce password phishing and reuse. But people still lose phones, replace laptops, change numbers, leave jobs, and forget which account syncs credentials.
A backup method is not a weakness if it is protected well. The danger is an outdated recovery email, phone number you no longer control, or backup code stored in an unsafe place.
NIST recognizes phishing-resistant authentication such as passkeys, while CISA continues to recommend MFA and strong account recovery habits.
- Lost phone.
- Broken laptop.
- Changed phone number.
- Old recovery email.
- Forgotten platform account password.
- Work device returned to employer.
Inventory your current recovery setup
Before enabling passkeys, review account settings. Confirm the login email, recovery email, recovery phone, MFA method, backup codes, trusted devices, and connected accounts.
Only use recovery emails and phone numbers you control. Remove old work, school, or abandoned methods before they become the only path back.
Add backup codes securely
If the provider offers backup codes, generate new ones and store them securely. Do not save them in an unprotected screenshot, public cloud folder, or email draft.
A password manager or secure offline record can help, depending on your threat model and comfort.
Register more than one trusted device
Where supported, add passkeys on more than one device you control. This reduces the risk that one lost phone blocks access.
Do not add shared or public devices as trusted passkey devices.
Keep your password manager during transition
Many accounts still require passwords or recovery notes. Keep a password manager for unique passwords, backup codes, and account inventory.
Do not delete old passwords until the account confirms passkey sign-in and recovery works as expected.
Test recovery before you need it
Review the provider's recovery flow and confirm you can receive messages at the recovery email and phone. Avoid triggering unnecessary lockouts, but make sure the information is current.
For work accounts, follow employer policy and ask IT before changing authentication methods.
Check exposure on remaining password accounts
Passkeys help where enabled, but accounts that still use passwords need cleanup. Check email or username exposure and replace reused passwords.
Never enter current passwords or authentication codes into an exposure checker.
Frequently asked questions
Do passkeys need backup codes?
Some accounts offer backup codes or other recovery methods. Use official provider guidance and keep recovery current.
Should I remove my password after adding a passkey?
Only if the provider supports it and you understand recovery. Many accounts still keep passwords as backup.
Can I use passkeys on multiple devices?
Often yes, depending on the provider and platform. Add only devices you control.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
