Skip to content
All guides

Account security

What Is a Passkey?

A passkey is a login stored on a device you control and tied to the real website. This guide explains the idea in plain English and how to add one safely.

By the 4safer teamUpdated August 29, 20267 minutes read

How a passkey feels in real life

On a good day it feels like unlocking the phone.

Behind the scenes, the service stores a public piece of the key. Your device keeps the private piece. The two only work as a pair, and they are meant to work only for that real domain. You do not need to understand the math. You need the outcome: a list of leaked passwords from last year should not open the account if a passkey is required and you do not approve a fake prompt.

  • You open the real website or app.
  • The site offers “Sign in with passkey.”
  • You confirm with Face ID, a fingerprint, a PIN, or a security key.
  • You are in. There is no password to remember for that site.

Passkey, password, and MFA

A password is a secret you can type, reuse, and leak. Multifactor authentication adds a second proof, such as an app code or a text message. A passkey is a different kind of credential. On many sites it replaces the password. On others it sits beside the password as a stronger sign-in option. CISA tells households to add a second factor and names a FIDO security key as a strong choice. Passkeys use the same family of standards as those keys. NIST’s digital identity guidelines treat stronger authenticators as more appropriate when an account deserves higher confidence — which a mailbox that resets a bank login does. A text-message code can still be phished if you type it into the wrong page. A well-implemented passkey is built to refuse the wrong domain. That is the upgrade.

What a passkey cannot fix

Synced passkeys, stored in a platform account or a manager, are convenient. They also mean the recovery account that syncs them must stay locked down. Device-only keys and hardware security keys are less convenient and harder to copy. Pick based on the account, not on a slogan.

  • It cannot pull your email out of an old exposure file.
  • It cannot freeze credit.
  • It cannot help if you approve a sign-in you did not start.
  • It cannot survive a stolen unlocked phone if that phone is the only copy and has no screen lock.
  • It cannot work on a site that has not turned the feature on yet.

How to add a passkey without getting tricked

The FTC’s account-protection advice still applies: unique secrets, two-factor authentication, and extra care on email, banking, tax, and payment apps. A passkey is one of the stronger ways to do that second step. If a chat window asks you to “generate a passkey so we can verify the leak,” close it. Official setup happens inside the account, not in a stranger’s ticket. After a leak, which accounts deserve a passkey first?

If a site has no passkey option, use a unique password plus an authenticator app or a security key. Do not wait for every company to catch up before you harden the mailbox.

  • Type the official site. Do not use a “create your passkey now” link from unexpected mail.
  • Sign in the old way on that typed page.
  • Open Security or Sign-in settings.
  • Choose Create a passkey, or the wording that site uses.
  • Save it to the phone, computer, hardware key, or password manager you actually control.
  • Add a second passkey or a backup method so one lost phone is not a lockout.
  • If the site still allows passwords, make that password unique and leave MFA on until you are sure the passkey works.
  • Email
  • Apple, Google, or Microsoft accounts that hold the device
  • The password manager
  • Banks, brokerages, payroll, and tax logins
  • Shopping accounts that store cards

Living with passkeys

Keep the phone updated and locked. Review the list of passkeys in the platform settings and delete ones for accounts you closed. If you sell or give away a device, sign out and remove the keys first. If you lose every device that held the only passkey and you have no backup, use the provider’s official account recovery. That process can be slow. That is why a second key or a trusted manager copy is worth ten minutes now. Understanding what is a passkey is the easy part. Creating one on the official email site is the part that changes the next phishing email.

Practical checklist

  • Add passkeys only on websites you type yourself.
  • Start with email and the account that unlocks your phone.
  • Keep a backup key or a second device.
  • Unique password still required on sites without passkeys.
  • Deny sign-in prompts you did not start.
  • Screen lock on every device that stores a key.
  • Remove passkeys from a device before you give it away.
  • Never create a passkey at the request of an unexpected caller.

Frequently asked questions

Is a passkey the same as a saved password in the browser?

No. A saved password is still a string that can be stolen and reused. A passkey is a key pair meant to work only with the real site.

What if I use more than one phone?

Use a synced passkey through an account or manager you control, or register each device separately. Test a sign-in from the second device before you need it.

Should I delete my password after I add a passkey?

Only if the service lets you and you have a working backup. Some sites still need the password for recovery. Make it unique either way.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.