A phone using a passkey to unlock a secure online account

Passwords ask users and websites to share a secret. Passkeys use a different model: a pair of cryptographic keys. One remains protected on the user's device or credential manager, while the other is registered with the website.

When a person signs in, the site sends a challenge. The device proves that it holds the private key, usually after the user confirms with a fingerprint, face scan or screen-lock PIN. The private key itself is not sent to the site.

Why passkeys resist phishing

A password can be typed into a convincing fake login page. A passkey is linked to the genuine website domain. A fraudulent page on another domain cannot normally request and use the credential created for the real service.

This removes the reusable secret that phishing attacks try to steal. It also reduces the damage from a website database leak because the public key stored by the service cannot be used to impersonate the user by itself.

Biometrics do not go to the website

Face or fingerprint recognition usually unlocks the passkey locally. The site receives proof that the device authorised the sign-in, not a copy of the biometric image.

The same principle applies when a phone PIN is used. The local authentication method protects access to the credential; it is not the credential sent across the internet.

How passkeys work across devices

Credential managers can synchronise passkeys between devices connected to the same account. This makes a passkey available after a user upgrades a phone or signs in on a laptop.

Another common method uses a nearby phone to approve login on a computer. A QR code starts a secure proximity check, and the phone completes the cryptographic response. Users should still verify the website and device before approving.

What happens if a phone is lost?

A lost device does not automatically mean a lost account. Synced passkeys may be restored through the platform account's recovery process. Services can also allow more than one passkey, a hardware security key or a separate recovery method.

Recovery remains the weak point if it falls back to easily stolen email or SMS codes. Users should protect their primary email account, save recovery codes where offered and register a second trusted device.

Can passkeys be shared?

Some credential managers support controlled sharing, useful for household accounts. Sharing should happen only through the manager's built-in feature, not through screenshots or messages.

Businesses may use managed passkeys with device policies. The exact portability depends on the platform and service, so people who use several ecosystems should check export, recovery and cross-device options before removing every fallback.

Are passwords disappearing immediately?

No. Many sites still require passwords, and some offer a passkey only after a password-based account is created. During the transition, an account may be only as strong as its weakest recovery path.

The safest approach is to use a passkey where supported, keep devices updated and remove old sign-in methods only after confirming recovery options.

The bottom line

Passkeys replace a memorised secret with cryptographic proof tied to the legitimate website. They offer strong phishing resistance and faster sign-in, while biometrics remain on the device. Their success still depends on secure device locks and careful account recovery. Find more practical guides in the Technology section and read our explainer on how AI search overviews work.