Passkeys explained: signing in without a password

Passkeys replace the password: you sign in with your fingerprint, your face or your device PIN – phishing-proof and easier day to day. Here is how it works.

“Another password to remember?” – that is exactly what passkeys are meant to end. Instead of a secret you type in (and forget, reuse, or hand to a scammer), you sign in with your fingerprint, your face or your device PIN. It sounds futuristic, but it already works at most large services.

The short version

  • Passkey instead of password: you unlock the sign-in the way you unlock your phone.
  • Phishing-proof: there is no password to enter on a fake page.
  • Nothing to remember: no secret that can be weak, reused or stolen.
  • Across devices: passkeys sync encrypted, through your provider or your password manager .

How a passkey works – without a computer science degree

When you set one up, your device creates a key pair: a private key and a public one. The public key sits with the service (Google, your bank). The private key stays on your device and never leaves it.

When you sign in, your device proves to the service that it holds the matching private key – unlocked by your fingerprint, your face or your PIN. No secret is ever transmitted that anyone could intercept.

The decisive advantage Because you type no password, no convincing fake page can trick you. The passkey technically only works on the real website it was created for.

Passkey vs. password

PasswordPasskey
Have to remember ityesno
Can be phishedyeseffectively no
At risk in a breachyesno (no secret is stored)
Signing intypingfingerprint / face / PIN
Second factor neededrecommendedalready included

Setting one up

The exact steps differ per service, but the pattern is always the same:

Four steps to your first passkey

  • 1. Open your account: look for “passkey” in the service’s security settings (often under “sign-in” or “security”).
  • 2. Create the passkey: tap “add a passkey” and confirm with fingerprint, face or device PIN.
  • 3. Choose where it lives: on the device itself, in your system’s cloud (Apple, Google, Microsoft) or in your password manager .
  • 4. Test it: sign out and back in once, so you know the flow.

What if I lose my device?

A fair worry, and it is handled. With most providers, passkeys are backed up encrypted and reappear on a new device once you sign in. What matters is:

  • Protect the account holding your passkeys (Apple ID, Google account, Microsoft account or password manager) with a strong master password .
  • Set up more than one device where you can, so you are never locked out.
  • Keep any recovery codes somewhere safe.

Do I still need passwords and 2FA?

Yes – for now. Passkeys are spreading fast, but plenty of services do not support them yet. For everything else, two things stay mandatory:

  1. Unique passwords through a password manager .
  2. Two-factor authentication everywhere a passkey is not yet an option.

Our recommendation

Turn on passkeys wherever they are offered – especially for email, your Google or Apple account, and large stores. They are both more convenient and safer than passwords. Until they are everywhere, a password manager with 2FA remains your baseline.

Frequently asked questions

Are passkeys safer than passwords?

Yes, clearly. A passkey cannot be phished, because there is no secret you type in anywhere. The private key never leaves your device, and the sign-in only works on the real website – a fake page gets nothing.

What happens if I lose my phone?

Your passkeys are normally backed up, encrypted, in your provider’s cloud (Apple, Google, Microsoft) or in your password manager, and they reappear on a new device once you sign in. So the account holding them needs to be well protected, and a second device is worth having.

Do I still need a password manager?

Yes. Not every service supports passkeys yet, and every other account still needs a strong unique password. Many password managers now store both passwords and passkeys in one place.

Is a passkey the same as two-factor authentication?

Not quite. A passkey combines two things in one step: something you have (your device) and something you are or know (fingerprint, face or PIN). It replaces the password and the second factor together – a passkey sign-in needs no extra code.

Topics: Passkeys, Passwords, 2FA