A passkey is a FIDO credential used to sign in to an app or website. Instead of sending a reusable password, the device proves possession of a private cryptographic key.
How it works
The service stores a public key. Your phone, computer or security key keeps the matching private key. You approve sign-in using the device’s PIN, fingerprint, face unlock or another local method. The service receives a cryptographic proof, not your biometric data.
Why passkeys resist phishing
FIDO explains that a passkey is created for a specific domain and account. A fake site cannot simply collect and reuse it the way it can collect a password.
Synced and device-bound passkeys
Some passkeys sync through a platform account so they are available on several devices. Others stay on one device or hardware security key. The recovery plan differs, so check what the provider supports before removing an old device.
What passkeys do not solve
- A stolen unlocked device
- Weak account-recovery procedures
- Malicious software already controlling the device
- Scams that persuade you to send money voluntarily
Before switching
Update recovery email and phone details, secure the platform account that syncs your passkeys, and add another recovery method where the service permits it.
The bottom line
Passkeys can provide simpler and more phishing-resistant sign-in than reusable passwords. Their safety still depends on device security and a recovery plan you understand.