What is a passkey?
A passkey is a sign-in key that lives on your device or in your password manager. When a site asks you to sign in, your device checks it’s you with your face, fingerprint or PIN, then proves to the site that it holds the key. You never see or type the key. The FIDO Alliance, the industry group that wrote the standard, says you sign in “with the same process that they use to unlock their device”.
How does a passkey work?
Every passkey is a pair of keys made for one site. One key is private. It stays with you, on your phone, your computer, your password manager or a hardware security key. The other key is public, and the website keeps it.
When you sign in, the site sends your device a random challenge. Your device asks you to unlock it. Then it signs the challenge with the private key and sends back the signature. The site checks that signature with the public key it already has. If it matches, you’re in. Microsoft describes the same steps in its Windows passkey docs: the device “must prove that it possesses the private key by signing a challenge”.
Two things follow from that. The private key never travels to the website, so a break-in at the site can’t leak it. Apple’s passkey security page puts it plainly: the public key “is not a secret”. And your face or fingerprint never leaves your device either. It only unlocks the key locally.
Why a passkey can’t be phished
Each passkey is tied to the web address of the site that made it. Your browser or phone will only offer the passkey for google.com on google.com. A fake page at go0gle-login.com gets nothing, because your device has no passkey for that address. The software does the checking, so you don’t have to spot the fake.
This is the biggest gain over passwords. A careful person can still type a good password into a convincing fake page at 11 p.m. With a passkey, there’s nothing to type.
Passkey vs password: what’s the difference?
A password is a secret you know and the site also keeps a copy of (hopefully scrambled). A passkey is a secret only your device knows, and the site keeps a public key that can’t be used to sign in.
| Password | Passkey | |
|---|---|---|
| What you do to sign in | Type or paste it | Face, fingerprint or PIN |
| What the site stores | A copy of your secret, usually hashed | A public key, useless to a thief |
| Can it be reused on other sites? | Yes, and people do | No, one per site |
| Can a fake site trick you into giving it up? | Yes | No, it only works on the real address |
| Can it be guessed? | If it's weak | No |
| Works on any device, anywhere | Yes | Mostly, with a phone nearby or a synced manager |
Passwords still have one edge. You can type one on a borrowed computer with nothing else in hand. Passkeys need your phone nearby or your password manager signed in. That’s why most sites keep your password as a fallback after you add a passkey. So you still want good passwords for now. Our password generator makes random ones in the browser.
Passkey vs 2FA codes
Two-factor codes (a text message, or six digits from an authenticator app) sit on top of a password. They help a lot. But a code is still something you type, so a good fake page can ask for it and pass it on to the real site before it expires.
A passkey already covers both factors. You need the device that holds the key, and you need to unlock it with your face, fingerprint or PIN. Google says so on its passkey help page: if your account has 2-Step Verification, “your passkey bypasses the second authentication step, since this verifies that you own the device.”
Where are passkeys stored?
In whatever app your device uses to keep sign-ins. The standard calls these passkey providers. As of September 2026 the common ones are:
- iPhone, iPad and Mac:the Passwords app, which syncs through iCloud Keychain. Apple says iCloud Keychain is end-to-end encrypted with keys Apple doesn’t know.
- Android and Chrome: Google Password Manager, synced through your Google Account.
- Windows: Windows Hello keeps passkeys on that one PC. Windows 11 can also hand passkeys to a manager you pick, under Settings, then Accounts, then Passkeys, then Advanced options. Microsoft Password Manager in Edge can sync them.
- 1Password and Bitwarden: both save passkeys and work on Windows, Mac, iPhone and Android. 1Password lists its browser extension and apps. Bitwarden’s mobile apps need iOS 17 or Android 14.
- A hardware security key such as a YubiKey. The passkey can’t leave the key at all.
That last one points to the two kinds of passkey. A synced passkeyis copied to all your devices through your manager’s cloud. A device-bound passkeynever leaves the one device or key it was made on. Synced is easier to live with. Device-bound is harder to steal, since no copy sits in anyone’s cloud.
If you mix platforms (an iPhone and a Windows PC, say), a cross-platform manager like 1Password or Bitwarden saves you a lot of hopping. Apple Passwords and Google Password Manager each work best inside their own world.
How do I use a passkey on a computer that doesn’t have it?
Use your phone. On the computer’s sign-in page, pick the option to use a passkey from another device. A QR code appears. Scan it with your phone’s camera, then unlock the phone. On Google’s sign-in page the path is Try another way, then Use your passkey.
Both devices need Bluetooth on. The phone and computer use it only to prove they’re in the same room. That stops someone far away from sending you a QR code and borrowing your sign-in. Microsoft’s docs say both devices also need an internet connection, and the passkey itself isn’t copied to the computer. The FIDO documents call this cross-device sign-in, or “hybrid”. It works between brands, so an iPhone can sign you in on a Windows PC.
What happens to my passkeys if I lose my phone?
It depends on where they were stored.
- Synced passkeys come back when you sign in to the same manager on a new device. Apple says passkeys can be recovered through iCloud Keychain even if you lose every device, as long as you can get back into your Apple Account.
- Device-bound passkeys are gone with the device. You sign in with your password or another backup method, then make a new passkey.
Either way, remove the lost phone’s passkeys from your accounts. A thief would still need to unlock the phone, but there’s no reason to leave them there. For a Google Account, Google’s stepsare to sign in on another device and remove the passkey from Security & sign-in. And keep at least one backup way in on every important account, like a password in your manager or a recovery code.
Can you move passkeys to another password manager?
Yes, since late 2025. The FIDO Alliance wrote a pair of standards for it. One is the Credential Exchange Format, which sets out what the moved data looks like. It became a FIDO Proposed Standard in August 2025. The other, the Credential Exchange Protocol, covers how two apps hand the data over safely. The transfer stays encrypted the whole way, with no loose file of your sign-ins sitting in your Downloads folder.
As of September 2026, this is what works:
- iPhone, iPad and Mac:since iOS 26 and macOS 26, the Passwords app can export passwords and passkeys to another manager on the same device. Ricky Mondello, who works on Apple’s password features, listsApple Passwords, 1Password, Bitwarden, Dashlane, DuckDuckGo and Devolutions as apps that support it. He notes 1Password and some others haven’t added it on the Mac yet.
- Android: Google Play services 26.21, released June 1, 2026, added import and export between Google Password Manager and other managers using this standard.
- Windows:Microsoft’s passkey help pages don’t describe a way to export passkeys saved in Windows Hello.
Transfers happen between two apps on one device. There’s no direct iPhone-to-Android button. The workaround is a cross-platform manager: move your passkeys from Apple Passwords into Bitwarden or 1Password on the iPhone, and they sync to your Android phone from there.
How to delete a passkey
Deleting a passkey takes two steps, and people often do only one. The website has your public key. Your manager has the private key. Remove it from the site’s account settings so the site stops accepting it. Remove it from your manager so it stops popping up.
How to remove a passkey from a Microsoft account
Go to account.live.com/proofs/manage and sign in. Find the entry with the passkey icon, select the arrow to open it, and choose Remove. For a work or school account, use mysignins.microsoft.com/security-info instead. Microsoft warnsthat if you remove every way to prove it’s you, the account goes into a restricted state for 30 days. Add another method first.
On Windows
Open Settings, then Accounts, then Passkeys. Select the three dots next to the passkey and choose Delete passkey. This only clears passkeys saved on that PC. Passkeys in another manager get deleted in that manager.
On iPhone, iPad or Mac
Open the Passwords app and unlock it. Tap Passkeys, pick the account, then tap Edit and Delete. It’s removed from your other Apple devices on the same Apple Account too. Changed your mind? Apple’s help page points to the Deleted section of the Passwords app.
In a Google Account
Open your Google Account, tap Security & sign-in, then Passkeys and security keys. Pick the passkey and tap Remove. Passkeys that an Android phone made on its own are removed by signing that phone out under Manage all devices.
Should you switch to passkeys?
For your email, your Apple, Google or Microsoft account, and your bank if it offers one, yes. Those are the accounts a phishing page most wants, and passkeys stop that attack. Pick one manager that works on all your devices and keep your passkeys there. Then set up a backup way in on each account before you need it.
Passkeys also mean fewer passwords sitting on your clipboard. Every password you copy and paste passes through it, and our guide to whether it’s safe to copy and paste passwords covers where that goes wrong. (Relic, our clipboard history app, skips copies a password manager marks as private on Windows and Mac.) For the passwords you still need to give to someone, read how to send a password securely. And if “end-to-end encrypted” on a passkey manager’s sales page sounds vague, our end-to-end encryption explainersays what it does and doesn’t cover.
Sources
- Passkeys, FIDO Alliance
- Terminology, passkeys.dev
- About the security of passkeys, Apple Support
- Find saved passwords and passkeys on your iPhone, Apple Support
- Sign in with a passkey instead of a password, Google Account Help
- Google system release notes (Play services v26.21), Google (2026)
- Manage your saved passkeys, Microsoft Support
- Support for passkeys in Windows, Microsoft Learn (2026)
- Storing passkeys, Bitwarden Help
- Save and sign in with passkeys in your browser, 1Password Support
- Portability without compromise: a new standard for secure credential transfer, 1Password (2025)
- Switching password managers in 2026, Ricky Mondello (2026)