---
title: What Is a Passkey? Passkey vs Password, Explained | Relic
description: A passkey lets you sign in with your face, fingerprint or PIN instead of a password. How passkeys work, how they compare to passwords and 2FA, and how to delete one.
canonical: https://relic.space/blog/what-is-a-passkey
source: https://relic.space/llms.txt
---
[Clipboard security & privacy](https://relic.space/blog/topics/clipboard-security)

# What is a passkey?

A passkey is a way to sign in without typing a password. Your phone or computer holds a secret key for the site, and you unlock it with your face, your fingerprint or your PIN. Google and Microsoft accounts offer them, and so do a growing number of other sites. They're safer than passwords mainly because a fake website can't trick you into handing one over. Below: how they work, where they're kept, and what to do when you lose a phone or want one gone.

[JGJordan Gibbs](https://relic.space/authors/jordan-gibbs) October 7, 2026 8 min read

## What is a passkey?

A passkey is a sign-in key that lives on your device or in your password manager. When a site asks you to sign in, your device checks it’s you with your face, fingerprint or PIN, then proves to the site that it holds the key. You never see or type the key. The [FIDO Alliance](https://fidoalliance.org/passkeys/), the industry group that wrote the standard, says you sign in “with the same process that they use to unlock their device”.

## How does a passkey work?

Every passkey is a pair of keys made for one site. One key is private. It stays with you, on your phone, your computer, your password manager or a hardware security key. The other key is public, and the website keeps it.

When you sign in, the site sends your device a random challenge. Your device asks you to unlock it. Then it signs the challenge with the private key and sends back the signature. The site checks that signature with the public key it already has. If it matches, you’re in. Microsoft describes the same steps in its [Windows passkey docs](https://learn.microsoft.com/en-us/windows/security/identity-protection/passkeys/): the device “must prove that it possesses the private key by signing a challenge”.

Two things follow from that. The private key never travels to the website, so a break-in at the site can’t leak it. Apple’s [passkey security page](https://support.apple.com/en-us/102195) puts it plainly: the public key “is not a secret”. And your face or fingerprint never leaves your device either. It only unlocks the key locally.

### Why a passkey can’t be phished

Each passkey is tied to the web address of the site that made it. Your browser or phone will only offer the passkey for google.com on google.com. A fake page at go0gle-login.com gets nothing, because your device has no passkey for that address. The software does the checking, so you don’t have to spot the fake.

This is the biggest gain over passwords. A careful person can still type a good password into a convincing fake page at 11 p.m. With a passkey, there’s nothing to type.

## Passkey vs password: what’s the difference?

A password is a secret you know and the site also keeps a copy of (hopefully scrambled). A passkey is a secret only your device knows, and the site keeps a public key that can’t be used to sign in.

|                                              | Password                              | Passkey                                         |
| -------------------------------------------- | ------------------------------------- | ----------------------------------------------- |
| What you do to sign in                       | Type or paste it                      | Face, fingerprint or PIN                        |
| What the site stores                         | A copy of your secret, usually hashed | A public key, useless to a thief                |
| Can it be reused on other sites?             | Yes, and people do                    | No, one per site                                |
| Can a fake site trick you into giving it up? | Yes                                   | No, it only works on the real address           |
| Can it be guessed?                           | If it's weak                          | No                                              |
| Works on any device, anywhere                | Yes                                   | Mostly, with a phone nearby or a synced manager |

Passwords still have one edge. You can type one on a borrowed computer with nothing else in hand. Passkeys need your phone nearby or your password manager signed in. That’s why most sites keep your password as a fallback after you add a passkey. So you still want good passwords for now. Our [password generator](https://relic.space/tools/password-generator) makes random ones in the browser.

## Passkey vs 2FA codes

Two-factor codes (a text message, or six digits from an authenticator app) sit on top of a password. They help a lot. But a code is still something you type, so a good fake page can ask for it and pass it on to the real site before it expires.

A passkey already covers both factors. You need the device that holds the key, and you need to unlock it with your face, fingerprint or PIN. Google says so on its [passkey help page](https://support.google.com/accounts/answer/13548313?hl=en): if your account has 2-Step Verification, “your passkey bypasses the second authentication step, since this verifies that you own the device.”

## Where are passkeys stored?

In whatever app your device uses to keep sign-ins. The standard calls these [passkey providers](https://passkeys.dev/docs/reference/terms/). As of September 2026 the common ones are:

* **iPhone, iPad and Mac:**the Passwords app, which syncs through iCloud Keychain. Apple says iCloud Keychain is end-to-end encrypted with keys Apple doesn’t know.
* **Android and Chrome:** Google Password Manager, synced through your Google Account.
* **Windows:** Windows Hello keeps passkeys on that one PC. Windows 11 can also hand passkeys to a manager you pick, under Settings, then Accounts, then Passkeys, then [Advanced options](https://support.microsoft.com/en-us/accounts-billing/security/manage-your-saved-passkeys). Microsoft Password Manager in Edge can sync them.
* **1Password and Bitwarden:** both save passkeys and work on Windows, Mac, iPhone and Android. 1Password lists its [browser extension and apps](https://support.1password.com/save-use-passkeys/). Bitwarden’s [mobile apps](https://bitwarden.com/help/storing-passkeys/) need iOS 17 or Android 14.
* **A hardware security key** such as a YubiKey. The passkey can’t leave the key at all.

That last one points to the two kinds of passkey. A **synced passkey**is copied to all your devices through your manager’s cloud. A **device-bound passkey**never leaves the one device or key it was made on. Synced is easier to live with. Device-bound is harder to steal, since no copy sits in anyone’s cloud.

If you mix platforms (an iPhone and a Windows PC, say), a cross-platform manager like 1Password or Bitwarden saves you a lot of hopping. Apple Passwords and Google Password Manager each work best inside their own world.

## How do I use a passkey on a computer that doesn’t have it?

Use your phone. On the computer’s sign-in page, pick the option to use a passkey from another device. A QR code appears. Scan it with your phone’s camera, then unlock the phone. On Google’s sign-in page the path is **Try another way**, then **Use your passkey**.

Both devices need Bluetooth on. The phone and computer use it only to prove they’re in the same room. That stops someone far away from sending you a QR code and borrowing your sign-in. Microsoft’s docs say both devices also need an internet connection, and the passkey itself isn’t copied to the computer. The FIDO documents call this cross-device sign-in, or “hybrid”. It works between brands, so an iPhone can sign you in on a Windows PC.

## What happens to my passkeys if I lose my phone?

It depends on where they were stored.

* **Synced passkeys** come back when you sign in to the same manager on a new device. Apple says passkeys can be recovered through iCloud Keychain even if you lose every device, as long as you can get back into your Apple Account.
* **Device-bound passkeys** are gone with the device. You sign in with your password or another backup method, then make a new passkey.

Either way, remove the lost phone’s passkeys from your accounts. A thief would still need to unlock the phone, but there’s no reason to leave them there. For a Google Account, [Google’s steps](https://support.google.com/accounts/answer/13548313?hl=en)are to sign in on another device and remove the passkey from Security & sign-in. And keep at least one backup way in on every important account, like a password in your manager or a recovery code.

## Can you move passkeys to another password manager?

Yes, since late 2025\. The FIDO Alliance wrote a pair of standards for it. One is the Credential Exchange Format, which sets out what the moved data looks like. It became a [FIDO Proposed Standard in August 2025](https://www.1password.community/blog/developer-blog/portability-without-compromise-1password-helps-author-a-new-standard-for-secure-/163208). The other, the Credential Exchange Protocol, covers how two apps hand the data over safely. The transfer stays encrypted the whole way, with no loose file of your sign-ins sitting in your Downloads folder.

As of September 2026, this is what works:

* **iPhone, iPad and Mac:**since iOS 26 and macOS 26, the Passwords app can export passwords and passkeys to another manager on the same device. Ricky Mondello, who works on Apple’s password features, [lists](https://rmondello.com/2026/09/07/switching-password-managers-2026/)Apple Passwords, 1Password, Bitwarden, Dashlane, DuckDuckGo and Devolutions as apps that support it. He notes 1Password and some others haven’t added it on the Mac yet.
* **Android:** Google Play services 26.21, released June 1, 2026, added [import and export](https://support.google.com/product-documentation/answer/14343500?hl=en) between Google Password Manager and other managers using this standard.
* **Windows:**Microsoft’s passkey help pages don’t describe a way to export passkeys saved in Windows Hello.

Transfers happen between two apps on one device. There’s no direct iPhone-to-Android button. The workaround is a cross-platform manager: move your passkeys from Apple Passwords into Bitwarden or 1Password on the iPhone, and they sync to your Android phone from there.

## How to delete a passkey

Deleting a passkey takes two steps, and people often do only one. The website has your public key. Your manager has the private key. Remove it from the site’s account settings so the site stops accepting it. Remove it from your manager so it stops popping up.

### How to remove a passkey from a Microsoft account

Go to account.live.com/proofs/manage and sign in. Find the entry with the passkey icon, select the arrow to open it, and choose **Remove**. For a work or school account, use mysignins.microsoft.com/security-info instead. [Microsoft warns](https://support.microsoft.com/en-us/accounts-billing/security/manage-your-saved-passkeys)that if you remove every way to prove it’s you, the account goes into a restricted state for 30 days. Add another method first.

### On Windows

Open Settings, then **Accounts**, then **Passkeys**. Select the three dots next to the passkey and choose **Delete passkey**. This only clears passkeys saved on that PC. Passkeys in another manager get deleted in that manager.

### On iPhone, iPad or Mac

Open the Passwords app and unlock it. Tap **Passkeys**, pick the account, then tap Edit and Delete. It’s removed from your other Apple devices on the same Apple Account too. Changed your mind? Apple’s [help page](https://support.apple.com/en-us/104955) points to the **Deleted** section of the Passwords app.

### In a Google Account

Open your Google Account, tap **Security & sign-in**, then **Passkeys and security keys**. Pick the passkey and tap **Remove**. Passkeys that an Android phone made on its own are removed by signing that phone out under **Manage all devices**.

If you still get asked to use a passkey you deleted, it’s probably saved in a second manager. Check 1Password, Bitwarden or your browser, and delete it there too.

## Should you switch to passkeys?

For your email, your Apple, Google or Microsoft account, and your bank if it offers one, yes. Those are the accounts a phishing page most wants, and passkeys stop that attack. Pick one manager that works on all your devices and keep your passkeys there. Then set up a backup way in on each account before you need it.

Passkeys also mean fewer passwords sitting on your clipboard. Every password you copy and paste passes through it, and our guide to whether it’s [safe to copy and paste passwords](https://relic.space/blog/is-it-safe-to-copy-and-paste-passwords) covers where that goes wrong. (Relic, our clipboard history app, skips copies a password manager marks as private on Windows and Mac.) For the passwords you still need to give to someone, read [how to send a password securely](https://relic.space/blog/how-to-send-a-password-securely). And if “end-to-end encrypted” on a passkey manager’s sales page sounds vague, our [end-to-end encryption explainer](https://relic.space/blog/what-is-end-to-end-encryption)says what it does and doesn’t cover.

## Sources

* [Passkeys](https://fidoalliance.org/passkeys/), FIDO Alliance
* [Terminology](https://passkeys.dev/docs/reference/terms/), passkeys.dev
* [About the security of passkeys](https://support.apple.com/en-us/102195), Apple Support
* [Find saved passwords and passkeys on your iPhone](https://support.apple.com/en-us/104955), Apple Support
* [Sign in with a passkey instead of a password](https://support.google.com/accounts/answer/13548313?hl=en), Google Account Help
* [Google system release notes (Play services v26.21)](https://support.google.com/product-documentation/answer/14343500?hl=en), Google (2026)
* [Manage your saved passkeys](https://support.microsoft.com/en-us/accounts-billing/security/manage-your-saved-passkeys), Microsoft Support
* [Support for passkeys in Windows](https://learn.microsoft.com/en-us/windows/security/identity-protection/passkeys/), Microsoft Learn (2026)
* [Storing passkeys](https://bitwarden.com/help/storing-passkeys/), Bitwarden Help
* [Save and sign in with passkeys in your browser](https://support.1password.com/save-use-passkeys/), 1Password Support
* [Portability without compromise: a new standard for secure credential transfer](https://www.1password.community/blog/developer-blog/portability-without-compromise-1password-helps-author-a-new-standard-for-secure-/163208), 1Password (2025)
* [Switching password managers in 2026](https://rmondello.com/2026/09/07/switching-password-managers-2026/), Ricky Mondello (2026)

## Frequently asked questions

Is a passkey safer than a password?+

Yes, for the attacks most people face. A passkey can't be reused on another site, guessed, or typed into a fake login page, and the website only keeps a public key that is useless to a thief. The weak spot moves to your device and your password manager account, so keep a screen lock on and protect the account that syncs your passkeys.

Do I still need my password after I make a passkey?+

Usually, yes. Most sites keep your password as a backup when you add a passkey. Google says adding a passkey doesn't remove any sign-in or recovery options already on your account. Keep the password in your password manager in case you ever sign in from a device where the passkey isn't available.

Can someone use my passkey if they steal my phone?+

Only if they can unlock the phone. Every passkey sign-in asks for the phone's face scan, fingerprint or PIN first. That is why a strong screen lock matters more once you use passkeys. If the phone is gone, sign in from another device and remove the passkeys that lived on it.

Can I share a passkey with someone?+

Not by copying it. Google's help page says passkeys can't be shared, copied or written down. Some managers let you share one another way. Apple Passwords, for example, can share passwords and passkeys with a group of people you trust, who then sign in on their own devices.

JG

Written by

[Jordan Gibbs](https://relic.space/authors/jordan-gibbs)Founder, Relic

Jordan Gibbs is the founder of Relic, an end-to-end encrypted, permanent, searchable memory for everything you copy. He writes widely about AI, agents, and practical tooling on Medium, where he is read by tens of thousands, and builds privacy-first software. Here he covers how everyday tools like the clipboard actually work, and how to use them without handing your data to someone else.

[Medium](https://medium.com/@jordan%5Fgibbs)[GitHub](https://github.com/jordan-gibbs)[LinkedIn](https://www.linkedin.com/in/jordan--gibbs/)

Part of

[Clipboard security & privacy](https://relic.space/blog/topics/clipboard-security)
* [Is your clipboard a security risk?· pillar](https://relic.space/blog/is-your-clipboard-a-security-risk)
* [Types of ciphers, from Caesar to AES](https://relic.space/blog/types-of-ciphers)
* [Which messaging apps are end-to-end encrypted in 2026](https://relic.space/blog/which-messaging-apps-are-end-to-end-encrypted)
* [Can websites read your clipboard?](https://relic.space/blog/can-websites-read-your-clipboard)
* [Is it safe to copy and paste passwords?](https://relic.space/blog/is-it-safe-to-copy-and-paste-passwords)
* [What is end-to-end encryption, in plain English](https://relic.space/blog/what-is-end-to-end-encryption)
* [How to keep your clipboard private](https://relic.space/blog/how-to-keep-your-clipboard-private)
* [What is personally identifiable information (PII)?](https://relic.space/blog/what-is-personally-identifiable-information)
* [What is AES encryption?](https://relic.space/blog/what-is-aes-encryption)
* [What is zero-knowledge encryption?](https://relic.space/blog/what-is-zero-knowledge-encryption)
* [How to send a password securely](https://relic.space/blog/how-to-send-a-password-securely)

Keep reading

[7 minIs it safe to copy and paste passwords?Pasting a password is convenient and your password manager relies on it. But the clipboard is shared memory with a short, leaky life. When copying a password is fine, and when it bites you.Read ](https://relic.space/blog/is-it-safe-to-copy-and-paste-passwords)[8 minHow to send a password securelySending a password by email or chat leaves it sitting in inboxes forever. Sharing one safely with a one-time link or a password manager, and what never to do.Read ](https://relic.space/blog/how-to-send-a-password-securely)[8 minWhat is end-to-end encryption, in plain EnglishEnd-to-end encryption gets thrown around in marketing, but the idea is simple: only you hold the key, so nobody in the middle can read your data. How it actually works, minus the jargon.Read ](https://relic.space/blog/what-is-end-to-end-encryption)

securitypasswordsprivacy
