Security

Passkey

A sign-in method that replaces a password with a cryptographic key stored on your device and unlocked with a fingerprint, face or device PIN. It is resistant to phishing because the key only works on the genuine site.

How it works

A passkey signs in using a cryptographic credential associated with a particular service. The service verifies proof from the authenticator rather than receiving a reusable password. The user typically unlocks the credential locally with a device PIN or biometric action; that local action is different from sending a fingerprint to the website.

A practical example

A person can create a passkey for a supported account and later confirm sign-in on their phone or computer. A lookalike website cannot simply collect that credential as a typed password because authentication is bound to the intended service. Supported cross-device sign-in may also be available, depending on the system.

What to check

Check which account and credential provider are involved, whether the passkey is device-bound or synchronized, and how recovery works if a device is lost. Register through genuine account settings and confirm a usable recovery path before removing other methods. Keep the device and the provider account protected, especially where credentials synchronize.

Limits and safe use

Passkeys do not make a stolen unlocked session harmless or remove every weakness in account recovery. Support varies between services, devices and browsers. A misleading request to change recovery details still needs verification. Choosing a passkey is one part of account protection; access to its storage and recovery environment also matters.

Technical sources

← All glossary terms