How it works
A passkey signs in using a cryptographic credential associated with a particular service. The service verifies proof from the authenticator rather than receiving a reusable password. The user typically unlocks the credential locally with a device PIN or biometric action; that local action is different from sending a fingerprint to the website.
A practical example
A person can create a passkey for a supported account and later confirm sign-in on their phone or computer. A lookalike website cannot simply collect that credential as a typed password because authentication is bound to the intended service. Supported cross-device sign-in may also be available, depending on the system.
What to check
Check which account and credential provider are involved, whether the passkey is device-bound or synchronized, and how recovery works if a device is lost. Register through genuine account settings and confirm a usable recovery path before removing other methods. Keep the device and the provider account protected, especially where credentials synchronize.
Limits and safe use
Passkeys do not make a stolen unlocked session harmless or remove every weakness in account recovery. Support varies between services, devices and browsers. A misleading request to change recovery details still needs verification. Choosing a passkey is one part of account protection; access to its storage and recovery environment also matters.