Plain-language summary
A passkey uses public-key cryptography so a website can verify that your device holds the right private key without receiving a reusable password. The passkey is tied to the legitimate website, which helps resist common credential-phishing attacks.
What happens during sign-in
The service stores a public key. Your device keeps the corresponding private key and uses it only after you approve the sign-in with a device PIN, fingerprint, face check or another local unlock method. The biometric data normally stays on the device and activates the credential rather than being sent to the website.
Why passkeys can resist phishing
A passkey is bound to the website or application identity. A convincing fake page on a different domain cannot normally ask the authenticator to produce a valid response for the real service. NIST describes WebAuthn-based cryptographic authentication as a phishing-resistant approach.
Synchronized and device-bound passkeys
Some passkeys synchronize through a platform account so they can be used across the user’s devices. Others remain on a specific hardware key or device. Synchronization improves convenience and recovery, while device-bound credentials can suit higher-assurance needs.
Passkeys do not eliminate recovery risk
Losing every trusted device or losing access to the platform account can still create a recovery problem. Keep recovery contacts, backup authenticators and account recovery options current. Treat the account that synchronizes passkeys—often an email or platform account—as especially important.
Practical takeaway
Use passkeys where they are offered, especially for important accounts, but keep a second recovery route and protect the devices or platform account that store them.
Further reading
See NIST’s current Digital Identity Guidelines for authentication and phishing-resistance concepts.
Using passkeys across devices
A service may let you approve sign-in on a nearby phone, synchronize a passkey through a platform account or register more than one authenticator. The exact experience varies by provider and operating system. Before deleting an old device, confirm that another device can sign in and that recovery options remain available.
When a password still exists
Some services add a passkey while retaining the old password and recovery routes. The account is only as strong as every remaining sign-in path. Keep the password unique, review weaker fallback methods and remove obsolete authenticators where the service allows it.
Passkeys and shared devices
Be cautious when creating a passkey on a device controlled by someone else or shared among several people. The device’s local account, screen lock and synchronization settings affect who can use or remove the credential. Use a personal profile and sign out after temporary cross-device authentication.
How to introduce passkeys safely
Start with one important account, register a second trusted authenticator if supported and test sign-in from another device before removing older methods. Review the account’s list of passkeys periodically and delete entries for devices or security keys you no longer control.