Get Your Free Guide to Understanding Passkeys
What Are Passkeys and How They Work Passkeys represent a newer way to prove your identity online without relying on traditional passwords. Unlike passwords,...
What Are Passkeys and How They Work
Passkeys represent a newer way to prove your identity online without relying on traditional passwords. Unlike passwords, which are character strings you must remember and type in, passkeys use a combination of something you have (like your phone or computer) and something you are (like your fingerprint or face). This technology is based on cryptography, which is a way of encoding information so only authorized people can read it.
When you create a passkey for an account, your device generates two connected keys: a private key that stays on your device and a public key that the website or service stores. When you later want to sign in, your device uses your private key to prove you are who you say you are. The website checks your private key against the public key it has on file. If they match, you are granted access. This happens automatically without you having to type anything, and it happens so quickly you may not even notice the process.
The major difference from passwords is that passkeys are not transmitted over the internet. Your private key never leaves your device. This means hackers cannot intercept it the way they might intercept a password typed into a website. Even if someone steals a website's database of public keys, those keys alone cannot be used to sign in to your account. A hacker would need access to your actual device and would need to unlock it using your fingerprint or face, which is much harder to obtain.
Major technology companies began rolling out passkey support around 2022 and 2023. As of 2024, passkeys are supported by major platforms including Google, Apple, Microsoft, and many banks and financial services. Industry experts predict that passkeys will eventually replace passwords as the standard way to sign in online, though this transition will likely take several years.
Practical Takeaway: Understand that passkeys work by storing a key on your device and using biometric verification, rather than relying on you remembering and typing a password. This method is more secure because your private key never leaves your device.
Key Differences Between Passkeys and Passwords
Passkeys and passwords operate on fundamentally different principles, and recognizing these differences helps you understand why security experts recommend making the switch. A password is something you create and remember. You type it in each time you need to sign in. Because passwords exist in your memory and are transmitted to websites, they face several vulnerabilities. People tend to reuse passwords across multiple sites, write them down, or choose passwords that are easy to guess. Passwords can be intercepted during transmission if the connection is not secure. Websites store passwords in their systems, and if that system is breached, your password may be stolen.
Passkeys, by contrast, are generated by your device using complex mathematical algorithms. You do not create them or memorize them. Your device manages them automatically. When you need to sign in, you simply authenticate using your fingerprint, face recognition, or a PIN that unlocks your device. Your passkey itself never leaves your device and is never transmitted to the website. This means the risks associated with password reuse, weak passwords, forgotten passwords, and password interception simply do not apply.
In practical terms, signing in with a passkey is faster and simpler than signing in with a password. With a password, you must find and open your password manager, find the correct entry, copy the password, navigate to the website, paste it, and wait for verification. With a passkey, you navigate to the website, your device recognizes that it has a passkey for that site, and you authenticate with your fingerprint or face. The entire process takes seconds. No typing is required.
From a security perspective, passkeys are resistant to several common attack methods. They cannot be phished, because the website never asks you for your passkey. They cannot be brute-forced, because there are no passwords to guess. They are resistant to credential stuffing, which is when hackers use passwords stolen from one website to try to access accounts on other websites. Because each passkey is unique to each device and each website, a compromised passkey on one site does not put your accounts on other sites at risk.
Practical Takeaway: Recognize that passkeys are managed by your device and authenticated with biometrics, whereas passwords require you to remember and type them. This makes passkeys both more convenient and more secure than traditional passwords.
How to Create and Store Your Passkeys
Creating a passkey is a straightforward process that begins when you visit a website or app that supports them. Most services that offer passkeys will show you an option during the account creation or password change process. This option might be labeled "Create a passkey," "Use passkey," or "Passwordless sign-in." When you select this option, your device will guide you through the process of creating the passkey. You will be asked to verify your identity using your device's built-in authentication method, such as your fingerprint, face recognition, or a PIN.
Different devices store passkeys in different ways. On iPhones and iPads, passkeys are stored in iCloud Keychain, which is Apple's secure storage system. These passkeys sync across all your Apple devices if you have iCloud enabled. On Android devices, passkeys are stored in Google Password Manager or in your device's secure enclave. On Windows computers, passkeys can be stored locally or synced through your Microsoft account. On Mac computers, passkeys sync through iCloud Keychain. The important thing to know is that your device manufacturer provides secure storage, and you do not need to do anything special to store your passkeys once they are created.
If you use multiple devices, your passkeys will be available across those devices if they are from the same manufacturer and connected to the same account. For example, if you create a passkey on your iPhone and your iPad is also connected to your iCloud account, that same passkey will be available on your iPad. This syncing happens automatically. However, if you use both Apple and Android devices, your passkeys created on the iPhone will not automatically sync to your Android phone. In this situation, you may want to use your device's password manager or a third-party password manager that supports passkeys.
Some people worry about what happens if they lose their device or forget their PIN. If you lose a device that has your passkeys, you should change your account passwords or passkeys on that website as soon as possible using another device. Most websites that support passkeys also allow you to sign in using a backup method, such as a recovery code or your email address. This is why it is important to keep your account recovery email up to date. If you set up a recovery option when creating your account, you can regain access even if you no longer have your passkey.
Practical Takeaway: Create a passkey by selecting the passkey option during account creation or password change, then verify your identity with your device's biometric method. Your device automatically stores and syncs your passkeys across your devices from the same manufacturer.
Security Benefits and What Makes Passkeys Safer
Passkeys provide multiple layers of security that work together to protect your accounts. The first layer is encryption. Your passkey uses public-key cryptography, which is the same technology that protects sensitive communications for governments and financial institutions. This means that even if someone gains access to the website's database, they cannot use the public key information they find there to sign in to your account. They would need the corresponding private key, which is stored only on your device.
The second layer is biometric authentication. In order to use your passkey to sign in, someone would need to have your device and would need to be able to unlock it with your fingerprint or face. This is substantially harder than stealing a password, which can be captured through phishing, keylogging, or credential stuffing. Biometric data is difficult to fake and is stored securely on your device in a way that prevents apps from accessing it directly. Your fingerprint or face scan never leaves your device.
The third layer is device-specific binding. Each passkey is tied to the specific device where it was created. If a hacker somehow obtains a passkey file from your device, they cannot use it on another device because the website will recognize that it is being used from an unexpected device or location. The website can then require additional verification before granting access. This is fundamentally different from passwords, which work the same way from any device and any location.
Research on passkey security has been conducted by multiple independent organizations. In 2023, a study by the Microsoft Security Research team found that passkeys were resistant to all tested attack methods, including phishing, credential stuffing, and man-in-the-middle attacks
Related Guides
More guides on the way
Browse our full collection of free guides on topics that matter.
Browse All Guides โ