openideurope.eu

Passkeys explained: how passwordless login works

Passkeys replace passwords with a key on your device. Learn how they work, where they are stored, what happens if you lose a phone and who supports them.

Login securityPublished

A passkey is a way to sign in without typing a password. When you create one, your device generates a pair of cryptographic keys: a private key that stays with you and a public key that the service stores. To log in, you confirm with your fingerprint, face or screen lock, and your device signs a one-time challenge from the website. The service checks the signature with the public key and lets you in.

The technology behind this is FIDO2 and WebAuthn, standardised by the FIDO Alliance and the W3C. If you want the technical layer, see our page on FIDO2 and WebAuthn. Here we stay with what passkeys mean in daily use.

How a passkey login works

  1. Creating the passkey. In the security settings of a service you choose “Create a passkey”. Your device creates a key pair and confirms with your biometrics or PIN.
  2. Storing it. The private key is saved in your device’s secure storage, your platform account (for example iCloud Keychain or Google Password Manager) or a password manager. The public key goes to the website.
  3. Signing in. The website sends a random challenge. Your device signs it, but only after you unlock it, and only if the website address matches the one the passkey was created for.
  4. Done. No password is typed, no code is copied, and nothing reusable crosses the network.

The last point is what makes passkeys different from two-factor authentication: you do not add a second step, you replace the weak first step. Unlocking the key with biometrics or a PIN is still “something you have plus something you are or know”, so one login already combines two factors.

Why passkeys are harder to attack

  • They resist phishing. A passkey is bound to the genuine domain. On a look-alike page, your browser simply finds no matching passkey. There is nothing for you to be tricked into typing. This is why passkeys count as phishing-resistant authentication.
  • They cannot be reused or guessed. Every service gets its own key pair, and a passkey is long and random by design.
  • A breach does not expose them. If a service is hacked, the attacker obtains public keys, which are useless for logging in.
  • Your biometrics stay local. Fingerprint or face data is processed on your device and is not sent to the service.

The German Federal Office for Information Security (BSI) says that when a trusted provider offers a passkey, you can use it to replace your password. For a deeper comparison, read passkeys vs passwords.

Where passkeys are stored

Storage How it works Good to know
Apple (iCloud Keychain, Passwords app) Synchronised across your Apple devices, end-to-end encrypted Needs two-factor authentication on the Apple Account
Google Password Manager Synchronised across Android devices and Chrome Can also be used on other platforms via QR code
Windows Hello Stored on that PC, protected by face, fingerprint or PIN Since late 2025 third-party managers can plug in
Password manager Synchronised across all platforms the manager supports Best option if you mix Apple, Android and Windows
Hardware security key Stored on the key itself, does not sync Needs a spare key as backup, see hardware security keys

A passkey that synchronises is called a synced passkey. One that never leaves a particular device or key is device-bound. Synced passkeys are more convenient and recover more easily. Device-bound ones keep the secret in exactly one place, which some organisations prefer.

What if you want to switch providers?

For a long time, passkeys were hard to move between ecosystems. The FIDO Alliance has since published the Credential Exchange Protocol (CXP) and the Credential Exchange Format (CXF), which let you move passkeys and passwords from one credential manager to another in encrypted form instead of via a plain CSV file. As of October 2026, the specification is published as a proposed standard, Apple has built import and export into iOS 26, and Google has added support on Android through Google Play services (version 26.21 and later, rolling out since mid-2026). Support varies by app, so check that both your old and new manager offer it before you migrate.

What happens if you lose your device?

With synced passkeys, you sign in to your iCloud, Google or password manager account on a new device and your passkeys return. That is why the account that holds your passkeys deserves the strongest protection you can give it. Passkeys on a hardware key are lost with the key, so register at least two keys. Many services also keep a fallback such as an email link or recovery codes. See account recovery before you need it.

Who supports passkeys today

Google, Microsoft, Apple, Amazon, PayPal and many banks, shops and social networks support passkeys. Microsoft has made new personal accounts passwordless by default since 2025. Coverage grows steadily but is not complete, so expect a mix of passkeys and passwords for some time. For a password manager this is convenient: it holds both and offers the right one.

Your next steps

  1. Pick one account that matters, such as your email or Apple, Google or Microsoft account.
  2. Create a passkey in its security settings. Our step-by-step guide to setting up passkeys covers iPhone, Android, Windows and Mac.
  3. Make sure your recovery path works (a second device, recovery codes or a second key).
  4. Repeat for other services as they offer it, and keep using strong, unique passwords plus two-factor authentication where passkeys are not available.

Passkeys are not a reason to panic about your old passwords. They are a calmer, simpler way to log in that happens to be safer too.

Frequently asked questions

Is a passkey the same as a password?

No. A password is a secret you know and send to the website. A passkey is a key pair: the private half never leaves your device or password manager, and the website only stores the public half. Nothing secret travels over the internet.

What happens if I lose my phone?

If your passkeys are synchronised (iCloud Keychain, Google Password Manager or a password manager), you sign in on your new device and they appear there. If a passkey is stored only on one device or a hardware key, you need a second passkey, a backup method or the service's account recovery.

Do passkeys send my fingerprint to the website?

No. Your fingerprint or face is only used locally to unlock the key on your device. The website never receives biometric data, only a signed confirmation.

Can I use passkeys on a computer that is not mine?

Yes, for most services. You can choose to use a passkey from your phone: the computer shows a QR code, your phone scans it, and the two devices check that they are close to each other over Bluetooth before you confirm.

Are passkeys supported everywhere yet?

Not everywhere. Large providers such as Google, Microsoft, Apple, Amazon and PayPal offer them, but many smaller sites still need a password. Keep a strong password and a second factor on those.

More in Login security