Passwords have been the weakest link in online security for decades. People reuse them, forget them and type them into fake websites. Passkeys are the replacement backed by Apple, Google, Microsoft and the FIDO Alliance — and they’re already supported by many of the services you use every day.
What is a passkey?
A passkey is a digital key stored on your device (phone, laptop or security key). Instead of typing a password, you unlock it the same way you unlock your phone: fingerprint, face scan or device PIN.
Behind the scenes, it uses public-key cryptography:
- When you create a passkey, your device generates a pair of keys
- The public key is sent to the website — it’s not secret, and it’s useless to attackers on its own
- The private key never leaves your device
When you sign in, the website sends a challenge, your device signs it with the private key, and the site verifies the signature with the public key. No shared secret ever travels across the internet.
Why passkeys are safer
| Threat | Passwords | Passkeys |
|---|---|---|
| Phishing sites | Easily typed into a fake page | Bound to the real domain — won’t work on a fake one |
| Data breaches | Stolen password hashes can be cracked | Sites only store public keys — nothing useful to steal |
| Reuse across sites | Very common | Impossible — every passkey is unique |
| Weak choices like “123456” | Common | Not possible |
That first row is the big one. A passkey created for yourbank.com simply will not respond to yourbank-login.com, no matter how convincing the fake page looks.
Where can I use passkeys?
Many major services now support them, including Google, Microsoft, Apple, GitHub, PayPal, Amazon and WhatsApp. Look for options such as “Passkeys”, “Sign in with a passkey” or “Security keys” in your account’s security settings.
How to set one up
- Sign in to the service with your existing password
- Go to Security settings → Passkeys
- Click Create a passkey
- Confirm with your fingerprint, face or device PIN
That’s it. Next time you sign in, choose the passkey option and verify with your biometrics.
Your fingerprint or face data never leaves your device. It only unlocks the passkey locally — the website never sees it.
“What if I lose my phone?”
This is the most common worry, and it’s well handled:
- Synced passkeys — Apple (iCloud Keychain), Google (Password Manager) and password managers like 1Password and Bitwarden sync passkeys, end-to-end encrypted, across your devices. Get a new phone, sign in to your account, and your passkeys come back.
- Multiple passkeys — you can register more than one passkey per account (phone + laptop + hardware key)
- Recovery options — keep your account’s backup methods (recovery codes, backup email) up to date
Before removing your password entirely, make sure you have at least two ways to sign in. Save recovery codes somewhere safe and offline.
Signing in on someone else’s computer
You can still use your passkey: choose “use a phone or tablet”, scan the QR code with your phone and approve the sign-in. Bluetooth is used to check that your phone is physically nearby, which blocks remote attackers.
Should you switch?
For your most important accounts — email, banking, cloud storage and social media — yes. Passkeys are faster than passwords, impossible to forget and immune to the phishing attacks behind most account takeovers.
Start with your primary email account, since it’s the key to resetting everything else. Your future self will be glad you did.
I switched my Google and GitHub accounts to passkeys after reading this. So much easier than typing passwords.
The ‘what if I lose my phone’ section answered exactly what I was worried about.