Passwords have a long list of problems: people reuse them, forget them, and hand them over to convincing phishing pages. Passkeys are an industry-backed alternative designed to remove the password from the sign-in process entirely.
What is a passkey?
A passkey is a pair of cryptographic keys. One key stays private on your device (or in your password manager); the other is stored by the website. When you sign in, your device proves it holds the private key — usually after you unlock it with a fingerprint, face scan or PIN. Nothing reusable is typed or sent.
Why passkeys are more secure
- Phishing-resistant: a passkey only works on the genuine website it was created for.
- Nothing to steal from a data breach: the website stores only a public key.
- No reuse: every site gets its own unique passkey automatically.
How to start using passkeys
- Update your phone and computer to recent operating system versions.
- Open the security settings of an account that supports passkeys (many large services now do).
- Choose “Create a passkey” and confirm with your device unlock method.
- Keep at least one backup sign-in method, such as a recovery code, stored safely.
Good to know
Passkeys can sync between your devices through your platform account or password manager, so losing one phone does not have to mean losing access.
Should you switch today?
For important accounts that already support them — email, cloud storage, shopping — passkeys are worth enabling. Keep your password manager for everything else; the transition will take years, and both will coexist for a while.