Breaches & Passwords
Passkeys Explained for Normal People (2026 Guide)
The short version
A passkey is a login stored on your phone or computer and unlocked with your face, fingerprint, or PIN. There is nothing to remember, nothing to type, and nothing a fake website can steal, because the key only works on the real site. If your passkeys sync through Apple, Google, Microsoft, or a password manager, losing a phone is an inconvenience rather than a lockout. Most sites still keep a password as a fallback, so keep that password strong. Our verdict: turn passkeys on for email, banking, and anything holding your card, starting today.
What a passkey actually is
A passkey is a replacement for a password. Instead of a secret you memorize and type, it is a pair of cryptographic keys your device creates for one website. The private half stays on your phone or computer, guarded by your face, fingerprint, or PIN. The site only ever holds the public half, which cannot log anyone in by itself.
The FIDO Alliance, the industry group that wrote the standard, describes a passkey as a credential that lets you sign in "with the same steps that they use to unlock their device." That is the whole user experience. A site asks you to sign in, your phone asks for your face or fingerprint, and you are in.
The technology underneath is called FIDO2 and WebAuthn, and it was built jointly by Apple, Google, Microsoft, and others. Apple shipped passkeys in iOS 16 in September 2022. Google made them the default sign-in option for personal accounts in October 2023. In May 2025, Microsoft announced that brand new Microsoft accounts would be passwordless by default.
Why a passkey cannot be phished
The private key never leaves your device, and your browser will only use it on the exact website it was created for. A lookalike site at a misspelled address gets nothing, because there is no code to read out and no password to type. Phishing works by fooling you. A passkey takes you out of the decision entirely.
GitHub's documentation puts it plainly: passkeys "are bound to a website domain" and "the web browser will refuse to authenticate to a lookalike phishing website." Microsoft says the same thing from the other side, noting that the check is enforced by the browser or operating system "rather than relying on human verification."
That is the difference from a six-digit code. A phishing page can ask you for a code and relay it to the real site within seconds, which is why phishing still works against people with two-factor authentication. The US standards body NIST defines phishing resistance as protection that works "without relying on the vigilance of the claimant." Passkeys meet that definition. Codes do not.
A second benefit: because the website stores only your public key, a breach of that site leaks nothing replayable, so credential stuffing has nothing to work with.
The two flavors: synced and device-bound
There are two kinds of passkey, and the difference matters when things go wrong. A synced passkey is backed up to a cloud account and appears on all your devices. A device-bound passkey lives on one piece of hardware, typically a security key such as a YubiKey, and cannot be copied anywhere.
Which one you get depends on where you save it when the prompt appears. On an iPhone or Mac, passkeys go into iCloud Keychain, which Apple says is "end-to-end encrypted with strong cryptographic keys not known to Apple." On Android and in Chrome, they go into Google Password Manager, which Google says is "always end-to-end encrypted" and requires a screen lock. Since September 2024, Google has let you save passkeys there from Windows, macOS, Linux, and Android as well.
On Windows, Microsoft offers a choice: sync the passkey through Microsoft Password Manager or another synced manager, or store it locally on that one PC using Windows Hello. That local option is device-bound, and it behaves like a hardware key if the PC dies.
NIST's 2025 guidelines call synced passkeys "syncable authenticators" and accept them for ordinary consumer logins. For most people, synced is the right default.
What happens when you lose your phone
With a synced passkey, losing the phone is recoverable. You sign in to your Apple, Google, or Microsoft account on a new device, prove it is you, and the passkeys come back. With a device-bound passkey, the key is gone with the device. Microsoft's support page says it without hedging: "You lose the passkey unless you have another recovery method."
The recovery paths are specific, and it is worth knowing yours before you need it. For Apple, passkeys are recovered through iCloud Keychain escrow. You sign in with your Apple Account and password, respond to a text sent to your registered phone number, and enter the passcode of one of your devices. Apple allows only 10 attempts. After the tenth failure, its security documentation says the escrow record is destroyed and "the keychain is lost forever."
For Google, a new device needs either the screen lock of another device that already has your passkeys, or your Google Password Manager PIN. Google caps wrong guesses at 10 or fewer. If you cannot recover the PIN on any device, resetting it "deletes all your passkeys," and you will create new ones site by site.
Three lessons follow. Keep a second device signed in if you can. Keep your recovery phone number current and protect it, because a text to it is part of the Apple flow and a SIM swap hands your recovery path to someone else. And if a phone is stolen, remove its passkey from your account security settings using another device.
Hardware keys are the exception. Yubico states that passkeys on a YubiKey "are not copyable," and its own advice is to buy a spare and register it with every account at the same time as the first.
Signing in on a computer that does not have your passkey
You do not need the passkey on every device. When a laptop asks for a passkey it does not hold, it shows a QR code. You scan it with the phone that holds the passkey, unlock with your face or fingerprint, and the laptop signs you in. Both devices need Bluetooth on so the phone can prove it is nearby.
Microsoft's documentation explains that the Bluetooth check lets your phone "authorize another device securely over Bluetooth without transferring or copying the passkey itself." The passkey stays on the phone. This is what makes a shared work computer, a library terminal, or a friend's laptop usable without weakening anything.
What the numbers say about passwords versus passkeys
Passwords are the weak point attackers count on. In May 2025 Microsoft reported observing 7,000 password attacks per second, more than double the 2023 rate. The same post said passkey sign-ins succeed about 98 percent of the time, against 32 percent for passwords. Adoption has followed: the FIDO Alliance's 2026 survey found three quarters of people have enabled a passkey somewhere.
| Consumers in 2026 | Share |
|---|---|
| Aware of passkeys | 90% |
| Have enabled a passkey on at least one account | 75% |
| Use passkeys regularly when available | 49% |
| Passkeys in use worldwide (FIDO estimate) | 5 billion |
Source: FIDO Alliance, "The State of Passkeys 2026," May 7, 2026. Consumer figures from a Sapio Research survey of 11,000 consumers across ten countries in April 2026.
The breach data is moving too. Verizon's 2026 Data Breach Investigations Report, published May 19, 2026, found that exploiting software vulnerabilities was the top way into organizations at 31 percent of breaches, the first time in the report's 19 years that anything beat stolen credentials. Credential abuse fell to 13 percent and phishing sat at 16 percent. That is still more than one breach in four starting with a human handing over a login, which is exactly what passkeys are designed to end.
Where you can use one today
Most large consumer accounts already offer passkeys, including Google, Microsoft, Amazon, eBay, GitHub, Nintendo, and Target. You add one from the account's sign-in or security settings, and it takes under a minute. Amazon's announcement was candid about the transition, noting that passwords "will still be around in the foreseeable future."
- Google - the default option; over 400 million accounts were using passkeys by May 2024.
- Microsoft - new accounts are passwordless by default; in May 2025 Microsoft said it saw nearly a million passkeys registered every day.
- Amazon - Your Account, then Login & Security, then Passkeys. Works on the web and in the Amazon and Audible apps.
- eBay - under Sign in and security; sign in with "a fingerprint, pattern, or PIN" and skip the password.
- GitHub - a passkey satisfies both the password and the two-factor step at once.
- Nintendo and Target - both offer passkeys in account security settings; Nintendo notes your biometric data never leaves the device.
For everything else, 1Password maintains a community index at passkeys.directory that lists which sites and apps accept passkey sign-in.
Password managers can hold passkeys too
If you already use a password manager, you can store passkeys there instead of in Apple's or Google's system, and they will sync across every platform you use. 1Password, Bitwarden, Dashlane, and Proton Pass all save and use passkeys. That keeps your logins in one place and avoids tying your accounts to one phone brand.
This is also where the lock-in question lives. Until recently, a passkey saved to iCloud Keychain stayed in Apple's world. At its June 2025 developer conference, Apple announced that passkeys "can now be transferred securely between participating credential manager apps" on its 2025 operating systems, using a format built with the FIDO Alliance. Bitwarden supports that transfer on iOS 26 and Android 14 and later. 1Password can export passkeys on iOS and Android, but its desktop apps cannot yet.
The honest summary for 2026: moving passkeys between ecosystems works on phones, is patchy on desktop, and the standard behind it is still being finalized. Pick a home for your passkeys and stay there. If you have not chosen a manager yet, our password manager and 2FA guide explains how to choose one.
The honest limitations
Passkeys fix the password, not the whole account. Nearly every site keeps a password or recovery code as a fallback, so an attacker who cannot phish your passkey can still phish your password. Account recovery becomes the weak link, and setup screens are still confusing. The UK's National Cyber Security Centre held back its recommendation for a year for these reasons.
In January 2025 the NCSC wrote that it was not ready to recommend passkeys for "mass adoption across all services yet," pointing to the several "flavours" of passkey, the confusion of different vendors using different words, and the need for people to know what to do "in the event of losing one - or all - of their devices." In April 2026 it reversed course, saying passkeys "should now be consumers' first choice of login across all digital services" because the industry had fixed enough of the rough edges.
Attackers have adapted rather than given up. In August 2026, The Register reported on a phishing kit that, after tricking someone out of a fallback password, registers the attacker's own passkey on the victim's account for lasting access. The lesson is not that passkeys failed. It is that the fallback password and the recovery flow are now the target, so check the passkey list on your accounts occasionally.
Is it worth switching yet?
Yes, for anything that matters. Turn on passkeys for your email first, then banking, payment apps, shopping accounts with a saved card, and the Apple, Google, or Microsoft account that holds your passkeys. Keep the strong fallback password in your manager, keep two-factor authentication on, and learn your recovery route before you need it.
- Start with email. It resets everything else. If it is a Google or Microsoft account, the passkey option is already in security settings.
- Decide where passkeys live - iCloud Keychain, Google Password Manager, or your password manager. Use one home, not three.
- Add a second device or a PIN so a lost phone is recoverable. Apple users: know your device passcode. Google users: set the Password Manager PIN.
- Do not delete the password. Most sites will not let you anyway. Make it long and unique, and store it in the manager.
- Move 2FA off SMS where the site allows an authenticator app or a security key.
- Review your passkey list twice a year and remove any device you no longer own.
Email comes first because it receives the recovery emails for every other account. Our guide to recovering a hacked email account shows what you are trying to avoid.
Check what a passkey would be protecting
A passkey stops the next stolen password from working. It does nothing about the passwords, phone numbers, and addresses that already leaked in past breaches and now sit in attacker databases feeding the fallback attacks above. Knowing which of your accounts are already exposed tells you where to add passkeys first.
RedactZero's free exposure scan checks your email against known breaches and shows what leaked with it, so you can prioritize. Nothing you scan is stored. For the rest of the series, see our breaches and passwords hub and the opt-out guides for removing the personal details that make recovery-flow scams convincing.
See which accounts already leaked
Run a free scan to check your email against known breaches and see what data classes were exposed - no account, nothing stored.
Frequently asked questions
What is a passkey in simple terms?
A passkey is a login that lives on your phone or computer instead of in your head. You approve each sign-in with your face, fingerprint, or device PIN. There is nothing to remember or type, and the website never receives a secret that could be stolen and reused.
Do I still need a password if I have a passkey?
Usually, yes. Almost every site that offers passkeys still keeps your password as a fallback, and Amazon says plainly that passwords will be around for the foreseeable future. Keep that fallback password long, unique, and stored in a password manager, and keep two-factor authentication switched on.
What happens to my passkeys if I lose my phone?
If the passkeys were synced through iCloud Keychain, Google Password Manager, Microsoft Password Manager, or a password manager, you sign in to that account on a new device, prove it is you, and they come back. A passkey stored only on one device, such as a hardware security key, is lost with it, so keep a backup key or a second sign-in method.
Can a passkey be phished or stolen in a data breach?
Not in the way a password can. The private key never leaves your device, and your browser will only use it on the exact website it was created for, so a lookalike site gets nothing. A breach of the website exposes only the public half, which cannot be used to log in as you.
Can I use a passkey on a computer that does not have it?
Yes. The computer shows a QR code, you scan it with the phone that holds the passkey, and you approve the sign-in with your face, fingerprint, or PIN. Both devices need Bluetooth on so the phone can prove it is physically nearby. The passkey itself is never copied to the computer.
Are passkeys safe to store in a password manager?
Yes. 1Password, Bitwarden, Dashlane, and Proton Pass all store and sync passkeys, and doing so keeps your logins in one place across Apple, Google, and Windows devices. The trade-off is that your manager's master password and its own recovery process become the thing to protect most carefully.
Can I move my passkeys from Apple to Google or to 1Password?
Only partly, as of 2026. Apple added secure passkey transfer between credential manager apps in its 2025 operating systems, and Bitwarden and 1Password can export passkeys on iOS and Android, but not yet on desktop. The industry standard for moving passkeys is still being finalized, so pick a home for your passkeys and stay there for now.
Should I still use two-factor authentication with passkeys?
Yes. A passkey protects the sign-in it is used for, but the password fallback and the account recovery process still exist, and those are what attackers now target. Keep an authenticator app or security key on your important accounts and avoid SMS codes where you can, because your phone number is a recovery link too.
Sources: FIDO Alliance Passkey Central and passkeys.dev reference pages (February 2026); FIDO Alliance, "The State of Passkeys 2026," May 7, 2026; Apple Support, "About the security of passkeys" (September 2024) and Apple Platform Security, "Escrow security for iCloud Keychain" (May 2024); Apple Newsroom, 2022; Apple WWDC25, "What's new in passkeys," June 2025; Google Security Blog, October 12, 2022; Google blog posts of October 10, 2023, May 2, 2024, and September 19, 2024; Google Account and Chrome Help pages; Microsoft Learn, "Support for passkeys in Windows," May 2026; Microsoft Support passkey pages; Microsoft Security Blog, May 1, 2025; Verizon 2026 Data Breach Investigations Report, May 19, 2026; NIST SP 800-63B-4, July 2025; UK NCSC, January 15, 2025 and April 23, 2026; The Register, August 21, 2026; Yubico passkey FAQ and blog; GitHub Docs; About Amazon; eBay, Nintendo, and Target help pages; 1Password, Bitwarden, Dashlane, and Proton Pass support pages.