Independent, practical guides for a better digital life.
Tech Tutorials

How to Use Passkeys Instead of Passwords: Beginner Guide

Learn how to create, store, sync, recover, and safely use passkeys across Android, iPhone, Windows, shared devices, and supported accounts.

Realistic paper-craft illustration for How to Use Passkeys Instead of Passwords: Beginner Guide

Passwords ask you to remember or store a secret that can be typed into a sign-in form. Passkeys work differently. A passkey is a cryptographic credential held by your phone, computer, password manager, or physical security key. You approve its use with the same face, fingerprint, PIN, or pattern that unlocks the device.

For most people, that means less typing and fewer opportunities to enter a credential on a fake website. It does not mean that every account becomes impossible to lose or steal. Your device lock, credential manager, recovery email, phone number, and the service's own recovery process still matter.

The safest way to begin is not to replace every password in one afternoon. Start with one account, understand where the passkey is saved, confirm that you have a recovery route, and test sign-in on another device. Once that workflow makes sense, you can move other supported accounts gradually.

What a Passkey Actually Replaces

When you create a passkey, your device creates a pair of cryptographic keys. The service receives the public key. The private key remains under the control of your device or passkey provider. During sign-in, the service sends a challenge and your device uses the private key to approve it after you unlock the credential.

There is no reusable password for you to type or for the service to store in the traditional way. A passkey is also associated with the real website or app for which it was created. That design makes passkeys resistant to common phishing pages because a lookalike domain cannot normally request the credential created for the genuine domain.

The FIDO Alliance passkey overview distinguishes two common forms:

  • A synced passkey is stored by a credential manager and made available on other approved devices using the same provider account.
  • A device-bound passkey stays on a particular phone, computer, app, or physical security key and is not automatically copied elsewhere.

Neither form is automatically right for everyone. Synced passkeys are convenient and can provide redundancy after one device is lost. Device-bound passkeys can suit people or organisations that need tighter control over where a credential exists. The practical question is where you want the key stored and how you will regain access if that place becomes unavailable.

Check the Basics Before Creating One

A passkey depends on the security of the device that unlocks it. Before setup, update the operating system and browser, then confirm that the device has a strong screen lock. Do not use an easily guessed PIN such as a birthday or repeated digits. Remove fingerprints or face profiles belonging to anyone who should not be able to approve your account sign-ins.

Protect the platform account behind your credential manager. For example, passkeys saved to Google Password Manager depend on access to your Google Account and its recovery options. Passkeys in iCloud Keychain depend on your Apple Account, approved devices, and recovery configuration. A passkey saved locally with Windows Hello depends on that Windows device unless another copy or sign-in method exists.

Review your recovery email and trusted phone number before removing any older sign-in method. If either belongs to a previous employer, old phone number, or inaccessible inbox, fix it first. A secure credential is not useful if the recovery path leads somewhere you no longer control.

It also helps to separate work and personal accounts. Saving a personal passkey inside an employer-managed browser profile can create problems when you leave the organisation or the administrator resets the device.

Choose Where the Passkey Will Be Saved

The creation prompt may offer more than one destination. Read it rather than selecting the first button automatically.

Google Password Manager

Google says passkeys saved in Google Password Manager can be backed up and made available across eligible devices signed in to the same Google Account. Its current Chrome passkey management guide explains that a Google Password Manager PIN or an Android screen-lock credential can be used to unlock saved passkeys.

This can be convenient if you use Android and Chrome on several devices. Check that you are signed in to the correct Google Account, especially if the browser contains personal and work profiles. Do not save a personal credential into a shared profile simply because it is already open.

Apple Passwords and iCloud Keychain

Apple stores passkeys in the Passwords app and can sync them through iCloud Keychain to approved Apple devices. Apple requires two-factor authentication for the Apple Account when using this passkey system. Its passkey security documentation also describes protected iCloud Keychain recovery if the user's devices are unavailable.

Before relying on that recovery, confirm that your trusted number, device passcode, and Apple Account recovery choices are current. Apple also supports an account recovery contact, which can help in certain lockout situations without giving that person direct access to your account.

Windows Hello and Microsoft Password Manager

Windows can store a passkey locally using Windows Hello. A local credential may not follow you to another computer. Google's current Chrome documentation specifically warns that a passkey saved only in Windows Hello cannot be recovered through Google Password Manager if the computer is lost or Windows is reinstalled.

Microsoft also supports synced credential managers and device-bound choices. Its create and save a passkey guide lists password managers, phones, physical security keys, and Windows Hello as possible destinations, depending on the account and device.

Physical security keys

A compatible FIDO security key can hold device-bound passkeys. This may be useful as a separate credential or recovery option, particularly for important accounts. Keep it somewhere secure and do not attach the only key permanently to a laptop bag that could be lost with the computer.

Support, storage capacity, backup behaviour, and PIN requirements differ among security keys. Check the manufacturer's official documentation and the account's supported sign-in methods before buying one.

Create Your First Passkey

Choose a service you already use and can recover easily. Sign in through its official app or type the known website address yourself. Do not begin from an unexpected email, advertisement, or message link.

The labels vary, but the process usually follows this pattern:

  1. Open the account's Security, Sign-in, or Authentication settings.
  2. Find an option such as Create a passkey, Add a passkey, or Passwordless sign-in.
  3. Read the account name and website shown in the prompt.
  4. Choose where the passkey should be saved if more than one provider is offered.
  5. Approve creation with the device's face, fingerprint, PIN, or pattern.
  6. Give the passkey a recognisable name if the service supports labels.
  7. Sign out and test the new sign-in method before changing anything else.

Not every website or app supports passkeys, and supported flows are not identical. Google's Chrome passkey guide notes that the option may appear during sign-in or inside account settings. If there is no passkey option, continue using a unique password and strong multi-factor authentication rather than forcing a workaround.

Some services allow a passkey and password to coexist. Others let you prefer passkeys while retaining recovery methods. Do not delete the password merely because a browser displayed a passkey prompt. First check the service's account settings and confirm what would happen on a new or unsupported device.

Test Sign-In on the Same Device

After creation, sign out of the service and return to its official sign-in page. Choose the passkey option, select the correct account, and approve the request with the device lock. The website should not ask you to reveal the device PIN to the site itself. The PIN or biometric prompt belongs to the operating system or credential provider.

If several accounts are listed, verify the email address before approving. A successful face or fingerprint scan only confirms that the person using the device is authorised to unlock the stored credential. It does not correct a wrong account selection.

Once the test succeeds, open the service's security activity page if available. Confirm that the sign-in came from your device and location. This creates a useful baseline for recognising unfamiliar activity later.

Use a Passkey on Another Device

If the passkey is synced, it may appear automatically after you sign in to the same credential provider on another approved device. Availability can depend on the operating system, browser, account, and provider settings.

You can also use a nearby phone to approve a sign-in on a computer that does not hold the passkey. The computer may display a QR code. Scan it using the phone that contains the passkey, then follow the phone's prompt. Bluetooth is commonly used to confirm that the devices are physically near each other, while the sign-in remains protected by the passkey protocol.

Only scan a cross-device sign-in QR code when you personally opened the genuine service and requested that option. A QR code sent in a chat or displayed by a caller can lead to an action you did not intend. The safety comes from initiating the correct flow, not from QR codes in general.

Apple's cross-device passkey instructions describe using an iPhone passkey on another device without saving the passkey to that other machine. Microsoft's passkey troubleshooting guidance notes that both devices may need Bluetooth enabled, physical proximity, internet access, and current software.

Be Careful on Shared and Public Computers

On a public library computer, hotel business centre, borrowed laptop, or shared family PC, prefer using a passkey from your nearby phone. Choose wording such as Use another device or Passkey from a nearby device rather than saving a new credential locally.

Do not add your personal fingerprint, face, PIN, browser profile, or credential-manager account to a public computer. After signing out of the website, close the browser window. If you downloaded any personal document during the session, remove it through the computer's normal process, but assume a public machine may retain activity beyond your control.

A home computer shared with family needs similar thought. Separate operating-system accounts are safer than sharing one unlocked profile. Anyone who knows the device PIN, or whose biometric profile is enrolled, may be able to approve credentials stored in that profile.

Build a Recovery Plan Before Removing Passwords

Passkeys reduce password problems, but account recovery can still become the weakest route. A service may fall back to email, SMS, support questions, identity checks, a password, or another passkey. A scammer will often target the easiest remaining path.

For each important account, record the following in a safe place:

  • Which credential manager or device holds the passkey.
  • Whether the passkey syncs or stays on one device.
  • Which email address and phone number receive recovery messages.
  • Whether a second passkey or security key is registered.
  • Where recovery codes are stored, if the service provides them.
  • How to remove a lost device from the account.

Do not store this list in an unlocked note on the same phone that contains every passkey. A secure password manager, protected offline record, or another method appropriate to your risk is better.

For high-value accounts, consider registering a second passkey through a different trusted device or a compatible security key if the service allows it. Test it before treating it as a backup. A spare that was never verified can fail when you need it most.

What to Do When a Device Is Lost

Use another trusted device to sign in to the platform account and the affected service. Mark the phone or computer as lost, lock or erase it through the platform's official device-finding tools where appropriate, and remove passkeys that were stored only on that device if the account lets you do so.

Google's account passkey help provides steps for removing a passkey associated with a lost or stolen device. Synced passkeys may still be available through an approved replacement device after you recover the credential-manager account. A device-bound passkey will not reappear unless another copy or recovery method exists.

Review recent sign-in activity after recovery. Losing a locked phone does not automatically mean the passkeys were used, but you should still revoke the device and look for unexpected sessions. If the device was unlocked when lost, act more urgently.

If you suspect account access rather than simple device loss, follow the checks in how to check if your phone is hacked. Update recovery details only through official account pages, not through links in messages claiming to help recover the device.

Understand the Limits of Phishing Resistance

Passkeys are designed so that the credential for a genuine domain is not presented to a lookalike domain. This is a major improvement over a password that a user can type anywhere. Still, passkeys do not make every online decision safe.

A fake support agent might persuade you to approve an unrelated action, change a recovery email, share your screen, or install remote-access software. An attacker may target the service's recovery process instead of the passkey. Malware or an unlocked device can create other risks outside the normal passkey flow.

Keep the same cautious habits you use for messaging and payment security. Securing WhatsApp from scams and unknown links is relevant because a convincing chat can lead you to a genuine account page while still persuading you to make the wrong change.

Never tell a website or caller your device PIN. Do not approve repeated prompts you did not initiate. A passkey prompt should appear because you are signing in to a service you chose to visit.

Manage Passkeys as Accounts Change

Review saved passkeys after replacing a phone, returning a work computer, changing credential managers, or closing an account. Delete obsolete credentials from the service's security settings and from the provider if necessary. First confirm that another working sign-in route exists.

Names such as “iPhone” or “Windows device” can become confusing after several upgrades. Use descriptive labels where the service allows them, such as the device type and creation month. Never include the device PIN or another secret in the label.

If you move between Android, Apple, and Windows devices, decide which credential provider will be your main home rather than accepting a different default each time. Cross-platform support has improved, but storage and sync behaviour still depend on the provider and software version.

For general phone hardening, review Android privacy settings worth changing. Device privacy, software updates, and a strong screen lock support every passkey stored on the phone.

A Sensible Migration Order

Begin with accounts that support passkeys clearly and have recovery information you have already verified. Email is important because it often controls recovery for other accounts, but it also deserves extra preparation. Make sure another trusted device or recovery method works before changing its sign-in setup.

Next, consider cloud storage, shopping, social accounts, and communication services. Financial or government services may have their own rules and may not support passkeys yet. Use only the methods shown in their official app or website.

Keep unique passwords for accounts that still require them. A passkey on one service does not make reused passwords safe elsewhere. The companion guide on using passkeys safely instead of passwords can help with the broader transition and ongoing account checks.

Your Passkey Setup Checklist

Before calling an account ready, confirm each point:

  • The device and browser are current and supported.
  • The screen-lock PIN is strong and enrolled biometrics are trusted.
  • The passkey was created from the service's official app or website.
  • You know whether it is synced or device-bound.
  • The credential was saved to the intended personal or work profile.
  • Sign-in works on the original device.
  • Sign-in or recovery also works on a second trusted route.
  • Recovery email, phone number, and codes are current.
  • No passkey was left on a public, borrowed, or returned device.
  • Lost-device removal and account activity pages are easy to find.

Passkeys are most useful when they remove a phishable password without creating a recovery mystery. Know where the credential lives, protect the account that syncs it, keep a tested fallback, and migrate one service at a time. That approach gives you the convenience of passkeys while keeping control of what happens when a device, provider, or account changes.

Reader answers

Frequently asked questions

Open a question to read the answer. Opening another answer closes the previous one.

What is a passkey?

A passkey is a cryptographic sign-in credential stored by your device, credential manager, or security key. You approve it with your device lock instead of typing a reusable password.

Are passkeys safer than passwords?

Passkeys resist common phishing because each credential is linked to the genuine website or app. They still depend on secure devices, protected recovery methods, and careful approval of sign-in prompts.

Can I use the same passkey on multiple devices?

Yes, if it is stored by a credential manager that syncs across your approved devices. A device-bound passkey remains on one device unless you create another credential.

What happens to my passkeys if I lose my phone?

Use another approved device or the service's recovery process, then remove the passkey associated with the missing device. A device-bound passkey may be unavailable without a backup method.

Should I delete my password immediately after creating a passkey?

No. Test the passkey and confirm a recovery route first. Some services keep the password as a fallback, while others offer a separate passwordless option.

Can I use a passkey on a shared computer?

Yes. Choose a passkey from your nearby phone and avoid saving a new credential, profile, biometric, or PIN on the shared computer. Sign out when finished.

Do all websites and apps support passkeys?

No. Support depends on the website, app, operating system, browser, and account type. Keep a unique password and strong multi-factor authentication where passkeys are unavailable.

Does a website receive my fingerprint or face data?

Google, Apple, and Microsoft state that biometric information used to approve a passkey remains on the device. The website receives cryptographic proof, not your fingerprint or face data.

Why is cross-device passkey sign-in not working?

Check that both devices have current software, Bluetooth enabled, internet access, and physical proximity. Restart the sign-in from the service's genuine page if the prompt has expired.

Should I create a backup passkey?

For an important account, a second passkey or compatible security key can provide a tested fallback if the service supports multiple credentials. Store the backup separately and securely.

Filed underpasskeys instead passwordspasskeys instead passwords 2026passkeys instead passwords for beginnerspasskeys instead passwords guidepasskeys instead passwords tutorialuse passkeys instead passwords