Passkeys let you sign in with the screen lock already protecting your phone or computer. You do not have to remember or type a password, and a fake website cannot collect the secret that proves you own the account. That makes passkeys a strong choice for accounts that support them.
How to Use Passkeys Safely Instead of Passwords
Use passkeys without creating a new lockout risk. Learn where passkeys are stored, how syncing works, what to do after device loss, and how to prepare secure account recovery.

Safe use still depends on a few decisions. You need to know where the passkey will be saved, how you will regain access after losing a device, and which old sign-in methods remain active. This guide walks through those decisions without assuming that every phone, browser, or account works the same way.
The short answer
Create passkeys only from the official app or website, and save them to a personal device, trusted password manager, or hardware security key that you control. Protect every device with a strong screen lock. Before removing an old sign-in method, test the passkey and confirm that your account recovery details are current.
A synced passkey is usually the most convenient option for an individual because the credential can become available on other approved devices through the same credential manager. A device-bound passkey stays on one device or security key. That can suit people who want tighter physical control, but it also makes a spare sign-in method more important.
If a phone, laptop, or security key goes missing, use another trusted device to open the affected account's security settings. Remove the passkey or lost device, review active sessions, and create a replacement. Lock or erase the lost device through its official recovery service when possible.
What a passkey changes
A passkey uses a cryptographic key pair. The website stores a public key. Your device or credential manager protects the private key and uses it to answer a fresh challenge during sign-in. The private key is not sent to the website.
Each passkey is associated with the website or app that created it. According to the FIDO Alliance explanation of passkeys, this binding to the online service is what makes a passkey resistant to ordinary credential phishing. A lookalike site cannot ask your passkey to authenticate to the genuine site's domain. There is also no reusable password for a criminal to steal from one service and try elsewhere.
Your fingerprint, face scan, PIN, or device pattern unlocks the passkey locally. FIDO says biometric information stays on the device and is not sent to the remote service. The website receives proof that the device completed the requested user verification. Your device PIN is not the passkey, and you should never type that PIN into a website.
This distinction matters when a prompt looks unfamiliar. A legitimate passkey flow asks you to approve sign-in through the operating system, browser, credential manager, or security key. A page that asks you to enter your phone PIN, computer PIN, fingerprint data, recovery code, or password is asking for something else. Stop and return to the official service directly.
Prepare your accounts before switching
A passkey is easier to use when account recovery has already been prepared. Complete these checks before creating the first one on an important account.
- Update the device and browser. Passkey support depends on the operating system, browser, and credential manager. Install current security updates before troubleshooting a missing option.
- Use a private screen lock. Anyone who can unlock a device may be able to use passkeys stored on it. Replace a shared or easily guessed PIN before adding account credentials.
- Review recovery details. Confirm that your recovery email address and phone number are current. Keep recovery codes in a secure place if the service provides them. Never store a recovery code in a public note or an unprotected screenshot.
- Choose a passkey provider. Decide whether the passkey should live in Apple Passwords and iCloud Keychain, Google Password Manager, Microsoft Password Manager, another trusted credential manager, Windows Hello, or a hardware security key. The choices offered depend on your device and the service.
- Keep one independent route back in. A second approved device, another passkey, a spare hardware key, or the service's recovery process can prevent one lost device from becoming a lockout.
Do not create a passkey on a family computer, office kiosk, public computer, or borrowed phone by accepting the default save location. A passkey on a shared device can remain usable after you sign out if another person can unlock that device. Google explicitly advises users to create Google Account passkeys only on personal devices they control.
If you often share a computer, use a passkey stored on your own phone for cross-device sign-in instead of saving a credential to the shared computer. The temporary computer displays the sign-in request, while your phone approves it.
Create a passkey without losing your fallback
The wording differs across services, but the safe sequence remains similar.
- Type the service's address yourself, use a saved bookmark, or open its official app. Do not begin from an unsolicited email, text message, advertisement, or QR code.
- Sign in and open the account's security or sign-in settings. Look for Passkeys, Sign-in methods, Password and security, or a similar label.
- Select the option to create or add a passkey. Read the account name and the proposed save location before confirming.
- If the wrong credential manager or device appears, choose an option such as Save another way, Other options, or Use another device. Cancel if you cannot identify where the credential will be stored.
- Unlock the selected device or security key with its normal local method. You might use a fingerprint, face scan, device PIN, pattern, or hardware key PIN.
- Return to the account's security page and confirm that the new passkey appears. Rename it with a useful device or provider label if the service allows this.
- Open a private browser window or another supported device and test the new passkey. Keep the existing recovery method until this test succeeds.
For a Google Account, Google's current instructions direct users to Security & sign-in, then Passkeys and security keys. The Google Account passkey guide also explains how to remove a passkey and how to use a phone to sign in on a computer.
On an iPhone, Apple requires iCloud Keychain and two-factor authentication for passkeys stored in iCloud Keychain. The Apple iPhone passkey guide shows the usual creation, sign-in, cross-device, and deletion steps. A website may use different button labels.
On Windows 11, a passkey can be stored locally with Windows Hello, in a synced credential manager, on a phone or tablet, or on a security key when the service supports that choice. Microsoft's passkey creation guide explains the available save locations. Work and school accounts may be restricted by an administrator.
Choose between synced and device-bound passkeys
The label shown during creation tells you where the credential will be available. Do not assume every passkey automatically follows you to a new device.
| Storage choice | Where it works | Main advantage | Preparation needed |
|---|---|---|---|
| Synced credential manager | Approved devices signed in to the same provider account | Convenient access and recovery after one device is lost | Secure the provider account and keep its recovery details current |
| Local device storage | The device where the passkey was created | Direct control without cloud syncing | Create another sign-in route before the device fails or is lost |
| Hardware security key | The physical security key | Portable, device-bound credential under physical control | Register a spare key or another recovery method and store it separately |
| Phone used from another device | Your phone approves a sign-in started nearby | Useful on a computer where you do not want to save the passkey | Keep Bluetooth available when the flow requests proximity verification |
FIDO states that synced passkeys use end-to-end encrypted synchronization and that providers protect account recovery with additional controls. The practical security question is broader than encryption alone. Someone who takes over the provider account or unlocks an approved device may gain access to synced credentials. Use strong recovery settings, remove old devices, and respond promptly to account alerts.
A local passkey can reduce reliance on a cloud provider, but it does not remove the need for recovery. If that device is damaged, erased, or stolen, the credential may be unavailable. Register another passkey before relying on a single local copy for an essential account.
Sign in on your usual device
Open the official app or website and select the account you want to use. The browser or operating system should offer the matching passkey. Confirm the service and account shown in the prompt, then use your normal device unlock method.
If a passkey does not appear, check that the correct credential manager is enabled, the device screen lock is active, and the browser and operating system are current. Also check whether you are signed in to the provider account that holds the passkey. Do not keep approving random prompts in the hope that one will work.
A service may still show a password field even when passkey sign-in is available. Look for options such as Use a passkey, Other ways to sign in, or Sign-in options. If the account offers no passkey choice, the service may not support it yet, or the feature may not be available for that account type.
Use a phone to sign in on another device
Cross-device sign-in is useful when the passkey lives on your phone but you need to use a computer. Start from the genuine service on the computer, choose the option to use a passkey from another device, and display its QR code. Scan that code with the phone that holds the passkey, then approve the sign-in on the phone.
The devices may use Bluetooth to confirm that they are physically close. FIDO explains that the actual sign-in remains protected by an additional cryptographic layer rather than relying on Bluetooth security alone. Keep the phone near the computer until the process finishes.
Treat an unexpected passkey QR code like any other unexpected sign-in request. Do not scan a code sent through a message or displayed by a caller claiming to be support. Begin the process yourself on the official site's sign-in screen. Check the domain, account, and approval prompt before unlocking the passkey.
On a public or borrowed computer, do not select an option that saves the passkey to that computer. Finish the session, sign out of the website, close the browser, and avoid saving account details. If the account is especially sensitive, review its active sessions later from your own device.
What to do if a device is lost or stolen
A lost device does not automatically reveal a passkey because the device should still require its screen lock. It does require prompt action because the lock protects more than passkeys and may be known to someone else.
- Use the official Apple, Google, or Microsoft device service to locate, lock, or erase the missing device when available.
- From another trusted device, open each important account's security settings. Remove the passkey associated with the lost device or remove the device session as the service instructs.
- Review recent sign-ins, recovery changes, forwarding rules, connected apps, and other passkeys for activity you do not recognize.
- Create and test a replacement passkey on a controlled device.
- Change any password that was saved on the missing device if the account provider recommends it or if the device may have been unlocked.
Google tells users to remove the passkey associated with a lost or stolen device. For an automatically created Android passkey, its guidance says to remove the device from the Google Account and sign out its sessions. Removing the entry only from a credential manager may not revoke it at the service, and deleting only at the service may leave a stale local entry. Check both places.
Microsoft similarly separates passkeys stored in Windows from sign-in methods registered with an account. Its saved passkey management guide advises users to add new security information before removing a needed Microsoft Account passkey. Work or school credentials may need deletion both in the account security portal and where the passkey was saved.
For Apple users, passkeys in iCloud Keychain can be available on other approved Apple devices. Apple describes encrypted recovery for iCloud Keychain and recommends preparing account recovery. Its passkey security guide explains device approval and recovery protections. An optional recovery contact can help if you lose access to your Apple Account, but that person does not receive access to the account.
Build recovery that does not undo the benefit
Passkeys remove the risk of typing a reusable secret into a fake site, but an account can still have weak recovery routes. A password, SMS code, support process, or recovery email that remains active may still be targeted. Review the whole sign-in and recovery page after adding a passkey.
Do not remove every fallback at once. First create and test at least two independent ways to regain access. A synced passkey on approved devices plus current provider recovery details may be enough for many people. A device-bound setup may use two hardware keys stored separately, or one hardware key plus another approved passkey. Follow the service's own recovery options rather than inventing a workaround.
Keep recovery codes offline or inside a well-protected vault. Do not save them in an ordinary photo, email draft, messaging chat, or unprotected cloud document. A recovery code can bypass the protection you gained from a passkey. No legitimate support agent needs your passkey, device PIN, one-time code, or recovery code.
When using Google Password Manager, Apple Passwords, Microsoft Password Manager, or another synced provider, secure the provider account itself. Update its recovery information, use account alerts, remove devices you no longer own, and avoid approving sign-in notifications you did not start.
If you want a broader account cleanup, the Tutorils guide to separating work and personal accounts can help you avoid saving credentials under the wrong profile. Android users can also review the best Android privacy settings to change before placing more account access on one phone.
Understand what phishing resistance does not cover
Passkeys block the familiar attack where a fake site steals a password or one-time code and reuses it at the real site. They also prevent password reuse because every service gets a separate cryptographic credential. These protections are built into the protocol rather than depending on a reader spotting every fake page.
They do not make a device, browser session, recovery process, or person impossible to attack. Criminals may still try to persuade you to reveal a recovery code, install remote-control software, approve a payment, change recovery details, or hand over an unlocked device. Malware on an already compromised computer can also create risks outside the passkey exchange.
A passkey approval proves control of the credential for that sign-in. It does not prove that every message, download, purchase, permission request, or person on the service is trustworthy. Keep evaluating what happens after sign-in. If a phone behaves unexpectedly, follow the Tutorils steps to find and remove spyware apps before using it for sensitive account recovery.
Use the same caution with account notifications. Open the official app yourself instead of tapping a sign-in link in a warning message. If an alert refers to activity you did not start, deny it, review sessions, and follow the provider's incident guidance.
Review and remove old passkeys safely
Open the security settings for important accounts after replacing a phone, changing credential managers, leaving a job, or noticing suspicious activity. Look for passkeys you do not recognize, duplicate names, old devices, and sign-in methods you no longer control.
Before deleting an entry, create and test the replacement. Then remove the old passkey from the service account. Also remove stale local entries from the credential manager or Windows settings when necessary. Removing a local copy and revoking a credential at the service are related actions, but they are not always the same action.
Give passkeys useful names such as Personal Pixel, Home Windows PC, or Backup security key if the service permits renaming. Avoid names containing a device PIN, recovery code, or other secret. A clear label makes a lost-device response faster and reduces the chance of deleting the wrong entry.
For readers who are completely new to the sign-in flow, the separate Tutorils beginner guide to using passkeys instead of passwords covers the basic concept. This guide should remain your safety and recovery checklist after setup.
A practical passkey safety checklist
Before relying on a passkey for an important account, confirm that:
- You created it from the official app or website.
- The account name and save location were correct.
- The device uses a private screen lock and current security updates.
- You can explain whether the passkey is synced, local, or stored on a hardware key.
- Recovery email addresses, phone numbers, contacts, or codes are current and protected.
- You tested sign-in before removing an older method.
- A second approved route exists if the main device is lost.
- You know where to revoke the passkey at the service and where to remove its stored copy.
- Old devices and unrecognized sessions have been removed.
- You still treat unexpected QR codes, support calls, recovery requests, and post-login actions with care.
Passkeys remove several weaknesses that come with passwords, but safe use is not automatic. The strongest setup is the one you can recover without relying on a stranger, a shared device, or an exposed code. Start with one important account, confirm where its passkey is stored, test a second sign-in route, and document how you would revoke it after device loss.
Reader answers
Frequently asked questions
Open a question to read the answer. Opening another answer closes the previous one.
Are passkeys safer than passwords?
Passkeys resist credential phishing and cannot be reused across websites. Their safety still depends on your device lock, passkey provider, account recovery methods, and how quickly you remove lost devices.
Does my fingerprint or face leave my device when I use a passkey?
No. FIDO says biometric processing stays on the device. The website receives proof that local verification succeeded, not your fingerprint, face scan, or device PIN.
What happens to my passkeys if I lose my phone?
Synced passkeys may remain available on another approved device. Lock or erase the lost phone, remove its passkeys or sessions from affected accounts, review activity, and create a tested replacement.
Can passkeys sync across different devices?
Yes, when saved to a supported synced credential manager. Devices must use the relevant provider account and meet its security requirements. A passkey stored only on one device does not automatically sync.
Should I create a passkey on a shared computer?
No. Someone who can unlock that computer may be able to use its passkeys. Use a passkey from your personal phone or security key without saving it to the shared computer.
Can a phishing website steal my passkey?
A passkey is bound to the service that created it, so an ordinary lookalike site cannot use it for the genuine domain. Scammers may still target recovery codes, unlocked devices, or post-login actions.
Can I use a phone passkey to sign in on a computer?
Usually, yes. Start the passkey flow on the official website, choose a nearby device, scan the displayed QR code with your phone, and approve the matching request on the phone.
Should I delete my password as soon as I create a passkey?
Test the passkey and confirm a separate recovery route first. Then follow the service's options. Some accounts retain a password fallback, while others allow a more complete passwordless setup.
Can I have more than one passkey for the same account?
Many services allow multiple passkeys, but the exact policy varies. Adding a second device or separately stored security key can provide a useful backup before you remove an old credential.
Where can I view or remove saved passkeys?
Check both the service's account security page and the credential manager or device settings where the passkey is stored. Revoking it at the service and deleting its local copy may be separate steps.