What is a passkey, and should I use one?
More and more websites and apps now offer a "passkey", and increasingly they prompt you to create one. A passkey is a newer, simpler, and safer way to sign in that is quietly replacing the password. It is worth understanding, because in most cases the answer to "create a passkey?" is yes.
What a passkey is
A passkey lets you sign in the same way you unlock your phone - with your face, your fingerprint, or your PIN. There is no password to type, remember, or get wrong. Behind the scenes, your device holds a secret key that proves it is you; you never see it, and it never leaves your device in a form anyone could steal.
Two things follow from that:
- There is nothing to remember. Signing in is just a glance or a touch.
- There is nothing for a scammer to phish. Because you never type a secret, a fake look-alike website has nothing to trick out of you - which is why passkeys are called "phishing-resistant".
Why they are safer than passwords
- A password can be guessed, reused, leaked in a breach, or phished. A passkey has no shared secret to steal.
- A passkey only works on the real website or app it was made for, so a fake page cannot use it.
- It cannot be handed over by mistake, because there is nothing to read out or type in.
Where your passkeys live
Your passkeys are saved by your phone or password manager and sync securely across your devices - Apple Passwords through iCloud Keychain, Google Password Manager on Android, or an app like 1Password. Sign in on a new device and they are simply there. You can also use your phone to sign in on a computer, usually by scanning a code on screen.
Should you say yes?
Usually, yes. When a site you trust offers to create a passkey, it is a good idea for anything that matters - your email, your bank, your main accounts. You do not have to do them all at once; add them as you go.
A few practical notes:
- You can keep your password as a backup while you get used to passkeys - you do not have to delete it.
- Make sure your phone or password manager is backing up, so a passkey is not stuck on one device, and set a recovery method on your Apple or Google account.
- Not every site offers passkeys yet, so you will still use passwords and two-factor authentication in the meantime.
If you only do one thing
Next time a site you trust offers a passkey, say yes - starting with your email. It is less to remember, and much harder to steal.
Related: How can I create strong passwords I can actually manage?
General information, correct when last reviewed. Platforms and threats change - always confirm critical steps on the official source. Product names are used only to describe their features; Monkleton Labs is not affiliated with, or endorsed by, them. No ads, no affiliate links.