Security
Passkeys, explained without the jargon
How a different sign-in method changes your everyday routine.

The basic idea
A passkey is a sign-in credential based on cryptographic keys rather than a password you type. A supported service checks that your device or credential manager holds the matching private key. You usually approve access using a device unlock method.
Why the website address matters
Passkeys are designed to work with the service they were created for. That can reduce the risk of entering a reusable password into an imitation website. It does not make every account action safe: attackers can still use deceptive messages or compromised devices.
Before switching
Check which devices and browsers you use, whether your credential manager supports syncing and how you would recover access after losing a device. Recovery arrangements vary by provider. Keep account recovery information current and protect the account that manages your synced credentials.
Try one account first
Start with a service you already use that offers passkeys. Create one through its official settings, then test sign-in from another device you regularly use. Keep a documented recovery path before removing an existing sign-in option.
FAQ: does my fingerprint go to the website?
In normal passkey use, device verification unlocks the credential locally; the website receives a cryptographic response rather than your fingerprint. The exact device and provider implementation still matters.
The takeaway
A better sign-in method is useful only when you understand recovery. Treat setup and recovery as one task, and follow the instructions from your chosen provider.
Prepared with AI assistance. General editorial information; verify product-specific details with the provider. Editorial standards
Explore more explainers ↗
