
A passkey lets you sign in by unlocking a trusted phone, computer, password manager, or security key. It can replace a password on some services or act as a strong additional sign-in method.
Why passkeys resist phishing
A passkey is created for a specific website or service. It does not give a lookalike phishing site a reusable password that can be copied and entered somewhere else.
Your fingerprint, face scan, or device PIN unlocks the passkey locally. The biometric information itself is not sent to the website.
Passkeys reduce several common password problems, but they do not make the whole account automatic or risk-free. You still need working recovery information and control of the devices or account that stores your passkeys.
Find out where the passkey will be stored
Before selecting Create a passkey, check which device or credential manager is offering to save it. Common locations include:
- The password manager connected to an Apple, Google, or Microsoft account
- A third-party password manager
- One specific phone or computer
- A compatible hardware security key
Some passkeys sync between devices through the same account or password manager. Others remain on one device. The setup screen should tell you what is being used.
Be careful on shared devices
Do not create a personal passkey inside a shared browser profile or shared device account unless everyone with access should be able to use that sign-in.
Separate user profiles are safer for a family computer. Each adult should normally unlock their own profile and save passkeys through their own account or credential manager.
If a child uses a managed family account, review the provider’s family controls before creating passkeys. Avoid using one adult’s personal sign-in as a shortcut for every household member.
Check recovery before adding a passkey
Confirm that the account has:
- A current recovery email or phone number
- Another trusted signed-in device where practical
- Backup or recovery codes if the provider offers them
- A clear way to remove a lost device or passkey
Adding a passkey does not necessarily remove the password or other recovery methods. The provider decides how the account behaves, so read the confirmation screen.
Store emergency codes using the recovery-code guide before changing an important sign-in routine.
Create the first passkey calmly
Use the service’s official app or website. Choose the passkey option from its security settings, then unlock the device when prompted.
After setup:
- Keep the current trusted session open.
- Open a private browser window or another device.
- Try signing in with the passkey.
- Confirm that you understand which device or account supplied it.
- Review the list of passkeys in the account’s security settings.
Remove a passkey if you created it on the wrong device or inside the wrong profile.
When a passkey may not be the best first step
Pause if:
- The only available device is shared under one login
- You do not control the account that syncs the passkey
- You are about to replace or erase the device
- The service’s recovery options are out of date
- Another family member relies on the account but does not understand the new sign-in process
Fix those issues first. A unique password plus reliable two-step verification is still a reasonable setup when passkeys do not fit the household yet.
Your sensible stopping point
You are done when one passkey works on a trusted personal device, you know where it is stored, recovery details are current, and you know how to remove it if the device is lost.
Continue with the guide to protecting your most important accounts before changing several accounts at once.


