Auth and identity · Protocol

Passkeys

A replacement for passwords: the device creates a unique key for each website and signs in with a fingerprint, face scan or screen lock PIN, with nothing to type or remember.

Ways to sign in · Free · updated

How it works

A passkey is a WebAuthn (FIDO2) credential. When someone creates one, their device makes a private key that stays on the device or in their password manager and gives the website only the matching public key. At sign-in the site sends a random challenge, the device asks for a fingerprint, face or PIN to unlock the key, and signs the challenge; the server checks that signature with the public key. No shared secret exists, so a leaked database holds nothing an attacker can sign in with.

Each passkey is bound to the website's domain, so a look-alike phishing site simply gets no answer, which is what sets passkeys apart from passwords and codes. Apple, Google and Microsoft support them across their platforms, and they sync between a person's devices through iCloud Keychain, Google Password Manager or password managers such as 1Password and Bitwarden. On a borrowed computer, a phone can approve the sign-in by scanning a QR code.

Adoption is still uneven: older devices, shared computers and people without a synced account can struggle, so apps usually offer passkeys alongside another method and invite users to add one after they sign in. On Android, Credential Manager handles creating and using them.

Passkeys pros and cons

Pros

  • Resistant to phishing, because each passkey only works on its own website
  • Nothing to remember or type; sign-in takes a tap or a glance
  • A server breach exposes only public keys, which are useless to attackers
  • Syncs across devices through Apple, Google and password managers
  • No messages to send and no per-use fees

Cons

  • Still unfamiliar to many users, so it needs clear prompts and a fallback
  • Older devices, shared computers and some browsers make it awkward
  • Account recovery still depends on another method
  • More work to build than a password form without a library or provider

When to use Passkeys

Pick it when

  • Returning users on phones and laptops from the last few years
  • Accounts worth protecting from phishing, such as money or admin access
  • You want to phase out passwords or SMS codes over time

Skip it when

  • It would be the only way in and many users have older or shared devices
  • Your auth provider lacks support and building it yourself is not an option

Passkeys pricing

Free

Free: an open standard built into operating systems, browsers and password managers. Some auth providers include passkeys only on paid plans.

Approximate, checked September 2026.What the other tools cost

Passkeys vs the alternatives

More in Auth and identity

Ways to sign in

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.