What this protects, and what it doesn't
Protects
- Against phishing: a passkey only works on the site it was created for, and the browser enforces that, so a lookalike page cannot use it.
- Against password reuse and database leaks: there is no shared secret to steal from the service; it only stores a public key.
- Against SIM swapping and intercepted SMS codes, once you remove text messages as a sign-in or recovery method.
- Against relayed one-time codes: unlike a code you type, a passkey cannot be passed on by a fake site in real time.
Does not protect
- A weak recovery path. If the account can still be recovered with an SMS code or a guessable e-mail, an attacker will use that path instead.
- A compromised device. Malware running on your unlocked computer or phone can act inside sessions you have already opened.
- Stolen session cookies. After you sign in, the site gives your browser a cookie; if malware steals it, the attacker is logged in without any passkey.
- Someone who can unlock your phone or computer. A synced passkey is only as safe as the screen lock and the account it syncs with.
Prerequisites
- A phone or computer with a screen lock (PIN, fingerprint or face unlock) and an up-to-date operating system.
- Optional but recommended for important accounts: two FIDO2 hardware security keys (USB or NFC), one for daily use and one as a backup.
- A safe place for recovery codes: a password manager or paper kept at home.
Step by step
-
Understand what a passkey is
A passkey is a sign-in credential based on the FIDO standards (FIDO2 and the W3C WebAuthn standard). Instead of a password, your device holds a private key that is unique to one site, and you unlock it with your screen lock: a fingerprint, your face or a PIN. The site only stores the matching public key.
There are two kinds:
- Synced passkeys are stored by a passkey provider (for example iCloud Keychain, Google Password Manager or a password manager) and copied to all your devices. They are convenient and survive the loss of a phone.
- Device-bound passkeys never leave one device, for example a hardware security key. The FIDO Alliance describes them as offering the highest assurance; the trade-off is that losing the key loses the passkey.
-
Start with the accounts that unlock everything else
Your main e-mail account comes first: whoever controls it can reset almost every other password. Then your Apple, Google or Microsoft account (it often holds your synced passkeys, photos and backups), your password manager, your bank, and your work accounts.
-
Add a passkey to a Google account
On the device you want to use, go to myaccount.google.com/signinoptions/passkeys, choose Create a passkey, and unlock your device when asked. Repeat on each device you use. Do not create one on a shared device.
To put the passkey on a hardware security key, choose Create a passkey, then Use another device, insert your key and enter its PIN. Adding a passkey does not remove your other sign-in or recovery methods, so continue with the recovery steps below.
-
Use passkeys on Apple devices
On iPhone, iPad and Mac, passkeys are saved in iCloud Keychain and sync to your other Apple devices. iCloud Keychain is end-to-end encrypted with keys Apple does not know, and it requires two-factor authentication on your Apple Account. When a site or app offers to create a passkey, accept it and confirm with Face ID, Touch ID or your passcode.
To sign in on a device that is not yours, most sites can show a QR code that you scan with your iPhone nearby; the passkey never leaves the phone.
-
Add a passkey to a Microsoft account
Sign in at account.live.com/proofs/manage (Advanced security options), choose Add a new way to sign in or verify, then Face, Fingerprint, PIN, or Security Key, and follow your device's prompts. You can save it on the device, in a password manager, on your phone or on a security key. Work and school accounts depend on your organisation; ask your IT team.
-
Register two hardware keys and set a PIN
A hardware security key is a small USB or NFC device that holds device-bound passkeys. Always register two keys on every account that accepts them, and keep the second one somewhere safe at home. Losing your only key can lock you out.
Set a FIDO2 PIN on each key (the site or your operating system asks for one the first time, or use the maker's app). The PIN is checked by the key itself and is not sent over the network. On a YubiKey, after 3 wrong PINs in a row you must unplug and reinsert it, and after 8 wrong PINs the FIDO2 part is blocked. The only way out is a reset, which deletes every passkey on that key. That is why the backup key matters.
-
Save your recovery codes
Most services give you single-use backup codes for when you lose your devices. For Google: open your Google Account, Security, 2-Step Verification, and under Backup codes get a set of 10. Each code works once; you can create a new set at any time, which cancels the old one.
Store codes in your password manager or on paper at home, not in your e-mail, photos or a note synced to the account they protect. If you need a strong master password for that password manager, the password generator creates one in your browser.
-
Remove text-message codes where you can
Codes sent by SMS can be intercepted or redirected by SIM swapping, where an attacker convinces your mobile operator to move your number to their SIM. Once you have passkeys, a backup key and recovery codes, remove your phone number as a sign-in and recovery method on accounts that allow it. Microsoft has announced that it is phasing out SMS for personal accounts for exactly these reasons.
Before you remove it, sign out and sign back in with each passkey and each hardware key, and check that your recovery codes are where you think they are.
-
Know why passkeys beat authenticator codes
Authenticator-app codes (TOTP) are much better than SMS, but you type them in, so a fake site can ask for the code and replay it to the real site within seconds. NIST's digital identity guidelines (SP 800-63B) state that one-time-password authentication is not phishing-resistant, and that phishing resistance requires cryptographic authentication bound to the site, such as WebAuthn/FIDO2. Keep TOTP for accounts that do not offer passkeys yet.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Registering a single hardware key and no backup method, then losing it.
- Adding a passkey but leaving SMS recovery switched on, so the weakest path still opens the account.
- Keeping recovery codes in the e-mail account they are meant to recover.
- Creating a passkey on a shared or borrowed computer.
- Guessing a forgotten security-key PIN until the key blocks and has to be wiped.
Going further
If your threat model is Medium or High, prefer device-bound passkeys on hardware keys for your e-mail, cloud and work accounts, and turn on the strongest account protection the provider offers. Review which devices hold your synced passkeys, and remove old phones and computers from your account.