What is a passkey?
A passkey signs you in with your fingerprint, face or PIN, with no password to type. How it works, where it is kept, and what happens if you lose the phone.
A passkey lets you sign in to an online account without typing a password. You confirm it is you the same way you open your phone or computer, with a fingerprint, your face or a PIN, and the device does the rest.
How it works
A passkey is a pair of matching keys, made by your device for one account on one website. The private key stays with you: on the device, in a password manager or on a physical security key. The public key is given to the website. The public key cannot be used to work out the private one.
- You start to sign in, and the website sends your device a random challenge.
- Your device asks for your fingerprint, face or PIN.
- The device signs the challenge with the private key and sends the signature back.
- The website checks the signature against the public key it holds, and lets you in.
The Australian Signals Directorate compares a passkey to a set of apartment keys kept in a key safe. Your PIN opens the safe, and the key inside opens the door. The PIN or fingerprint never leaves your device. The website sees only the signature.
Why it is harder to steal than a password
- There is nothing to type. A passkey is only ever presented to the website it was created for, so a fake sign-in page gets nothing.
- There is nothing to guess or reuse. Each account has its own key pair, made by the device.
- A breach of the website gives away less. The website holds only public keys, which are no use for signing in.
A passkey also counts as multi-factor authentication by itself. It combines something you have, the device, with something you are or know, the fingerprint or PIN that the device asks for.
Where a passkey is kept
- Synced passkeys are stored by a password manager, such as Apple’s iCloud Keychain, Google Password Manager or one you install yourself, and copied to your other devices.
- Device-bound passkeys stay on one piece of hardware, such as a security key, and are never copied.
Synced passkeys are easier to live with. Device-bound ones are stricter, and are often chosen for administrator accounts.
If you lose the phone
A synced passkey comes back when you sign in to the same password manager on a new device. A security key does not sync, so register a second key and keep it somewhere safe. Adding a passkey does not usually remove the sign-in and recovery methods an account already has, so check that those are still up to date.
Many services now offer passkeys in their security settings, often next to the options for multi-factor authentication. For accounts that need a stricter setup, read When should a business use hardware security keys?
Sources
- Use passkeys: personal cyber security handbook (Australian Signals Directorate) cyber.gov.au
- How passkeys work (FIDO Alliance, Passkey Central) passkeycentral.org
- Sign in with a passkey instead of a password (Google Account Help) support.google.com
- Authentication methods in Microsoft Entra ID: passkeys (FIDO2) (Microsoft Learn) learn.microsoft.com
- SP 800-63B-4: Digital identity guidelines, authentication and authenticator management (NIST) pages.nist.gov