Passkey
In short
A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
What is a passkey?
A passkey replaces a password with a cryptographic key pair. When you create a passkey for a website, your device generates a private key that stays on the device or in your password manager, and sends only the matching public key to the site. To sign in, you unlock the passkey with the same fingerprint, face scan, or PIN you use to unlock your phone or computer, so there is nothing to type or remember.
Passkeys are built on the FIDO2 standards, including the WebAuthn browser API. At sign-in, the server sends a random challenge, the device signs it with the private key, and the server checks the signature with the stored public key; neither the private key nor the fingerprint or face data ever leaves the user's device. Each passkey is tied to the exact domain it was created for, so the browser simply won't offer it on a look-alike phishing site. Passkeys can be synced across a user's devices by their platform or password manager, or kept on a hardware security key.
Because the server stores only public keys, a database breach reveals nothing an attacker can sign in with, and there are no passwords to reuse, guess, or brute-force. A passkey is like a house key that only fits your own front door and refuses to turn in any other lock, even a perfect copy of your door built by a burglar. Most major operating systems, browsers, and password managers support passkeys, and many services now offer them next to or instead of passwords, while keeping a recovery path for users who lose their devices.
Passkeys are often confused with two-factor authentication. Traditional 2FA adds a second step, such as a one-time code, on top of a password, and those codes can still be phished, while a passkey replaces the password entirely and is phishing-resistant by design. Because it combines something you have, the device, with something you are or know, a biometric or PIN, a passkey on its own often satisfies multi-factor requirements.
Key takeaways
- A passkey is a key pair: the private key stays with the user, and the site stores the public key.
- Users unlock passkeys with a biometric or device PIN instead of typing a password.
- Passkeys are bound to one domain, which makes them resistant to phishing.
- A server breach exposes only public keys, which are useless for signing in.
- Passkeys are built on the FIDO2 and WebAuthn standards.
Example
// In the browser: create a passkey for this site
const credential = await navigator.credentials.create({
publicKey: {
challenge: challengeFromServer, // random bytes, used once
rp: { id: "example.com", name: "Example" }, // the passkey only works here
user: { id: userIdBytes, name: "ada@example.com", displayName: "Ada" },
pubKeyCredParams: [{ type: "public-key", alg: -7 }], // ES256
authenticatorSelection: { residentKey: "required", userVerification: "required" },
},
});
// Send the result to the server, which stores only the public key
await fetch("/passkeys/register", { method: "POST", body: serialize(credential) });Readers ask
Are passkeys safer than passwords?
Yes, in most ways. They can't be guessed, reused across sites, or typed into a phishing page, and a server breach exposes only public keys; the main remaining risks are weak account recovery flows and a compromised device.
What happens if I lose the device with my passkey?
If your passkeys are synced through a password manager or platform account, they are still available on your other devices. Otherwise you sign in with another passkey or a recovery method the site offers, which is why sites should let users register more than one passkey.
What is the difference between a passkey and a security key?
A security key is a small hardware device that stores credentials. A passkey is the credential itself, which can live on a security key or be stored in and synced by a phone, computer, or password manager.
See also
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- PhishingSecurity, p. 27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- Digital SignatureSecurity, p. 11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- Brute-Force AttackSecurity, p. 4A brute-force attack is an attempt to break into an account or decrypt data by systematically trying huge numbers of possible passwords or keys until one works.
Spotted a mistake or something missing on this page?Suggest an edit