Skip to main content
Book 07 · SecurityPage 25 of 50

Passkey

Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/passkey

In short

A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.

What is a passkey?

A passkey replaces a password with a cryptographic key pair. When you create a passkey for a website, your device generates a private key that stays on the device or in your password manager, and sends only the matching public key to the site. To sign in, you unlock the passkey with the same fingerprint, face scan, or PIN you use to unlock your phone or computer, so there is nothing to type or remember.

Passkeys are built on the FIDO2 standards, including the WebAuthn browser API. At sign-in, the server sends a random challenge, the device signs it with the private key, and the server checks the signature with the stored public key; neither the private key nor the fingerprint or face data ever leaves the user's device. Each passkey is tied to the exact domain it was created for, so the browser simply won't offer it on a look-alike phishing site. Passkeys can be synced across a user's devices by their platform or password manager, or kept on a hardware security key.

Because the server stores only public keys, a database breach reveals nothing an attacker can sign in with, and there are no passwords to reuse, guess, or brute-force. A passkey is like a house key that only fits your own front door and refuses to turn in any other lock, even a perfect copy of your door built by a burglar. Most major operating systems, browsers, and password managers support passkeys, and many services now offer them next to or instead of passwords, while keeping a recovery path for users who lose their devices.

Passkeys are often confused with two-factor authentication. Traditional 2FA adds a second step, such as a one-time code, on top of a password, and those codes can still be phished, while a passkey replaces the password entirely and is phishing-resistant by design. Because it combines something you have, the device, with something you are or know, a biometric or PIN, a passkey on its own often satisfies multi-factor requirements.

Key takeaways

  • A passkey is a key pair: the private key stays with the user, and the site stores the public key.
  • Users unlock passkeys with a biometric or device PIN instead of typing a password.
  • Passkeys are bound to one domain, which makes them resistant to phishing.
  • A server breach exposes only public keys, which are useless for signing in.
  • Passkeys are built on the FIDO2 and WebAuthn standards.

Example

Creating a passkey with the WebAuthn APIjavascript
// In the browser: create a passkey for this site
const credential = await navigator.credentials.create({
  publicKey: {
    challenge: challengeFromServer,             // random bytes, used once
    rp: { id: "example.com", name: "Example" }, // the passkey only works here
    user: { id: userIdBytes, name: "ada@example.com", displayName: "Ada" },
    pubKeyCredParams: [{ type: "public-key", alg: -7 }], // ES256
    authenticatorSelection: { residentKey: "required", userVerification: "required" },
  },
});

// Send the result to the server, which stores only the public key
await fetch("/passkeys/register", { method: "POST", body: serialize(credential) });

Readers ask

Are passkeys safer than passwords?

Yes, in most ways. They can't be guessed, reused across sites, or typed into a phishing page, and a server breach exposes only public keys; the main remaining risks are weak account recovery flows and a compromised device.

What happens if I lose the device with my passkey?

If your passkeys are synced through a password manager or platform account, they are still available on your other devices. Otherwise you sign in with another passkey or a recovery method the site offers, which is why sites should let users register more than one passkey.

What is the difference between a passkey and a security key?

A security key is a small hardware device that stores credentials. A passkey is the credential itself, which can live on a security key or be stored in and synced by a phone, computer, or password manager.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings