A passkey lets you sign in without typing a reusable password. Your device or passkey provider keeps a private digital key, while the website stores a matching public key. When you sign in, the site sends a challenge; after you approve locally with a fingerprint, face scan, PIN, or another device-unlock method, your authenticator answers it. The site checks that answer without ever receiving your private key.
What a passkey is—and what it is not
Think of the website as keeping a lock that matches a key held by your device. The website can check that your key fits, but it does not get a copy of the key. This is an analogy: a passkey uses a cryptographic public-and-private key pair, not two literal halves of a secret code. The public key is not secret and cannot, by itself, sign you in.
When you create a passkey for an account, the authenticator—such as your phone, computer, browser, or credential manager—creates a unique key pair for that service. The authenticator keeps the private key; the service registers the public key. Apple’s explanation puts it simply: “The server never learns what the private key is.” Apple Developer’s passkey overview and the FIDO Alliance passkey FAQ describe this model.
How signing in works, step by step
- The service asks for proof. When you choose to sign in with a passkey, the website or app sends your authenticator a fresh challenge.
- You approve the sign-in on your device. Your phone or computer may ask for a fingerprint, face scan, PIN, or another local unlock action. This authorizes use of the passkey; it is not your website password.
- Your authenticator answers the challenge. It uses the private key to create a cryptographic response. The private key itself stays with the authenticator.
- The service checks the response. It uses the public key it registered earlier. If the response is valid, the service signs you in.
This challenge-and-response process is a form of asymmetric cryptography: the service can verify a response without knowing or storing the private key. FIDO describes the process in its passkey FAQ.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why passkeys help against phishing
A passkey is associated with the app or website for which it was created. A lookalike phishing page cannot simply ask you to type the passkey into a form, because there is no reusable secret to type. The authenticator is designed to use the credential with the correct service. Passkeys also avoid password reuse: one service’s passkey is not a password to try on another site.
For passkey sign-ins, services do not store a password that an attacker could take from a password database. These protections reduce particular risks; they do not prevent every kind of account takeover. Your device, credential provider, recovery options, and the service’s own security still matter. See the FIDO Alliance’s explanation of passkey security.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What your fingerprint, face, or PIN does
Your biometric or PIN is generally a local way to authorize the authenticator to use the private key. It is not sent to the website as the passkey proof. The exact prompt depends on your device and provider. Microsoft says of its documented passkey flow, “Biometric data stays on your device and is never shared with Microsoft.” That statement describes Microsoft’s implementation; prompts and handling details can differ across platforms. Microsoft Support explains its passkey flow and options.
Where passkeys are stored: synced or device-bound
Passkeys can be stored in an operating-system or browser credential manager, such as iCloud Keychain or Google Password Manager, or in a third-party provider such as 1Password or Dashlane. A provider may sync passkeys to other devices where you use that provider. The service’s public key does not move with them; it is the private credential on your authenticator that must be available when you sign in. Which devices and browsers can use a passkey depends on the provider and account. The FIDO Alliance FAQ describes these provider options.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
A device-bound passkey stays with one authenticator, such as a FIDO security key, instead of syncing through a provider. This can suit someone who wants a separate physical authenticator, but the key’s availability and recovery arrangements need to be considered. FIDO says a security key can also serve as a recovery credential if you lose access to devices holding synced passkeys. Confirm that both the account and your devices support the security key’s protocol and connection type. FIDO’s passkey guidance covers security keys.
Using a phone passkey to sign in on a computer
If the passkey is not stored on the computer, a supported sign-in flow can let a nearby phone authorize the computer session. The computer displays a QR code; you scan it with the phone that has the passkey and approve the request. FIDO describes Bluetooth Low Energy as a way to check that the phone and computer are nearby. The sign-in also uses cryptographic protections, rather than relying only on Bluetooth security. Whether this option appears depends on the service, devices, and software involved. FIDO explains cross-device authentication.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What happens if you lose your phone?
The answer depends on where the passkey is stored and how that provider and account handle recovery. If it was synced, another device connected to the same provider may have access to it, subject to that provider’s recovery process. If it was device-bound and the device is gone, you may need another registered sign-in method or a recovery credential, such as a separately held security key.
Apple says iCloud Keychain passkeys are end-to-end encrypted and can be recovered even if a user loses all devices. That is an Apple-specific property, not a promise that applies to every passkey provider or website. Before relying on a passkey as your only sign-in route, understand the recovery options for both the credential provider and the account you use it with. Apple Support explains passkey security and iCloud Keychain recovery.
Recommended Free Tools
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
How widely are passkeys being used?
In an April 2026 Sapio Research online survey of 11,000 people across ten countries, 90% reported awareness of passkeys, 75% said they had enabled one on at least one account, and 49% said they used passkeys regularly when available. The reported margin of error was ±0.9 percentage points at 95% confidence. In a separate survey of 1,400 decision-makers at organizations with at least 500 employees across the same ten countries, 68% said their organization had deployed or was actively deploying passkeys for employee sign-ins; the reported margin of error was ±2.6 percentage points at 95% confidence. The FIDO Alliance also estimated five billion passkeys in use worldwide, combining publicly available data with its own deployment data; that figure is an estimate, not a direct global count. The FIDO Alliance published the figures on May 7, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




