In 60 seconds
- A passkey lets your device prove possession of a private key without sending it to the website.
- Face or fingerprint checks normally unlock the credential on the device; the biometric template is not sent to the site.
- Before switching devices, confirm sync, recovery, and an alternative sign-in method.
How a passkey differs from a password
A service stores a public key while the matching private key remains under the user's control. Signing in asks the device to approve a cryptographic challenge. There is no reusable password secret for the website to receive or for a fake login page to collect.
Passkeys are bound to the legitimate domain, which makes them resistant to common phishing flows. A screen lock, PIN, fingerprint, or face check authorizes use of the credential locally.
Plan recovery before you rely on it
Some passkeys sync through a platform account; others may stay on one device or security key. The exact recovery model therefore depends on the provider and how the passkey was created.
Keep your platform recovery details current, register a second trusted device or security key when appropriate, and confirm whether the service retains another sign-in option before replacing a phone or computer.
Quick checklist
Create passkeys only on the genuine service domain
Confirm whether the credential syncs across devices
Keep account recovery details current
Register a backup sign-in method before replacing a device
What is confirmed — and what needs caution
- Passkeys are based on public-key credentials and FIDO standards.
- The service stores a public key, not the user's private key or biometric template.
- Do not create a personal passkey on a shared public device.
- Recovery and synchronization behavior differs by platform and service.
Primary sources
01Issueureum summarizes public source material in its own words. Product names belong to their respective owners. Check the linked official source for current details.