What are passkeys, and will they replace passwords?

What are passkeys and how do they work? A plain guide to passkeys vs passwords, phishing resistance, syncing, losing your phone and what passkeys can't replace.

A capybara at the front door of a cozy house presses its paw on a small fingerprint pad beside the lock while holding a glowing phone, as a ring of old keys hangs unused on a hook by the door.
On this page

What are passkeys? A passkey is a way to sign in without a password. It is a pair of cryptographic keys: a private key that stays on your phone, computer or password manager, and a public key that the website keeps. You unlock it with your fingerprint, face or device PIN, and because it only works on the real website, a fake site cannot trick you into handing it over.

Below: how passkeys work in plain words, why they resist phishing, what happens if you lose your phone, their honest downsides, and one nuance most guides skip: why signing in with a passkey is not the same as unlocking end-to-end encrypted data.

What are passkeys? The short answer

A passkey replaces the password you type with a secret your device keeps and never reveals. When you create one, your device makes two matching keys:

  • The private key stays with you: in your phone, your computer, a password manager or a hardware security key.
  • The public key goes to the website, which files it with your account.
Public-key cryptography
A system with two linked keys. The private key can create a digital signature; the public key can only check it. Think of a wax seal: only you own the seal, but anyone holding a picture of it can tell a real impression from a fake. Nobody can carve a new seal from the picture.

Passkeys are built on open standards from the FIDO Alliance and the W3C's WebAuthn specification, so the same passkey works across browsers and operating systems that support them. The UK's National Cyber Security Centre recommends choosing passkeys over passwords wherever they are available.

How do passkeys work?

Signing in with a passkey is a short conversation between the website and your device:

Website

Sends a random challenge that is valid for this sign-in only.

challenge

Your device

Checks which site is asking. You confirm with a fingerprint, face or PIN, and the private key signs the challenge.

signature

Website

Checks the signature with your public key. If it matches, you are in.

Signing in with a passkey. The site sends a fresh challenge, your device signs it after you confirm, and the site checks the signature with the public key it stored. No secret crosses the network.

Two details make this safer than a password:

  1. Your fingerprint or face never leaves the device. It only tells your own phone or computer to use the private key. Google states that biometric data used for passkeys stays on your device and is never shared with Google.
  2. Every sign-in is different. The challenge is new each time, so a recorded signature is useless for the next sign-in.

Why passkeys resist phishing

A phishing site works by looking like the real one. You type your password into examp1e-login.com, and the criminal replays it on the real site. SMS codes and app codes can be phished the same way, because you type them in too.

A passkey is tied to the website's domain when it is created. Your browser tells the device which domain is asking, and the device will only use the passkey made for that exact domain. On a look-alike address, the passkey simply does not appear, and there is nothing for you to type. The U.S. NIST digital identity guidelines (SP 800-63B-4) call this "verifier name binding" and count it as a form of phishing resistance.

Phishing resistance is not the same as being unhackable, though. Malware on your computer can steal the session after you sign in, a scammer can talk you into using a weaker fallback such as an SMS code, and anyone who can unlock your device can use the passkeys on it. Google warns about exactly that last point: create passkeys only on devices you own.

Passkeys vs passwords: what a data breach leaks

When a website with passwords is breached, attackers get password hashes they can try to crack offline, and every cracked password is then tried on other sites. Our article on AI and password cracking shows how that works. When a website with passkeys is breached, attackers get public keys. A public key cannot sign anything, so it is useless for signing in, and there is nothing to crack.

Password

  • You create it, so it can be weak or reused
  • The site stores a hash that can be cracked after a breach
  • You can type it into a fake site
  • Needs a second factor to resist phishing, and many second factors can be phished too

Passkey

  • Your device creates it; it is unique to each site
  • The site stores only a public key, which is useless to a thief
  • Only works on the domain it was made for
  • Combines something you have (the device) with your fingerprint, face or PIN

Synced and device-bound passkeys

There are two kinds of passkeys, and the difference matters when something goes wrong.

Synced passkeys are copied, encrypted, across your devices by a provider:

  • Apple syncs passkeys through iCloud Keychain, which Apple describes as end-to-end encrypted with keys Apple does not know.
  • Google saves passkeys in Google Password Manager and, since September 2024, syncs them between Android and Chrome on Windows, macOS and Linux, end-to-end encrypted with the help of a Google Password Manager PIN.
  • Microsoft added passkey saving and syncing to its password manager in Edge in November 2025, starting on Windows.
  • Password managers such as 1Password, Bitwarden and Dashlane store passkeys in your vault, so they work on every platform the manager supports.

Device-bound passkeys never leave one piece of hardware, typically a USB or NFC security key. They are the strictest option: NIST allows synced passkeys for most everyday accounts but not at its highest assurance level, where the key must not be copyable. The cost is that a lost security key is a lost passkey, so you need a spare.

Signing in on another computer with your phone

You can use a passkey stored on your phone to sign in on a computer that has none. The computer shows a QR code, you scan it with the phone and confirm with your fingerprint or PIN. Bluetooth has to be on, because the phone and computer check that they are physically close to each other. That stops a criminal from sending you a QR code from the other side of the world.

What happens if you lose your phone?

It depends on where your passkeys live.

  • Synced passkeys are still on your other devices. If you lose every device, the provider's recovery process takes over. Apple, for example, recovers iCloud Keychain with your Apple Account password, a text message to your registered phone number and your device passcode, and it destroys the escrowed copy after 10 failed attempts (Apple). On a new device, Google asks for your Google Password Manager PIN or the screen lock of an old Android device.
  • Device-bound passkeys are gone with the device. Register a second security key as a backup.
  • In both cases, remove the lost device's passkeys from your account settings, since anyone who can unlock the device could use them.

Are passkeys safe? The honest downsides

Passkeys are a clear step up from passwords, but they are not finished.

  • Moving between providers is still awkward. The FIDO Alliance is standardizing how to transfer passkeys securely. As of September 2026, its Credential Exchange Format is a Proposed Standard, while the matching Credential Exchange Protocol is still a working draft. Apple's systems since iOS 26 and macOS 26 can already move passwords and passkeys between supporting apps on the same device, and Android offers app makers a similar same-device transfer.
  • Recovery often falls back to weaker methods. Many services still let you recover an account with an email link or SMS code. If that path is easy to abuse, it is the new weakest link.
  • Passwords are not gone. Many sites that offer passkeys still keep a password as well, and a passkey cannot protect the password you did not remove.
  • Support varies. Not every site, browser or device handles passkeys the same way yet.

Adoption is growing quickly. In May 2026 the FIDO Alliance reported an estimated 5 billion passkeys in use. In its survey of 11,000 consumers in ten countries (conducted by Sapio Research in April 2026), 75% said they had turned on a passkey for at least one account, and 49% said they use passkeys regularly when available. These are the FIDO Alliance's own figures, and the alliance promotes passkeys.

Will passkeys replace passwords?

For signing in to everyday websites, passkeys are steadily taking over, and the NCSC advice is simple: use them where you can. Passwords will stay around for years, though, as fallbacks, for sites that have not switched, and for one job passkeys do not do on their own: unlocking encrypted data.

Passkeys and end-to-end encryption: sign-in is only half the job

In an end-to-end encrypted app, your data is locked with a key that the service never has. That key has to come from somewhere only you control, which is why most such apps derive it from a master password (our guide to end-to-end encrypted notes explains the idea).

A normal passkey sign-in does not provide such a secret. The device signs a challenge and the website checks the signature. That proves who you are, but the app gets nothing it could turn into a decryption key.

WebAuthn has an optional add-on for this, the PRF extension. With it, the authenticator computes a secret value that is tied to one passkey and never stored by the website, and the app can turn that value into an encryption key. Bitwarden, for example, documents passkey sign-in that also unlocks the vault when the passkey, browser and device support PRF; otherwise you unlock the vault another way, such as with the master password. Support depends on the browser, the device and the passkey provider.

Does Cappa support passkeys?

No. As of September 2026, Cappa has no passkey sign-in and no second sign-in factor. One master password does both jobs: it signs you in and it is the source of the key that unlocks your vault. Your browser runs it through Argon2id and derives two separate keys: one proves your identity to the server, the other unlocks your notes and never leaves your device. The server never receives the password itself.

The downside is the one this article is about: anyone who phishes your master password gets both your sign-in and your notes. Until something else is in place, your protection is:

  1. A long random master password: 16 or more random characters or six random words. Our master password guide shows the math.
  2. A password manager to store and fill it. It fills the password only on the site where you saved it, which gives you some of the domain checking a passkey would.
  3. Your recovery code, kept safe and separate, because nobody can reset a forgotten master password for you. See our recovery code guide.

For what encryption can and cannot protect you from, read the limits of encryption.

FAQ

Are passkeys safer than passwords?

Yes, for most people. A passkey cannot be guessed, reused on another site or typed into a phishing page, and a breach of the website leaks only public keys. The remaining risks are around your device and the account that syncs your passkeys, so protect those well.

Can a passkey be hacked or stolen?

The private key is not sent to websites, so it cannot be phished or leaked from a site's database. Someone could still use your passkeys if they can unlock your device or take over the account that syncs them, and malware can steal a session after you sign in. Keep your devices locked and updated.

What happens to my passkeys if I lose my phone?

Synced passkeys remain on your other devices and can be restored through your provider's recovery process. Passkeys on a single security key are lost with it, so register a backup key. In either case, remove the lost device from your accounts.

Do I still need a password manager if I use passkeys?

Probably, yes. Many sites still need passwords, and a good password manager stores passkeys too, which makes them available on all your devices. It also keeps the unique random passwords you need for everything that does not support passkeys yet.

Is a passkey the same as two-factor authentication?

Not exactly, but it covers similar ground. A passkey combines something you have (the device holding the key) with something you are or know (your fingerprint, face or PIN), so many services accept it on its own instead of a password plus a code.

Written by the Cappa team

We build Cappa, a private Markdown notes app that encrypts your notes on your device before they are synced. We write about the decisions behind it, including the limits, so you can judge them yourself.