
What Is a Passkey? How It Works as Password Alternative, Safety
If you’ve been hearing whispers about passkeys but aren’t quite sure what all the fuss is about, you’re not alone. Passwords have been the gatekeepers of our digital lives for decades, and swapping them out for something more secure sounds almost too good to be true. The good news is that major organizations—Google, Microsoft, and even the UK’s own National Cyber Security Centre—are now actively pushing passkeys as the default way to sign in. Here’s what that means for you.
Alternative to: passwords · Uses: public key cryptography · Authentication: biometrics or screen lock · Managed by: device software · Supported by: Google, Microsoft
Quick snapshot
- Passkeys use public-key cryptography (NCSC Blog)
- Up to 8× faster than password+2SV login (NCSC)
- Phishing-resistant by design (Microsoft Support)
- Full cross-platform adoption timeline
- Exact recovery process if all devices lost
- Enterprise vs consumer implementation differences
- Google default: 2023 (Infosecurity Magazine)
- Apple introduction: 2024 (Infosecurity Magazine)
- Microsoft consumer rollout: 2025 (Infosecurity Magazine)
- NCSC endorsement: 2026-04-23 (The Register)
- Passwords should not be used where passkeys are available (NCSC News)
- UK leads global adoption with >50% of Google users registered (NCSC News)
- Government services like NHS App adopting passkeys (NCSC News)
| Field | Detail |
|---|---|
| Definition | Secure password alternative using device biometrics |
| Standard | FIDO-based public key cryptography |
| Primary Use | Passwordless sign-in |
| Top Sources | NCSC, Google Safety, Microsoft |
| UK Adoption | >50% of Google users registered at least one passkey (ITPro) |
| Speed Advantage | Up to 8 times faster than password+2SV |
What is a passkey and how does it work?
A passkey is a passwordless login technology that relies on public-key cryptography rather than remembered secrets. When you create a passkey, your device generates a pair of cryptographic keys: a private key that stays on your device and a public key that gets stored by the website or service you’re signing into. The private key never leaves your device—during login, you authenticate with your fingerprint, face scan, or PIN, and your device proves possession of the private key without transmitting it anywhere.
Public key cryptography basics
The mathematics behind passkeys aren’t new—cryptographers have used public-private key pairs for decades to secure communications. What makes passkeys practical for everyday login is how the process has been simplified. According to the NCSC Blog, passkeys use an authenticator to generate these key pairs without any secrets ever being shared between your device and the website. This means even if a service’s database is breached, attackers only get the public key, which is useless without its matching private key sitting safely in your device.
Device-based authentication
Credential managers like Apple Passwords, Google Password Manager, and Microsoft Password Manager handle the creation, storage, and syncing of passkeys across your devices. Per NCSC guidance, passkeys can be stored on your devices or physical security keys, giving you flexibility in how you manage authentication. The key advantage is that you no longer need to remember complex passwords—your device handles that burden while keeping your credentials private and secure.
What is an example of a passkey?
The easiest way to understand passkeys is to see them in action. When you sign into your Google Account on a new device, instead of typing a password and waiting for a verification code, you might see a prompt asking you to use your fingerprint or confirm with your phone’s screen lock. That’s a passkey in practice—your device proves it holds the private key linked to your Google account, and you’re logged in within seconds.
Real-world usage scenarios
Google made passkeys the default sign-in option in 2023, and since then adoption has climbed steadily. According to ITPro reporting, over 50% of UK Google users have registered at least one passkey. Microsoft followed suit in 2025, making passkeys available to all consumer accounts and reporting that their passkey updates reduced password use by over 20% in experiments. The pattern across both platforms is the same: you set up a passkey once, then sign in faster on every subsequent visit.
Passkeys eliminate the need to remember credentials and are significantly faster than traditional login methods. Over 9 million Google Workspace customers already use passkeys, according to Google’s Safety Center.
What are the downsides of passkeys?
Passkeys aren’t perfect, and understanding their limitations helps you make informed decisions about when to adopt them. The most significant trade-off is device dependency. If your phone dies, your laptop is in for repair, or you need to sign in on a friend’s computer, you may face friction without backup options set up in advance. Recovery processes—getting back into an account when you’ve lost all your devices—remain less standardized than password recovery flows.
Potential limitations
Platform support varies. While major services like Google, Microsoft, PayPal, and eBay support passkeys, not every website has implemented them yet. Per Computer Weekly, implementation challenges held back broader endorsement until recently, when cross-platform syncing between Android and iOS improved substantially. Some enterprise environments also lag behind consumer services in rolling out passkey support.
Compatibility issues
Your passkey experience depends heavily on which devices and browsers you use. Passkeys sync via cloud accounts—Microsoft Password Manager for Microsoft ecosystems, iCloud Keychain for Apple devices—but the experience can differ between platforms. Shared accounts or family devices present complications too, since passkeys are typically tied to individual user profiles rather than household-level authentication.
Device loss without proper backup creates account recovery headaches. Set up multiple authentication methods before you need them—the NCSC advises using password plus two-step verification with a manager where passkeys aren’t yet available.
Are passkeys safe?
Security experts have answered this question clearly. The NCSC’s technical report from April 2026 concludes that passkeys are at least as secure as, and generally more secure than, pairing the strongest password with two-step verification. That’s a significant statement from an organization that spent years cautioning against premature adoption.
Security benefits
Passkeys are inherently phishing-resistant because they are bound to specific domains. As Microsoft Support explains, your passkey will only work on the legitimate website—it can’t be tricked into authenticating a fake login page. Traditional passwords, by contrast, can be captured and replayed on phishing sites with alarming ease. Google passkeys stay private on the device entirely, with no central database storing credentials that could be breached.
Known risks
No security measure is bulletproof. Passkeys tied to a single device create a physical security dependency—if someone gains access to your unlocked device, they may be able to authenticate as you. Screen lock protection mitigates this significantly, but the threat model differs from passwords, where a stolen password requires knowledge rather than physical access. Additionally, cloud-synced passkeys introduce a new attack surface: whoever controls your iCloud or Microsoft account controls your passkeys.
NCSC states passkeys are always as secure or more secure than passwords plus two-step verification. The trade-off shifts from “can my password be guessed?” to “can my device or cloud account be compromised?”
How do I obtain a passkey?
Setting up your first passkey is straightforward, though the exact steps depend on which service you’re adding it to. Most major platforms now guide you through the process when you sign in or visit your account security settings. The general flow involves navigating to the passkey option, confirming with your biometric or PIN, and confirming that the passkey should be saved to your credential manager.
Creating on Google
To create a passkey for your Google Account, sign in and navigate to your account security settings. Look for “Passkeys” in the sign-in options section. Google offers an option to use your phone’s screen lock or a physical security key. Once created, your passkey syncs to your Google account, making it available across your devices signed into the same account. Per Google’s Safety Center, passkeys can be stored on devices or physical security keys.
Managing in Chrome
Chrome manages passkeys through your Google account on desktop and through your device’s credential manager on mobile. You can view and delete saved passkeys in Chrome settings under passwords and passkeys. Apple users will find passkeys in their device settings under Passwords or Security, where they can manage individual passkeys and choose whether to sync them via iCloud.
The NHS App is among the first government applications using passkeys for patient access, per Computer Weekly. Expect more public services to follow as government adoption grows.
Upsides
- More secure than passwords plus 2SV per NCSC
- Phishing-resistant by design
- Up to 8× faster login than traditional methods
- No passwords to remember or reuse
- Endorsed by Google, Microsoft, Apple, and NCSC
- Reduces provider costs by replacing SMS verification
Downsides
- Device dependency—if you lose all devices, recovery can be difficult
- Limited platform and website support compared to passwords
- Recovery processes less standardized than password flows
- Cross-platform syncing varies between ecosystems
- Shared accounts or family devices create complications
- Cloud-synced passkeys introduce account takeover risk
How to set up your first passkey
Getting started with passkeys takes less than five minutes for most users. Here’s the practical walkthrough for the two most common platforms.
- For Google Accounts: Sign in at myaccount.google.com, select “Security” from the left menu, scroll to “Passkeys” under “How you sign in to Google,” and click “Create a passkey.” Confirm with your device’s biometric or PIN when prompted.
- For Microsoft Accounts: Sign in at account.microsoft.com, navigate to “Security,” select “Passwordless account,” and follow the prompts to enable passkeys. Your Microsoft passkey will sync via Microsoft Authenticator or Windows Hello.
- For Apple devices: Enable iCloud Keychain in Settings > Passwords, then navigate to any supporting website and look for the passkey option when signing in. Your passkey saves to iCloud Keychain automatically.
- Set up backup options: Add multiple devices and ensure your cloud account recovery options are current. This prevents lockout if your primary device fails.
The FIDO Alliance notes that Apple, Google, and Microsoft are collectively pushing passkeys as the passwordless future. Microsoft’s Security Blog reported that their passkey updates reduced password use by over 20% in experiments—numbers that demonstrate real-world momentum behind the technology.
“Passkeys are at least as secure as, and generally more secure than, pairing the strongest password with two-step verification.”
— NCSC News (National Cyber Security Centre)
“Passwords should not be used where passkeys are available.”
— The Register (NCSC guidance)
Summary
Passkeys have crossed the threshold from promising experiment to officially recommended standard. The NCSC’s April 2026 endorsement is the clearest signal yet that passwords should no longer be the default choice where passkeys are available. Major platforms have already made the switch—Google, Apple, and Microsoft have collectively woven passkeys into their ecosystems, and adoption is climbing. The question for most users isn’t whether passkeys are safe; they demonstrably are. The practical question is whether you’ve set up backup authentication before you need it.
Related reading: reverse proxy · secured credit card
Passkeys represent a shift to passwordless authentication using asymmetric cryptography, as the detailed German passkey guide thoroughly outlines for German readers.
Frequently asked questions
What is a passkey on Google?
A Google passkey is a credential tied to your Google Account that lets you sign in using your device’s biometric or screen lock instead of a password. Google made passkeys the default sign-in option in 2023, and over 50% of UK Google users have registered at least one.
What is a passkey on a computer?
On a computer, a passkey is a credential stored either in your browser or operating system’s credential manager. On Windows, passkeys sync via Microsoft Authenticator or Windows Hello. On Mac, passkeys sync via iCloud Keychain. You sign in by confirming with your biometric or device PIN.
What is a passkey on a phone?
On a phone, a passkey is stored in your device’s secure enclave and typically managed through the operating system’s credential manager—Apple Passwords on iOS, Google Password Manager on Android. Authentication happens via fingerprint, face scan, or screen lock PIN.
What is a passkey password?
“Passkey password” is a misnomer—passkeys don’t use passwords at all. A passkey uses public-key cryptography with a private key stored on your device and a public key stored by the service. You authenticate with biometrics or a PIN, not a typed password.
What is a passkey for Outlook?
A passkey for Outlook works through your Microsoft Account. Microsoft made passkeys available to all consumer accounts in 2025, and you can set one up through your Microsoft account security settings. The passkey syncs across your devices via Microsoft Password Manager.
What is a passkey for Amazon?
Amazon supports passkeys as an alternative to password login. You can set up an Amazon passkey through your account’s Login Settings. The passkey allows you to sign in using your device’s biometric or screen lock rather than entering your Amazon password.
What is a passkey PIN?
A passkey doesn’t require a separate PIN—instead, you use your device’s existing screen lock PIN, fingerprint, or face scan to authenticate. The device proves possession of the private key without transmitting it, so there’s no need for a separate passkey-specific PIN.
Where do I find my passkey?
You don’t “find” a passkey like you might find a saved password. Passkeys live in your device’s secure storage and are managed through your operating system’s credential manager or platform-specific apps like Google Password Manager, Apple Passwords, or Microsoft Authenticator.