PASS PHRASES / FIELD NOTE
Passkeys: Sign In Without a Shared Secret
Understand what a passkey changes, how devices unlock it, and why recovery still matters.
A Different Kind of Sign-In
A passkey uses a public/private key pair. The service holds the public key, while the private key is controlled by your authenticator or passkey provider. Sign-in proves possession without sending a reusable secret to the service.
Passkeys are bound to the intended website or app identity. This makes them resistant to ordinary credential-phishing pages that imitate a real sign-in. It does not make a stolen unlocked device, compromised account session or unsafe recovery process harmless.
Your PIN or Biometric Unlocks the Authenticator
A fingerprint, face check or device PIN commonly authorizes use of the passkey locally. The website does not receive that fingerprint or face template. The exact experience depends on your device, authenticator and service.
A passkey with user verification can satisfy multiple factors in one sign-in flow, depending on the service’s policy. You do not necessarily need a separate one-time code just because the flow feels simple.
Synced or Device-Bound?
Synced passkeys can be available across devices through a passkey provider. Protect the provider account and understand its recovery rules. Device-bound passkeys, such as those on some hardware security keys, stay with that authenticator; have a spare or another recovery route.
Neither model is automatically right for every situation. Consider which devices you use, whether an organization manages them, and what happens if one is lost.
Before You Remove the Old Sign-In
- Create a passkey using the genuine service’s account settings.
- Confirm the passkey works on the devices you expect to use.
- Register a second supported authenticator or prepare documented recovery.
- Secure the email account used for recovery.
- Only then consider removing an older method, following the service’s guidance.
Passkeys Are Not Your Wi-Fi Joining Phrase
Your router vendor may offer a passkey for its management account. That does not automatically change how a device joins WPA2/WPA3-Personal Wi-Fi. Network joining and account administration are separate security boundaries.