Passkey: What It Is and How to Choose the Right Setup

A passkey replaces passwords with biometric or PIN-based login using public-key cryptography. Learn how passkeys work and how to get started.

What is a Passkey?

A passkey is a passwordless authentication credential based on the FIDO2/WebAuthn standard. Instead of typing a password, you verify your identity with your device’s biometric sensor (fingerprint or face recognition) or a device PIN. Behind the scenes, passkeys use public-key cryptography: a private key stays locked inside your device’s secure hardware, while a public key is registered with the service. Because the private key never leaves your device and no shared secret travels over the network, passkeys are fundamentally resistant to phishing, credential stuffing, and brute-force attacks.

Apple, Google, and Microsoft have jointly committed to passkey support across their platforms, and the list of services that accept passkeys, including GitHub, Amazon, PayPal, and many others, is growing rapidly. Passkeys represent the most significant shift in consumer authentication in decades.

In-Depth

How Passkeys Work Under the Hood

When you register a passkey with a service, your device generates a cryptographic key pair. The private key is stored in a tamper-resistant area, such as Apple’s Secure Enclave or Google’s Titan M2 chip, where it cannot be extracted. The public key is sent to the service’s server. When you sign in, the server sends a random challenge; your device signs it with the private key, and the server verifies the signature with the public key. At no point does a password or secret token cross the network, which is why passkeys eliminate entire categories of attacks.

How Passkeys Differ from Passwords

Passwords are “shared secrets” stored on both the user’s side and the server’s side. If the server is breached, every password in its database is at risk. Passkeys are asymmetric: the server only holds the public key, which is useless to an attacker. This means that password reuse, phishing, and database leaks all become non-issues. A password manager makes password life easier, but a passkey removes the password concept entirely.

Syncing and Sharing Passkeys

Apple’s iCloud Keychain, Google Password Manager, and Microsoft accounts each provide passkey sync across devices within their ecosystem. If you use an iPhone and a Mac under the same Apple ID, your passkeys follow you automatically. For cross-platform use, third-party password managers like 1Password and Bitwarden can store and sync passkeys across Windows, macOS, Android, and iOS. You can also store passkeys on a hardware security key, which works independently of any specific device or ecosystem.

Passkeys and Enterprise Security

Passkeys are not just a consumer convenience; they are increasingly adopted by enterprises to secure employee accounts. Organizations face massive costs from password-reset helpdesk calls and credential-related breaches. Passkey adoption eliminates both problems. IT administrators can require passkey-only authentication for sensitive internal systems, removing the risk of employees falling for phishing emails. Many identity providers and single-sign-on platforms now support passkeys natively, making enterprise-wide rollout straightforward.

Limitations and Current Challenges

Despite their advantages, passkeys face some growing pains. Not all websites and apps support passkeys yet, so passwords remain necessary as a fallback in many places. Cross-platform passkey portability is improving but still imperfect; moving passkeys from one ecosystem to another (e.g., Apple to Android) requires a compatible password manager or manual re-registration. Users who are unfamiliar with the concept may find the setup process confusing at first. As adoption accelerates and user interfaces improve, these friction points are expected to diminish over the coming years.

How to Choose

1. Start with Services You Already Use

Google, Apple, Microsoft, GitHub, Amazon, and PayPal all support passkeys today. Begin by enabling passkeys on your most important accounts. You can keep password login as a fallback during the transition, so there is no risk of being locked out.

2. Understand the Sync Ecosystem

iCloud Keychain passkeys sync only among Apple devices. Google Password Manager covers Android and Chrome. If you work across multiple platforms, a cross-platform password manager that supports passkeys, such as 1Password or Bitwarden, provides the most seamless experience.

3. Prepare Recovery Options

If you lose every device that holds your passkeys, you will be locked out. Mitigate this risk by registering passkeys on multiple devices and keeping a backup hardware security key in a safe location. Some services also offer one-time recovery codes that should be printed and stored securely.

Passkeys and Accessibility

Passkeys improve accessibility for users who struggle with password management due to memory difficulties, motor impairments that make typing complex passwords challenging, or vision impairments that make reading CAPTCHA prompts difficult. Because passkey authentication relies on biometrics (a touch or glance) or a simple device PIN, it lowers the barrier to secure authentication for a broader range of users. As the technology matures, it has the potential to make strong security genuinely inclusive.

How Passkeys Work Alongside Existing Security

Passkeys do not require you to abandon your current security setup overnight. Most services allow passkeys and passwords to coexist, so you can enable a passkey while keeping your password and two-factor authentication active as a fallback. Over time, as you gain confidence in the passkey workflow and more services adopt the standard, you can gradually phase out passwords entirely. This transitional approach reduces the risk of lockouts and lets you adopt the technology at your own pace.

Passkeys are built into modern smartphones and computers at no cost, but hardware security keys extend passkey capability to cross-platform scenarios and provide a phishing-proof portable credential that does not depend on any single device ecosystem. The three picks below cover the best all-around hardware passkey key for cross-platform users, the best budget option for basic FIDO2 authentication, and a fingerprint-based key for users who authenticate frequently. See our hardware security key guide for full protocol details.

ProductHighlightsPrice Tier
YubiKey 5C NFCFIDO2 + passkey storage, USB-C + NFC, cross-platform, multi-protocolPremium
Yubico Security Key C NFCFIDO2/U2F, USB-C + NFC, iOS + Android + desktop, budgetBudget
YubiKey Bio-C EditionFIDO2 + fingerprint sensor, USB-C, no PIN needed, passwordlessPremium

YubiKey 5C NFC — Best Hardware Passkey Key for Cross-Platform Users

The YubiKey 5C NFC is the recommended hardware passkey storage device for users who work across multiple ecosystems — Windows laptops, macOS, Android, and iOS — and want a single portable credential not tied to Apple Keychain, Google Password Manager, or any specific platform. It stores FIDO2 passkeys directly on the key’s secure element, meaning your passkeys are available on any device by simply inserting (USB-C) or tapping (NFC) the key. Unlike platform-synced passkeys, these credentials do not require an internet connection to authenticate and are not vulnerable to cloud account compromise. Beyond passkeys, the YubiKey 5C NFC also supports TOTP/HOTP one-time passwords, PIV smart-card authentication, and OpenPGP, making it useful for developer, enterprise, and advanced security workflows. Always buy and register two keys: one to carry daily and one stored safely as a backup. For anyone who wants passkey functionality that works identically on every device and operating system they own, the YubiKey 5C NFC is the definitive choice.

View on Amazon

Yubico Security Key C NFC — Best Budget FIDO2 Key for Passkey Use

The Yubico Security Key C NFC delivers the essential FIDO2/WebAuthn authentication that underpins passkeys, at significantly less cost than the YubiKey 5 series. It supports passkey storage and FIDO2 authentication on the same services as the premium model: Google, Microsoft, GitHub, Amazon, and thousands of FIDO2-compatible sites and apps. USB-C connectivity works directly with modern laptops, and the NFC radio enables tap authentication on iOS (iPhone 7+) and Android phones. The trade-off compared to the 5C NFC is the absence of enterprise protocols — no TOTP, no PIV, no OpenPGP — which makes it unsuitable for advanced security workflows but perfectly adequate for consumer passkey use. As with all hardware keys, buy two for redundancy. For users whose primary goal is phishing-resistant passkey authentication on personal accounts and who do not need enterprise protocol support, the Security Key C NFC provides the same core protection at a lower price.

View on Amazon

YubiKey Bio-C Edition — Best Biometric Key for Frequent Passkey Authentication

The YubiKey Bio-C Edition adds a fingerprint sensor directly on the key, making passkey authentication seamless for users who authenticate many times per day. Instead of entering a PIN at each authentication event, you insert the USB-C key and touch the fingerprint sensor — verification completes in under a second. Up to five fingerprints can be enrolled, and all biometric data is stored exclusively on the key’s secure element; it never leaves the device or transmits over the network. The key supports FIDO2 passkeys and FIDO U2F authentication across Windows, macOS, and Linux over USB-C. The primary limitations are the absence of NFC (no phone tap authentication) and the lack of OTP, PIV, and OpenPGP support compared to the 5C NFC. For developers, IT professionals, and power users who access multiple accounts dozens of times daily and want frictionless passkey authentication without repeatedly entering a PIN, the biometric convenience of the Bio-C Edition justifies the premium over the non-biometric models.

View on Amazon

See Hardware Security Key Guide →

## The Bottom Line

Passkeys are the most promising replacement for passwords the industry has ever produced. They combine strong phishing resistance with a user experience that is actually easier than typing a password, since a fingerprint scan or face unlock is all it takes. As support spreads across major platforms and services, now is the time to start enabling passkeys wherever you can. Set up sync across your devices, keep a backup recovery method ready, and you will be well on your way to a password-free future.