For decades, usernames and passwords have been the standard way to prove our identity online. But as phishing attacks become more sophisticated and data breaches become increasingly common, relying on passwords alone is no longer enough. Passkeys are a relatively new sign-in method designed to gradually replace traditional passwords, allowing you to log in securely without having to remember a password.
What Are Passkeys?
Passkeys are a modern sign-in method that replaces the traditional username-and-password combination with a more secure and convenient way to access your online accounts.
Instead of typing a password that could be stolen, leaked, or guessed, you simply use your phone, computer, or a physical security key to verify your identity. In most cases, authentication happens using your fingerprint, facial recognition, or your device's PIN—the same method you already use to unlock your device.

Under the hood, passkeys are built on the FIDO2 standard, which combines WebAuthn (the W3C web authentication standard) and CTAP (the FIDO Alliance protocol for communication with authenticators). Backed by major companies including Google, Microsoft, and Apple, this open standard ensures broad compatibility across operating systems, web browsers, and devices.
How Do Passkeys Work?
When you create a passkey for a website or app, your device generates a unique pair of cryptographic keys: a public key and a private key.
The public key is sent to the service and stored on its servers, while the private key never leaves your device. It remains securely encrypted and is never shared with the website, the app, or any remote server.
The next time you sign in, the service sends a unique cryptographic challenge to your device. After you confirm your identity using your fingerprint, face, or device PIN, your device uses the private key to digitally sign the challenge. The service then verifies that signature with the matching public key it already has on file. If everything checks out, you're signed in.

Because the private key never leaves your device, there's no password—or other shared secret—for attackers to steal from the server. That makes passkeys inherently resistant to phishing attacks and significantly reduces the risk posed by data breaches.
Why Are Passkeys More Secure than Passwords?
Passkeys address many of the biggest security weaknesses associated with traditional passwords, making online accounts significantly harder to compromise.
They are inherently resistant to phishing attacks. Every passkey is cryptographically bound to the specific website or app where it was created. Even if you're tricked into visiting a convincing fake login page, your passkey simply won't work because the domain doesn't match the original site.
They also dramatically reduce the impact of data breaches. If a company's servers are compromised, attackers can only obtain public keys, which are useless without the corresponding private keys that remain securely stored on users' devices. There are no reusable passwords or shared secrets for attackers to steal.
Another major advantage is that there's nothing to remember—or reuse. Password reuse remains one of the leading causes of account compromise, allowing attackers to exploit stolen credentials across multiple services. Because every passkey is unique to a single account and website, this entire class of attacks effectively disappears.

Finally, passkeys can provide phishing-resistant authentication by combining something you have (your device) with something you are or know (your fingerprint, face, or device PIN). That said, some services may still require an additional verification step for specific situations, such as signing in from a new device or confirming sensitive account changes.
What Do You Need to Use Passkeys?
Getting started with passkeys is relatively simple. You only need a compatible device, a supported browser, and an account with a service that offers passkey authentication.
You need a device such as a smartphone, tablet, or computer running a supported operating system, including Android 9 or later, iOS/iPadOS 16 or later, Windows 10 (version 21H2 or newer), Windows 11, or macOS Ventura or newer. Alternatively, if you prefer a solution that isn't tied to a specific device, you can use a physical security key, such as a YubiKey or another FIDO-compatible security key.
You also need a browser that supports WebAuthn, the web standard that enables passkey authentication. Most modern browsers, including the latest versions of Chrome, Edge, Firefox, and Safari, support this technology.
Finally, you need an account with an online service that supports passkeys. Many major platforms have already added support, and adoption continues to grow as more companies move away from traditional password-based authentication.
How to Create a Passkey
The process is almost identical across most services. Let's take a look at how to set up a passkey on two popular platforms: Google and Microsoft.
Google:
- Go to g.co/passkeys and select Create a passkey.
- Under Passkeys and security keys, choose Create a passkey, then confirm your choice in the pop-up window.
- Follow the on-screen instructions to complete the setup. The exact steps vary depending on where you want to store your passkey: on your Windows device, your smartphone, or a password manager.

Microsoft:
- Go to account.microsoft.com and open Security.
- Select Manage how I sign in.
- Under Ways to prove who you are, choose Add a new way to sign in or verify > Face, fingerprint, PIN, or security key.
- Follow the instructions to create your passkey. The available options depend on where you want to store it, such as your Windows device, smartphone, or a password manager.
How to Sign In With Passkeys
Signing in with a passkey is extremely straightforward and eliminates the need to enter a password every time.
- Go to the service's sign-in page.
- Instead of entering your password, select Sign in with a passkey.
- Your device will ask you to confirm your identity using your fingerprint, Face ID, Windows Hello, or device PIN. Once verified, you're signed in instantly—without typing a password.
Passkeys in browsers
In addition to being stored on operating systems, passkeys can also be stored directly in a browser's built-in password manager, independently of the device you're using. This is useful if you don't want to be tied to a specific operating system.
Google Chrome: Chrome allows you to save passkeys in Google Password Manager, which can sync them across your devices when you're signed in to the same Google account. This means you can access your passkeys on other supported devices without having to create them again.
Microsoft Edge: Microsoft Edge uses Microsoft Password Manager to store and sync passkeys through your Microsoft account, offering a similar experience to Chrome's integration with Google Password Manager.
Passkeys in third-party password managers
Many users prefer not to rely entirely on a single company's ecosystem, so they choose independent password managers, such as Bitwarden or NordPass, to store and manage their credentials. Both services support passkey management, allowing users to keep their authentication credentials alongside their other sensitive data. (bitwarden.com ; nordpass.com )

The biggest advantage of this approach is portability. Passkeys stored in a third-party password manager can be used across different platforms, whether you are on Windows, macOS, Android, or iPhone, without being locked into a single operating system ecosystem.
The setup process is similar across operating systems:
- Install your password manager's browser extension.
- Set it as the default passkey provider through your browser or operating system settings.
- When creating a new passkey for a supported service, choose your password manager as the storage location. The passkey will then be available across your supported devices.
If you ever switch from Android to iPhone, or from Windows to Mac, your passkeys will still be available through your password manager without requiring any manual transfer or migration.
Passkeys in Mobile Apps
So far, we've mainly focused on signing in to websites through a browser. However, passkeys are now supported directly within mobile apps as well, providing the same passwordless authentication experience.
The process works much the same way as it does on websites. Instead of entering a password inside the app, you simply choose Sign in with a passkey and confirm your identity using your fingerprint, Face ID, or device PIN.
The app communicates with your device's passkey provider, such as Google Password Manager on Android, iCloud Keychain on iOS, or a third-party password manager. If the required passkey has already been created—either through a browser or another app from the same service—it will be available automatically.
This means you don't need to create a separate passkey for a website and another one for the mobile app of the same service. Once you create it, the same passkey can be used in both places, as long as it is stored in the passkey manager connected to your device or account.

What is Cross-Device Sign-in?
Cross-device sign-in allows you to use your phone as a "key" to sign in to a browser on a completely different device, without needing to store the passkey on that device. without needing to have the passkey stored on that device. This feature is part of the FIDO cross-device authentication flow, which allows a passkey stored on one device to be used for authentication on another device through a QR code-based process.
This is particularly useful when signing in on a device where you don't want to store your passkey, such as a work computer or a computer in a public library. It is also helpful when signing in across different ecosystems—for example, using a passkey stored on an iPhone to authenticate on a Windows PC.
To sign in using this method:
- On the sign-in page, select Sign in with a passkey or Use another device.
- A QR code will appear on the screen. Scan it with your phone, where your passkey is already stored.
- Your phone will ask you to verify your identity using your fingerprint, Face ID, or PIN. Once confirmed, the computer will complete the sign-in process without ever transferring the actual passkey away from your phone.
The connection between the two devices uses Bluetooth Low Energy (BLE) to verify that they are physically close to each other. This proximity check adds an extra layer of security and helps prevent someone from using a captured QR code remotely from another location.
What Happens If You Lose or Replace Your Device?
Because passkeys are usually synced through your account (such as a Google, Apple, or Microsoft account), switching to a new device is usually straightforward. Simply sign in with the same account, and your passkeys will become available on the new device.

If you lose your device, there's generally no reason to panic. A thief cannot simply use your passkeys, because they are protected by your device's security features, such as your fingerprint, face recognition, or PIN. Without unlocking the device or accessing your passkey provider account, the stored credentials cannot be used.
However, it is still a good practice to keep an alternative recovery method available for every important account, such as a recovery code or another supported verification option. This provides an additional safety net in case you lose access to both your device and your passkey provider.
Which Services Support Passkeys?
The number of services supporting passkeys continues to grow rapidly. Major platforms that already offer passkey authentication include Google, Microsoft, Apple, Amazon, PayPal, GitHub, and WhatsApp (in supported versions and regions).
To check whether a specific website or app supports Ppsskeys, you can visit passkeys.directory, a community-maintained directory that tracks services offering passwordless sign-in and is regularly updated with new additions.
Would you trust Passkeys instead of passwords?
Would you trust passkeys as your primary way to sign in, or do you still prefer traditional passwords?
Support PCsteps
Do you want to support PCsteps, so we can post high quality articles throughout the week?
You can like our Facebook page, share this post with your friends, and select our affiliate links for your purchases on Amazon.com or Newegg.
If you prefer your purchases from China, we are affiliated with the largest international e-shops:

