Passkeys are replacing passwords, and they are faster to use and more secure. If you take nothing else away from this article: when a website offers to create a passkey on a personal device or in a password manager you trust, say yes. It’s both easier than a password and more resistant to phishing. If you want to understand how passkeys work and why they matter, read on.
Summary
-
Passkeys replace passwords with something safer that you never have to remember
-
They work with Face ID, Touch ID, or your device passcode, so signing in is faster and much harder to fake
-
Apple can sync your passkeys across approved devices through iCloud Keychain
-
Passkeys are phishing-resistant by design because they work only with the real website or app they were created for
-
Many major websites already support them, including Google, Amazon, and Apple
A client of mine was doing everything right. He had app-based two-factor authentication on his account: the kind where you open an authenticator app and type in a six-digit code. But the phishing site he landed on wasn’t just collecting his password. It was passing his credentials to the real site in real time and relaying the 2FA code before it expired. His account was compromised anyway, despite doing exactly what he was supposed to do.
Passkeys are resistant to that kind of attack. A fake website cannot ask your passkey to approve a sign-in for the real website, so there is no password or temporary code for the scammer to relay. Whether you’ve never heard of passkeys or aren’t quite sure what they are, this is your guide.
What is a passkey, exactly?
Think of a passkey as a key that’s been cut in two. One half is public and is stored by the website. The private half stays under the protection of your device or password manager and is never handed to the website. When you sign in, your device uses its half to prove that it matches the website’s half without revealing the private key itself.
There is no account password for you to remember or enter during a passkey sign-in. You look at your phone for Face ID, touch the sensor for Touch ID, or enter the passcode you use to unlock your device. That local check gives your device permission to use the passkey.
Synced passkeys add an important detail to the key analogy. The private credential does not have to remain on one physical device. Apple Passwords can copy it between your approved devices using end-to-end encrypted iCloud Keychain syncing. The website still receives only the public key and a cryptographic proof during sign-in, never your private key.
Why are passkeys so much safer than passwords?
Passwords have two big problems. First, they can be stolen. When a website gets hacked, password data in its database can help an attacker break into accounts. Second, passwords can be tricked out of you. A phishing scam points you toward a fake website that looks like the real one, and the password you type goes straight to whoever built the fake.
Passkeys address both problems. A website stores a public key rather than a reusable secret that an attacker can enter somewhere else. And because a passkey is tied to the real website or app it was created for, a fake address cannot use it, no matter how convincing the page looks.
Passkeys also stop the kind of real-time phishing attack that trips up even careful people. Some scam sites relay a password to the real site and then ask for the temporary authentication code too. A passkey does not give the fake site a password or code that can be passed along.
That does not make the whole account invincible. If the account still accepts a password, texted code, or another phishable recovery method, an attacker may target that weaker path instead. A passkey provides excellent protection for the passkey sign-in itself, while the account’s remaining sign-in and recovery methods still matter.
How do you create a passkey?
There are two common ways, depending on the website.
Some sites offer to create a passkey automatically when you log in. You’ll see a prompt saying something like “Do you want to save a passkey?” or “Sign in faster next time with a passkey.” Accept it when you are using a personal device or a password manager you trust. Do not create a passkey on a public or shared device unless you deliberately choose the option to save it to your own phone or password manager.
Other sites require a bit of hunting. The setting is usually in the same place you’d go to change your password, often under Security, Password, or Sign-in Methods. Look for a section labeled “Passkeys.” Some sites put passkeys and physical security keys in the same part of their settings, but they are not always the same thing. A synced passkey lives in a device or password manager, while a device-bound passkey can live on a physical FIDO2 security key.
When you create one on an iPhone or Mac, Apple Passwords will usually offer to save it. Tap “Continue,” authenticate, and it is done.
A few things to know before you start:
-
iCloud Keychain needs to be turned on to sync passkeys with Apple Passwords. On an iPhone, go to Settings > [your name] > iCloud > See All > Passwords & Keychain, then make sure “Sync this iPhone” is on.
-
Two-factor authentication must be active on your Apple Account. Apple requires it for iCloud Keychain and passkey syncing.
-
Keep a strong, unique password anywhere the website still uses one. Save it in your password manager even if you normally sign in with a passkey.
-
Keep more than one reliable way back into an important account. I explain how to do that without leaving an unnecessarily weak backdoor later in this article.
How does Apple keep your passkeys available across all your devices?
Passkeys saved in Apple Passwords sync automatically through iCloud Keychain to approved Apple devices signed in to the same Apple Account. The data is end-to-end encrypted with keys Apple does not know.
If you lose one device, you can normally use a passkey from another approved device. If all your devices are unavailable, Apple may be able to restore iCloud Keychain through its protected recovery process. That process can require your Apple Account credentials, access to a trusted phone number, and a device passcode. A recovery contact can also help in some account-recovery situations. Because recovery still has requirements, it is worth keeping your trusted phone number current and setting up a recovery contact before you need one.

Can you move passkeys to a different password manager?
Yes, if both password managers support secure credential transfer. On iOS 26, iPadOS 26, macOS 26, and visionOS 26, participating password managers can transfer passwords and passkeys directly between one another. The transfer is encrypted and does not require placing the passkeys in an unprotected CSV or text file.
This makes choosing a password manager less permanent than it used to be, but support is not universal. Both the old and new password manager have to participate. This is also a transfer between managers, not continuous syncing between two separate services. Passkeys bound to a physical security key remain on that key.
Do passkeys work on non-Apple devices?
Yes. Passkeys are based on open standards backed by Apple, Google, Microsoft, and the FIDO Alliance. They work across current versions of iPhone, Android, Windows, macOS, and major browsers, although the exact prompts vary.
If you need to log in on a Windows computer, an Android phone, or a library computer, your iPhone can often handle the authorization. When you click the sign-in button on the other device, look for an option such as “Use a passkey from another device” or “Use a different device.” Choosing it displays a QR code. Point your iPhone camera at the code, follow the prompt, and authenticate with Face ID, Touch ID, or your passcode.
For this nearby-device method, both devices need Bluetooth turned on. Bluetooth confirms that your phone is physically nearby, while an additional encrypted connection protects the sign-in. The passkey remains on your iPhone during this process and is not saved to the computer you are using.
Current versions of Safari, Chrome, Firefox, Edge, and other compatible browsers can use passkeys on a Mac. Depending on the browser, macOS version, and password manager, you may need to approve access or enable an extension.
Apple Passwords is the focus here, but third-party managers such as 1Password and LastPass can also save and sync passkeys across supported versions of macOS, Windows, iOS, and Android. Check your manager’s current system requirements before relying on it for a particular device.
Which websites already support passkeys?
List updated: September 2, 2026. This is not a comprehensive list. Passkey availability can vary by account type, country, device, browser, and staged rollout. Some companies currently use a passkey only as a second factor after a password; those entries are labeled below.
Accounts you probably use every day
-
AOL
-
Apple
-
Google
-
Microsoft
-
Yahoo
Social and communication
-
Discord
-
Eventbrite (event organizers only)
-
Facebook
-
Instagram
-
LinkedIn
-
Messenger
-
Reddit
-
Snapchat
-
Telegram
-
TikTok
-
WhatsApp
-
X
Shopping and services
-
Amazon
-
Best Buy
-
Costco
-
eBay
-
Electrify America
-
Hearst Magazines
-
Home Depot
-
Instacart
-
Libby
-
Login.gov (second factor only)
-
Lowe’s
-
Lululemon
-
Ring
-
Shopify
-
SiriusXM
-
Target
-
Tesla
-
Ticketmaster
-
Uber
-
US Mobile
-
Verizon
-
Walmart
-
Yelp (mobile web only)
Finance
-
American Express
-
Cash App
-
Chase
-
Coinbase
-
Erie Insurance (second factor only)
-
Experian
-
Intuit, TurboTax, and QuickBooks (second factor only)
-
Merrill Lynch (second factor only)
-
PayPal
-
Robinhood
-
Truist (availability may vary)
-
U.S. Bank
-
Vanguard (second factor only)
-
Wells Fargo
Health
-
CVS
-
MyChart
-
Safeway Pharmacy
Travel
-
Air New Zealand
-
British Airways (second factor only)
-
Carnival Cruise Line
-
Flying Blue
-
Holland America
-
Hyatt
-
Kayak
-
Qantas
Tech and productivity
-
Adobe
-
Canva
-
ChatGPT
-
Daylite
-
Dell
-
DocuSign
-
Dropbox
-
GitHub
-
GoDaddy (second factor only)
-
Logitech
-
Namecheap (second factor only)
-
Nintendo
-
Notion
-
NVIDIA
-
Square
-
Squarespace (second factor only)
-
Stripe
-
Synology
-
Wikipedia
-
Wix
-
WordPress.com (second factor only)
-
Zoho
-
Zoom

Why does the login experience feel different from site to site?
Passkeys don’t behave identically everywhere. The underlying technology is the same, but each website decides how to fit passkeys into its sign-in and account-recovery policies.
Some sites let a passkey replace both the password and a separate two-factor code. When the site requires your device to verify you with a biometric or PIN, the sign-in combines something you have with something you know or are. Google is one example of a service that can let a passkey satisfy its second verification step.
Other sites accept a passkey but still request another confirmation for certain sign-ins or sensitive actions. Some use a passkey only as the second factor and still require the password first. That difference reflects the site’s implementation and risk policy rather than a problem with your passkey.
The broader direction is toward accounts that can operate without passwords, but adoption is uneven. Using a passkey on a personal device generally improves security even when a particular site has not removed every older sign-in method.
Can you set up more than one passkey on an account?
Many websites allow more than one passkey, but the rules vary. Adding a second passkey can be useful when you want an independent backup on another password manager, device, or physical security key. Name each passkey clearly when the website gives you that option, and review the list periodically so you can remove one tied to a lost device.
Some services also support account access for a spouse, caregiver, or adult child. When possible, use the service’s own family, delegate, or authorized-user feature so each person has a separate identity and the appropriate permissions. If the service instead allows multiple passkeys on one shared account, understand that each passkey may grant broad access to that account.
Apple also supports shared password groups. A passkey placed in a shared group becomes available to the trusted group members, but this is different from each person registering a separate passkey with the website. Group members can edit or delete shared credentials. Removing someone from the Apple group may not by itself end access they already had, so also review the passkeys and recovery methods on the website when access should end.
Only share account access with someone you fully trust, and check whether the service permits shared access. Financial, health, work, and government accounts may have rules against sharing one person’s credentials.
How do you remove weaker sign-in methods without locking yourself out?
Passkeys close an important phishing route, but an old sign-in or recovery method can remain a way around them. Text-message codes can be phished or intercepted through a SIM-swap attack. Codes from an authenticator app resist SIM swapping, but a convincing fake website can still ask you to type one and relay it in real time. Passkeys and physical FIDO security keys are designed to resist that kind of phishing.
Microsoft is already phasing out SMS authentication and account recovery for personal Microsoft accounts. For business and school accounts using Microsoft Entra ID, passkeys begin becoming the default on September 1, 2026, and Microsoft-provided SMS and voice authentication is scheduled to end on February 1, 2027. That is a useful sign of where account security is heading, but it is not a reason to delete your only working backup today.
For an important account, use this order:
-
Create a passkey in a trusted password manager and confirm that it is available on your other approved devices.
-
When the site allows it, add a second independent phishing-resistant method, such as another passkey stored separately or a physical FIDO2 security key.
-
Confirm that your recovery email and phone number are current. Protect the recovery email with its own passkey, and save one-time backup codes somewhere secure if the service provides them.
-
Test the passkey and your backup method in a private browser window before removing anything.
-
Once the stronger methods work, remove SMS, voice calls, and other phishable sign-in methods when the service allows it and when doing so will not leave you with only one route back into the account.
The simple rule is: replace a weak method before you remove it. Do not keep SMS forever merely because it is familiar, but do not trade a phishing risk for an account lockout.
Common mistakes to avoid
Creating a passkey on a public or shared device. Save the passkey to a personal device or password manager you control. If a public computer offers to store it locally, decline and choose the nearby-device option instead.
Thinking a passkey makes the entire account invincible. A passkey makes its sign-in path dramatically harder to phish, but passwords, recovery email, support procedures, and unlocked devices can still affect account security.
Keeping a weak fallback without checking whether you still need it. Once you have two reliable stronger methods and have tested recovery, remove SMS or other phishable methods if the account supports doing so safely.
Removing your only independent backup. Several devices using one synced password manager are convenient, but they may still depend on the same provider account and recovery process. A second passkey stored separately or a physical security key can provide a more independent backup for especially important accounts.
Key takeaways
-
Create a passkey when a site offers one on a personal device or in a password manager you trust
-
Confirm that Passwords & Keychain syncing is enabled on each Apple device where you expect your passkeys to appear
-
Protect your iPhone and Mac with a strong device passcode because it helps protect your passkeys
-
Keep at least two tested ways into important accounts, preferably including two phishing-resistant methods when the service supports them
-
Replace SMS and other weaker methods before removing them, then eliminate unnecessary fallbacks that could bypass your passkey
-
Remember that passkey support and migration depend on the website, password manager, device, and software version
If you’d like help setting up passkeys or reviewing whether your accounts are as secure as they should be, I offer one-on-one sessions in San Francisco, Washington DC, and via Zoom. Book a session, and we can go through it together at your pace.


