Home / Tech & AI
Passkeys Explained: How to Set Up and Use Them Safely
Understand how passkeys work, how to create one on your phone or computer, and how to recover access without weakening your account security.
By M. Usman
Passkeys let you sign in with the same fingerprint, face scan or PIN used to unlock your device. They are designed to replace a reusable password with a cryptographic credential tied to a website or app. This guide explains how to use passkeys, where they are stored, and the precautions that matter before you switch to passkey-first sign-in.
What is a passkey?
A passkey is a pair of cryptographic keys. The service keeps a public key, while the private key remains protected by your device or password manager. Signing in proves that you hold the private key without sending it to the website. Because there is no password to type into a look-alike page, passkeys provide strong protection against common phishing attacks.
Google's official passkey requirements and setup guide says supported devices include Windows 10 or newer, macOS Ventura or newer, Android 9 or newer, and iOS 16 or newer. Browser requirements can change, so keep your operating system and browser updated.
What you need before creating one
- A screen lock such as a PIN, fingerprint or face unlock.
- A supported browser and operating system.
- Bluetooth when using a phone's passkey to sign in on another computer.
- iCloud Keychain enabled when using Apple's built-in passkey synchronization.
- A working recovery method for the account.
How to create a Google Account passkey
Step 1: Open passkey settings
Sign in to your Google Account and open Security & sign-in. Choose Passkeys and security keys. Confirm that you are working with the correct Google Account.
Step 2: Create and verify
Select Create a passkey, review the device shown, and approve the request using the device screen lock. Create passkeys only on devices you personally own and control.
Step 3: Test before depending on it
Open a normal browser window, sign out, and test the new passkey. Do not remove your existing recovery options until you know the passkey works on the devices you regularly use.
How phone-to-computer sign-in works
On a computer, choose the passkey sign-in option and select another device if needed. A QR code may appear. Scan it with the phone that holds the passkey, keep Bluetooth enabled, and approve with the phone's screen lock. The proximity check helps stop remote attackers from simply forwarding a QR image.
Where passkeys are stored
A passkey may stay on one hardware security key or synchronize through a credential manager such as Google Password Manager or iCloud Keychain. Synchronization makes replacement devices easier to use, but your cloud account and device lock therefore need strong protection.
| Storage choice | Advantage | Main consideration |
|---|---|---|
| Phone or computer | Fast everyday sign-in | Device access must be protected |
| Synced password manager | Available across compatible devices | Secure the manager account |
| FIDO2 security key | Portable, separate hardware | Keep a backup or recovery method |
Important passkey safety rules
- Never create a passkey on a public, borrowed or shared device.
- Review registered passkeys after losing, selling or repairing a device.
- Keep account recovery email and phone details current.
- Protect every synchronized device with a strong screen lock.
- Treat unexpected QR sign-in prompts as suspicious.
Passkeys improve authentication, but they do not make every online activity safe. Continue checking links and software carefully. Our AI tools comparison follows the same principle: convenience should be evaluated alongside privacy and account security.
Frequently Asked Questions
Does creating a passkey delete my password?
Not necessarily. For a Google Account, adding a passkey does not automatically remove other authentication or recovery factors. The service may prefer passkey sign-in while retaining alternatives.
Can someone use my passkey if they steal my phone?
They would normally also need to unlock the phone. Report a lost device, remotely secure it where possible, remove its account sessions and review registered passkeys from another trusted device.
Are passkeys the same as two-factor authentication?
No. A passkey can satisfy strong authentication by proving device possession and local user verification. How it interacts with additional verification depends on the service and account policy.
Should I keep more than one passkey?
For important accounts, a second trusted device or hardware key can reduce lockout risk. Maintain recovery options and remove credentials you no longer control.
Conclusion
Passkeys remove the most phishable part of sign-in: the reusable password. Start with one important account, test recovery, and expand gradually. The safest setup combines passkeys with secure devices, current recovery information and regular account reviews.