Skip to content

Passkey vs Password: What Actually Changes When You Sign In

Passkey vs password, explained plainly: what a passkey is, how it signs you in, why fake login pages cannot use it and what to keep if a phone goes missing.

Published
Journey
4 min
Covered here
6 sections
Route
Tech
Smartphone, finger and fingerprint

Covered here

  1. What is a passkey?
  2. How do passkeys work when you log in?
  3. Passkey vs password at a glance
  4. Where your passkeys are stored
  5. Questions people ask before switching
  6. A sensible way to start

A password is a secret you remember and type. A passkey is a pair of cryptographic keys: one stays locked inside your phone, laptop or security key, the other is held by the website, and you approve each sign-in with a fingerprint, a face scan or your device PIN. The practical difference is that there is nothing to type, nothing to reuse and nothing a fake login page can collect. Passwords will be around for years yet, so most households end up running both side by side.

What is a passkey?

A passkey is a login credential built on public-key cryptography, the same branch of mathematics that protects the connection between your browser and your bank. When you create one, your device generates two linked keys. The public key goes to the service and is stored with your account. The private key stays in protected storage on your device or inside an encrypted password manager. A stolen public key on its own cannot sign anyone in.

Passkeys are based on open standards known as FIDO2 and WebAuthn, which is why the same approach works on phones, computers and browsers from different makers.

How do passkeys work when you log in?

  1. You pick the account or type your username, and the service sends your device a one-off challenge.
  2. Your device asks you to confirm it is really you with a fingerprint, your face or the screen-lock PIN. That check happens locally; the biometric data is never sent to the website.
  3. The device signs the challenge with the private key and sends back the signature.
  4. The service tests the signature against the public key it holds. A match lets you in.

Each passkey is tied to the genuine web address of the service that created it. A lookalike domain asking for a sign-in gets nothing, because your device holds no passkey for that address and simply has nothing to offer.

Passkey vs password at a glance

PasswordPasskey
What you provideA string of characters you typeA fingerprint, face scan or PIN on your own device
Where the secret livesIn your memory or a password manager, and with the servicePrivate key on your device or in a synced manager only
Reuse across sitesCommon, and a major cause of account takeoversImpossible by design: every account gets its own pair
Fake login pagesCan be typed into one by mistakeOnly works on the real address
If the service is breachedStolen password data may be cracked and tried elsewhereThe public key alone is of no use to an intruder
Losing accessReset by email or textUse another synced device or the account's recovery route

Where your passkeys are stored

Most passkeys are saved by the phone or computer's own credential manager, or by a separate password manager, and synced with end-to-end encryption across devices signed in to the same account. Create one on a phone and it can appear on the tablet and laptop that share that account. That works much like an eSIM holding a mobile plan on a chip inside the handset: the credential sits in protected hardware rather than on something you write down or carry separately.

Some people prefer a hardware security key, a small USB or NFC token. Passkeys saved on one of these do not sync anywhere, which is stricter but means you should register a second key and keep it in a safe place.

You can also sign in on a computer that holds none of your passkeys. The login page shows a QR code, you scan it with your phone, the phone checks that it is physically close by using Bluetooth, and you approve on the phone.

Questions people ask before switching

What happens if I lose my phone?

If your passkeys sync, they remain available on your other devices and return when you sign in to a replacement phone with the same account. If they lived only on the lost handset, you fall back on the service's normal recovery process. That is why the recovery email and phone number on your important accounts deserve a look while you set passkeys up.

Could someone use my fingerprint to get in?

The biometric check only opens your device. Anyone who knows your device PIN can do the same, so a long screen-lock PIN or passcode matters more with passkeys than it did before.

Should I delete the old password?

Many services keep the password as a fallback, and some let you remove it. A weak or reused password left in place undercuts the passkey, so either change it to something long and unique stored in a password manager, or remove it once you have at least two other ways in.

Do passkeys work for shared family accounts?

Some password managers allow a passkey to be shared with a trusted group. Where that is not possible, each person can usually add their own passkey to the same account if the service allows several.

A sensible way to start

  • Begin with the accounts that matter most: your main email inbox, the account behind your phone, and banking where it is offered.
  • Look in each account's security settings for wording such as "passkey" or "sign in without a password"; many services also offer one straight after a normal login.
  • Give each passkey a clear name if the service lists them, so you can remove the right one when a device is retired.
  • Keep at least two sign-in routes for every critical account: a synced passkey plus a recovery method, or two separate devices.

Passkeys remove a whole class of tricks, yet messages urging you to log in somewhere still deserve a pause. For accounts that still run on passwords, checking a link before you click remains a habit worth keeping.

Change here for

Also on this line