Passkeys explained: why sign-in is changing
Learn what a passkey stores, why a fake website cannot use it like a stolen password, and what recovery still matters.
Passkeys are an alternative to entering a password. A passkey uses a cryptographic key pair: the website stores a public key, while the private key stays with an authenticator such as your device or password manager. You unlock its use with a device gesture such as a PIN or biometric check.
Private key⇄Website
Public key
What changes for phishing?
A password can be typed into a convincing fake page. WebAuthn credentials are bound to a website’s domain, so an impostor domain cannot obtain a valid signature for the real site. This is why passkeys are described as phishing resistant. It does not make every account problem disappear: recovery methods and access to your devices still matter.
Synced and device-bound passkeys
Some passkeys sync through a credential provider across your devices; others remain on one device or security key. Before depending on one method, check how your provider handles new devices and account recovery.
What to do when a site offers one
Create a passkey on a device or credential manager you control, keep its recovery options current, and review the site's other sign-in methods. A passkey is a useful security improvement, but the whole account is only as strong as its remaining recovery paths.