Technology / Explainer
Passkeys, explained without the jargon
A different approach to signing in puts the secret behind the screen.
A password asks you to supply a shared secret. A passkey changes that exchange: your device proves that it holds the appropriate cryptographic key, without sending a reusable password to the service.
The FIDO Alliance describes passkeys as credentials based on public-key cryptography. A service holds a public key while the corresponding private key stays with a device or credential provider. Signing in typically uses a familiar device-unlock method, such as a PIN or biometric check.
Why the website matters
Passkeys are bound to the relevant service, which makes them resistant to phishing attempts that rely on a convincing imitation login page. The biometric information used to unlock a device is not handed to the website as the account credential.
That changes the user's job. Instead of remembering and protecting a text string for every login, the user needs to understand how the device or passkey provider stores, synchronizes and recovers access.
Recovery is part of the decision
Before changing an important account, look at its actual recovery options. A seamless sign-in on today's phone is only part of the story. What happens if that phone is lost? Can you access the account from another device? Which backup method remains available?
The answers depend on the service and provider, so a single experience should not be assumed to describe every implementation. Read the setup screen as carefully as the sign-in screen. The best account arrangement is one you can both use conveniently and recover deliberately. A new credential can simplify the front door while still requiring a sensible plan for the spare key.
Sources & further reading
Source material consulted for this explainer; interpretation and examples are our own.
This article is an original AI-assisted explainer. Factual background is linked above. Read our editorial approach.