Passkeys are sign-in credentials that replace passwords with cryptography. When a user creates a passkey for a website or app, their device generates a pair of keys: the public key goes to the service, and the private key stays with the user, on a phone, laptop or hardware security key, or in a credential manager that syncs it between their devices. To sign in, the user unlocks the passkey with a fingerprint, face scan or device PIN, and the device proves possession of the private key. Passkeys are built on FIDO2 standards and are one of the main forms of passwordless authentication.
At a glance
- Based on the FIDO2 standards (WebAuthn and CTAP), supported by major operating systems and browsers.
- Each passkey is tied to one website or app, so the browser or device won’t use it on a look-alike phishing site.
- Unlocked locally by biometric or PIN; the biometric itself is not sent to the service.
- Comes in two forms: synced (backed up across a user’s devices) and device-bound (kept on one device or security key).
- Commonly used to meet phishing-resistant MFA goals, subject to how they are deployed and policy.
What problem it solves
Passwords are the weak point in most account takeovers: they’re reused, leaked in breaches and typed into fake login pages. Adding a code or push approval as a second factor helps, but attackers relay those through phishing proxies or wear users down with repeated prompts.
Passkeys remove both problems for services that support them. There is no password stored on the server to steal, nothing for the user to type, and the credential only responds to the genuine site. Users also tend to find them faster than a password plus a code. For IT, that means fewer resets and a practical route to phishing-resistant sign-in without necessarily buying a hardware key for every user.
How it works
Registration. The user signs in the usual way and chooses to create a passkey. Their device creates a new key pair scoped to that service’s domain, stores the private key securely and sends the public key to the service.
Sign-in. The service sends a random challenge. The browser or operating system checks which domain is actually asking, finds the matching passkey and asks the user to unlock it with biometric or PIN. The device signs the challenge, and the service verifies the signature with the stored public key.
Synced passkeys. Credential managers built into operating systems, and many third-party password managers, encrypt and sync passkeys across a user’s devices. This makes passkeys easy to recover, but their security then depends on the sync account, which may be a personal account outside company control.
Device-bound passkeys. Hardware security keys and some managed devices keep the private key in hardware that doesn’t export it. Organizations can use attestation to restrict which authenticator models are accepted.
Cross-device sign-in. A user can sign in on a computer using a passkey on their phone, typically by scanning a QR code, with a proximity check between the devices.
Enterprise control. Your identity provider (IdP) decides whether passkeys are allowed, which kinds and for whom. Device management tools, such as mobile device management (MDM), help ensure the devices holding passkeys are company-managed and locked.
When it matters for buyers
- When moving beyond SMS or app codes. Passkeys are a common way to upgrade multi-factor authentication (MFA) to a phishing-resistant method.
- When choosing an identity provider or tier. Support for passkeys, device-bound restrictions and attestation varies.
- When deciding on synced versus device-bound. Many organizations allow synced passkeys for general staff and require device-bound keys for admins.
- When managing devices. Passkey policy works best when the devices that hold them are managed and up to date.
- When planning recovery. Lost devices and new phones are routine; recovery processes need to be strong without overloading the help desk.
Questions to ask vendors
- Do you support passkeys for workforce sign-in, and on which license tiers?
- Can we allow only device-bound passkeys for certain users, or restrict accepted authenticator models?
- Can we prevent passkeys from syncing to personal accounts, and how?
- How are passkeys enrolled for new users, and how do we stop an attacker from enrolling one?
- What is the recovery process if a user loses every device?
- Which of our applications can use passkeys directly, and which go through the identity provider?
How it differs from passwordless authentication
Passwordless authentication is the broad category of signing in without a password. It includes passkeys, but also smart cards, platform sign-in features, push approvals and one-time links or codes, some of which can still be phished. Passkeys are a specific, standards-based method within that category, built on public-key cryptography and tied to the genuine site. For managing and securing the laptops and phones that hold passkeys, see our unified endpoint management overview.
