
How it works
The service stores a public key, while the private key remains protected by the user's device or password manager. A fingerprint, face scan, or device PIN can authorize its use.

What people often miss
Passkeys resist many phishing attacks because they are tied to the legitimate site. Recovery and syncing still depend on the platform and account setup.
Why this question comes up
More major services now offer passkeys alongside or instead of traditional passwords.
Key points
- A passkey is a sign-in credential based on public-key cryptography that lets a device authenticate without sending a reusable password to the website.
- The service stores a public key, while the private key remains protected by the user's device or password manager. A fingerprint, face scan, or device PIN can authorize its use.
- Passkeys resist many phishing attacks because they are tied to the legitimate site. Recovery and syncing still depend on the platform and account setup.
Bottom line
A passkey is a sign-in credential based on public-key cryptography that lets a device authenticate without sending a reusable password to the website.
Source and verification
This Answer was checked against FIDO Alliance. Follow the source for the full official explanation and any later updates.