Skip to content
DopeSwagYolo

AI & Cybersecurity

What is a passkey?

A passkey is a sign-in credential that replaces a password with a pair of cryptographic keys. The private key is held on the user's phone, computer or security key, is not given to the website, and is unlocked with a fingerprint, face scan or PIN.

Also known as: passkeys, FIDO credential, passwordless sign-in

Researched and fact-checked by AI, with no human review. 8 sources listed below. How we verify

Last updated

How it works

The FIDO Alliance is the industry group that develops the FIDO standards passkeys are based on. It describes a passkey as a credential stored on a phone, computer or hardware security key. It says the credential lets a person sign in with the same step used to unlock the device: a biometric, a PIN or a pattern.

Behind that step is public-key cryptography. Browsers handle it through Web Authentication (WebAuthn), a World Wide Web Consortium (W3C) specification. Under WebAuthn, the user's device creates a key pair when the user registers with a website. The website stores the public key. The private key is not shared with it. To sign in, the device proves it holds the private key, so no password is sent. Each credential is scoped to one website, so a look-alike site cannot use it. Level 3 of WebAuthn became a W3C Recommendation, a finished web standard, on August 25, 2026.

FIDO distinguishes two kinds. Synced passkeys are copied between a user's devices through a cloud service. Device-bound passkeys never leave a single device, such as a security key.

Why it matters

Passwords can be phished, meaning typed into a fake site. On April 23, 2026, the UK National Cyber Security Centre said it would begin recommending passkeys wherever a service supports them. It assessed them as at least as secure as traditional multi-factor methods, which it called inherently phishable. It noted that users still depend on the security of their devices and credential managers.

US federal guidance treats the two kinds differently. NIST's digital identity guideline SP 800-63B-4, published in July 2025, has an appendix on syncable authenticators. It accepts them at authenticator assurance level 2 (AAL2) but not at AAL3, the highest of three levels. That is because keys used at AAL3 must not be exportable.

Where things stand in 2026

Apple, Google and Microsoft announced on May 5, 2022 plans to expand support for FIDO sign-in across their platforms. Microsoft said on May 1, 2025 that new Microsoft accounts would be passwordless by default.

On May 7, 2026, the FIDO Alliance estimated that 5 billion passkeys were in use worldwide. Sapio Research surveyed 11,000 consumers in ten countries for the alliance in April 2026. Of those, 75% said they had enabled a passkey on at least one account. Both figures are the alliance's own. The alliance promotes the technology.

Sources

Articles on AI & Cybersecurity