What a passkey changes

A passkey uses a cryptographic key pair. The service keeps the public key; the private key is managed by your device or passkey provider. Unlocking may use a device code or biometric verification depending on the hardware. That local code is not a new password to give to the website.

The mechanism is bound to the expected service: an imitation login page cannot use it like a typed password. This reduces phishing risk during authentication without establishing that every subsequent message or request is legitimate.

Synced or bound to a device

Some passkeys are synchronised across devices by a provider; others are bound to a device or hardware security key. Recovery therefore depends on where the key is stored and on the provider’s and service’s procedures. Identify that location before changing phones or managers.

Check current documentation for service, browser and hardware compatibility. GitHub documents passkey sign-in, for example; that availability must not be generalised to every platform in this directory.

Prepare a fallback

Before changing your main access method, check official recovery options. Add a second permitted method if the service allows it and keep recovery codes outside your primary device. Protect the passkey provider account too when it handles synchronisation.

Do not remove every older method in one operation. Test the new login on a trusted device, keep a usable session during setup and review connected devices. A shared device is a poor place for personal access that someone else might unlock.

A simple trial and team handover

Start with an account whose recovery you control. Record the provider, device and fallback without putting secrets in a public document. Fictional example: an association lead configures her personal passkey, tests a login and retains handover information about team roles without sharing the passkey.

For team accounts, use individual roles and service permissions where available. A passkey does not solve an administrator’s departure or account ownership: handover must identify who can revoke access and recover the space.

Frequently asked questions

Does a passkey remove every risk?

No. It protects authentication against forms of phishing, but not an already compromised device, careless sharing or poorly managed roles.

What happens if I lose my phone?

It depends on passkey storage and the service’s recovery methods. Prepare those options before loss and use official procedures only.

Before you act

Sources and verification scope

Official references consulted on 6 October 2026. Trial procedures and examples are editorial guidance; exact conditions depend on the service and device.

Continue with a practical method

Privacy: review spaces, audiences and traces →