Practical guide

Passkeys: What They Are and How to Use Them

A passkey replaces a reusable password with a cryptographic credential unlocked by your device PIN or biometrics; it is designed to resist phishing because it works only with the genuine service.

Passkeys: What They Are and How to Use Them — practical mobile guidancePractical guidance for UK mobile users

A passkey replaces a reusable password with a cryptographic credential unlocked by your device PIN or biometrics; it is designed to resist phishing because it works only with the genuine service.

How it works

The private credential stays protected on your device or trusted credential provider, while the service holds a public counterpart. A fake website cannot normally reuse the passkey for the real domain.

Before creating one

  • Protect the device with a strong passcode.
  • Secure the Apple, Google or password-manager account that may synchronise the passkey.
  • Understand whether the service offers another passkey, security key or recovery route.
  • Do not remove the existing sign-in method until the passkey has been tested.

Use on a new device

Depending on the provider, passkeys may synchronise through a protected ecosystem, be stored in a password manager, or be used from a nearby phone via a QR-based handoff. Follow the service’s current official flow.

Recovery still matters

Passkeys reduce phishing but do not remove the need to recover a lost device or credential account. Keep another trusted device or recovery method for important services.

Understand where the passkey is stored and how it recovers

A passkey is tied to a genuine service and unlocked with the device or password-manager security. It can resist common phishing, but losing access to the ecosystem that stores it can still create a recovery problem.

  • Identify whether the passkey syncs through Apple, Google or a password manager, or remains device-bound.
  • Keep another trusted device or independent recovery method for important accounts.
  • Review the account’s passkey list and remove devices you no longer control.
  • Test sign-in on a second device before retiring the old phone.

A passkey should reduce password reuse and phishing exposure; it should not become an undocumented single key to every account.

Official sources

Facts checked: 26 July 2026. Device behaviour, account features and menu paths can change. Recheck the current instructions for your exact device, software version and service before acting.