Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A passkey is a cryptographic sign-in credential tied to a website or service—not a password stored under a new name. The service keeps a public key; an authenticator uses its private key to approve a sign-in. Some passkeys sync through a credential provider, while others stay on one device or security key, so not every passkey moves when you replace hardware.

What a passkey is—and where WebAuthn fits

A passkey is a public-key credential associated with a website or other online service, known in the standards as a relying party. It consists of a key pair: the service stores the public key, while an authenticator holds or manages the private key. The private key is used to prove possession; it is not sent to the service as a password would be. W3C’s Web Authentication standard and the FIDO Alliance’s passkey explanation describe this model.

WebAuthn is the web API that lets a site ask the browser and an authenticator to create or use a public-key credential. The browser and authenticator mediate the operation rather than giving the site direct access to the private key. As W3C puts it, “The user agent mediates access to authenticators and their public key credentials in order to preserve user privacy.”

How a passkey sign-in works

1. Registration creates a credential

When you add a passkey, the service asks the browser to create a credential for that service’s identity. An authenticator creates or manages the key pair and returns public credential information for the service to associate with your account. The user agent and authenticator mediate the approval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. Sign-in proves possession of the private key

At sign-in, the service sends a challenge. After you approve the request, the authenticator uses the private key to sign it. The service checks that signature with the public key stored for your account. The service does not receive the private key or a reusable password.

This is why a copy of a service’s password database would not, by itself, give an attacker the passkey private keys: the service holds the public key, not the private one. The details of how a credential is protected or synchronized depend on the authenticator and provider.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why passkeys resist phishing

A passkey is scoped to the service identity for which it was created. A lookalike site has a different origin or domain, so the passkey flow for the real site does not simply hand that page a reusable secret. Unlike a password, a passkey is not something you can type into a counterfeit login page and thereby reveal.

FIDO describes phishing resistance as applying whether or not a passkey is hardware-bound. That means syncing and phishing resistance are separate properties: syncing affects availability across devices, while domain binding is the core reason the credential resists this kind of phishing. It does not mean every route to account takeover is impossible; for example, this protection does not itself establish how a service handles account recovery or a compromised device. See the FIDO Alliance’s explanation of passkeys.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why some passkeys move and others do not

“Passkey” covers credentials with different portability behavior. A synced passkey may be available on other devices through its provider. A device-bound passkey stays with one authenticator, such as a phone or a physical security key. Provider availability and transfer behavior vary; there is no provider-independent export or migration process established here.

What to compare Synced passkey Device-bound passkey
Using it on another or replacement device May be available through the same provider’s sync service. Does not automatically move with the device.
Resilience to losing one device Sync may help, subject to access to the provider account and service. Requires another registered authenticator or the service’s recovery process.
What access depends on The provider’s availability and account access, as well as the service account. The physical or device authenticator and the service account’s recovery options.
Phishing resistance FIDO says it applies. FIDO says it applies; hardware binding is not required.

A security key is a physical authenticator that can hold device-bound passkeys; a passkey is not limited to a phone’s fingerprint or face unlock. A biometric check is generally an approval gesture on the device, not biometric data sent to the website. FIDO describes security keys and passkeys in its passkey overview and specifications.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Using a nearby device is not the same as moving a passkey

Some sign-in flows let you use a nearby phone or security key to authenticate on another device. That cross-device sign-in is distinct from transferring the credential itself: FIDO describes it as a separate flow using CTAP and Bluetooth proximity verification. It lets the authenticator participate in a sign-in without making the passkey a credential stored on the computer you are using.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do before replacing or losing a device

If you still have the old device

  • Check whether the passkey is synced through a provider and whether you can access that provider account on the replacement device.
  • For a device-bound passkey, add another authenticator to the service account while you still have access, if the service supports it.
  • Find the service’s account-recovery route before you depend on a single authenticator.

If the device is already gone

A device-bound passkey does not follow the lost device automatically. Use another authenticator already registered to the account, if available, or follow the service’s account-recovery process. A synced passkey may still be available through its provider, but that depends on access to the provider and its supported behavior.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Pro-A FIDO2 Security Key Passkey Device with USB A & NFC, TOTP/HOTP Authenticator APP, FIDO 2.0 Two Factor Authentication 2FA MFA, Works with Windows/macOS/Linux/Gmail/Facebook/Dropbox/GitHub
  • FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
  • Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
  • Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
  • Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
  • FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.

W3C’s workforce example warns that single-device credentials are not resilient to losing that device and recommends additional authenticators or a recovery method. The practical lesson is to plan a second way in before relying on a device-bound passkey. Read the Web Authentication specification.

WebAuthn standards status

As of the standards milestones stated by W3C, Web Authentication Level 3 became a W3C Recommendation on 25 August 2026. Level 4 is a First Public Working Draft dated 15 September 2026, not a Recommendation. Standards status can change; see the Level 3 specification and Level 4 document.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.