Passkeys

Passkeys are cryptographic credentials that replace passwords with a key pair: the private key remains on the user's device or in a protected passkey store, while only the public key is stored with the service. The login is released locally, for example by fingerprint, facial recognition or device PIN.

Technically, passkeys are based on the standards of the FIDO Alliance and the W3C, summarized under FIDO2. During login, the device signs a challenge from the service; a reusable secret is not transmitted. Because every passkey is bound to the domain of the service, a fake page does not generate a valid proof; passkeys therefore count as Phishing-Resistant MFA. Since 2022, the major operating system and browser platforms have supported the method.

A distinction is made between synced passkeys, which are distributed to several devices via a cloud keychain or password manager, and device-bound passkeys, for example on hardware security keys, whose private key never leaves the device. Synced passkeys facilitate recovery and device changes; device-bound ones offer stricter control. Passkeys are an increasingly widespread form of Passwordless Authentication and a building block of Identity Security.