Passkeys replace a typed secret with cryptographic credentials held by your device or password manager. They are designed to work only with the genuine website or app that created them, which makes common phishing tactics less effective.
There is no reusable password to hand over
When you use a passkey, the service receives proof from your device rather than the private credential itself. A fake website cannot simply capture that proof and replay it elsewhere. Your fingerprint, face or device PIN usually unlocks the credential locally; the biometric is not sent to the service.
Recovery still deserves attention
A safer sign-in method does not remove the need for secure device recovery and session management. Protect the account that synchronises your passkeys, keep devices updated and remove old sessions. For sensitive payments, a service should still show the transaction details you are authorising.
A practical next step
- Create passkeys only from the service’s official app or website.
- Protect the device and account that stores or syncs them.
- Review destination and amount even when sign-in feels effortless.