
Before you create your first passkey
A passkey lets a supported website or app verify you through a device you already unlock. Instead of typing a reusable secret, you approve sign-in with a fingerprint, face scan, device PIN or another local unlock method. The service receives cryptographic proof tied to its own domain. That design makes a passkey much harder to surrender on a convincing phishing page, although it does not make account recovery or device security irrelevant.
Start by updating the operating system and browser on every device you expect to use. Turn on a strong screen lock, confirm that your recovery email and phone number are current, and make sure you can still sign in with the account’s existing method. Apple says passkeys on iPhone require iCloud Keychain and two-factor authentication in its current iPhone instructions. Do this preparation before changing a valuable account.
Choose where your passkeys will be stored
The prompt to create a passkey usually asks where to save it. On an iPhone, that may be Apple’s Passwords app and iCloud Keychain. Android commonly offers Google Password Manager. Windows can save a passkey locally with Windows Hello or in a supported synced credential manager. Pick the system you can reliably reach on your everyday devices, and understand whether the passkey stays on one machine or syncs through an encrypted account.
A mixed-device household needs extra thought. If you use an iPhone at home and Windows at work, a passkey stored only on one computer may be inconvenient. A synced manager can improve access, while a hardware security key can provide a separate portable option where supported. This choice also affects recovery: you need a secure way back into the manager account if a phone is lost. Our guide to how on-device and cloud processing differ provides useful background for evaluating local and synced storage.
Create one passkey and test it
Begin with a supported account that would not cause a crisis if you need to troubleshoot. Sign in normally, open its security or sign-in settings, and choose the option to create or add a passkey. Confirm the save location shown by your phone, browser or operating system, then approve with the device unlock method. Websites use different labels, so follow the service’s own account page rather than a random setup link sent by email or message.
Sign out and test the new passkey immediately. Select the passkey option, approve the device prompt and confirm that you reach the correct account. Do not delete an existing password or recovery method just because the first sign-in succeeds. Google’s passkey guidance says adding a passkey to a Google Account does not remove its existing authentication or recovery factors. That overlap gives you time to test before relying on the new method.
Set up passkeys on iPhone and Android
On iPhone, enable iCloud Keychain and two-factor authentication, then create the passkey from the supported website or app. The saved entry appears in Passwords, where it can sit alongside a password for the same account. Face ID, Touch ID or the device passcode approves sign-in. Check that Passwords syncing is active on the Apple devices where you expect the credential to appear, and never approve a prompt you did not initiate.
On Android, first enable a secure screen lock and confirm which password manager is selected in system settings. When a supported service offers a passkey, verify the account name and save destination before approving. Google lists Android 9 or later among its baseline requirements for Google Account passkeys, but individual services and managers can set newer requirements. If the option is missing, update the browser and app, leave private-browsing mode, and check the service’s own support page.
Use passkeys on Windows and across devices
Windows 11 can use Windows Hello to store and approve a local passkey with a PIN, face or fingerprint. Microsoft’s creation guide also describes saving to a phone, security key or synced credential manager. Read the destination carefully: choosing the Windows device can make the passkey local, while a manager may sync it. Work and school accounts can be limited by administrator policy.
To use a phone-held passkey on a nearby computer, choose an option such as passkey from another device. The computer may show a QR code for the phone to scan. Keep Bluetooth enabled on both devices, keep them close, and follow the phone’s confirmation prompt. The proximity check helps prevent remote misuse. Avoid this flow on a public computer unless necessary, sign out afterward, and decline any offer to save new account data on that computer.
Build a recovery plan before expanding
Once the first passkey works, add a second safe route for important accounts. That might be a passkey on another trusted device, a supported hardware security key, recovery codes stored offline, or a carefully protected recovery contact. The exact choices belong to the service. A spare method should live somewhere separate from the everyday phone; a backup stored in the same lost bag does not provide much resilience.
Review the device list and recovery settings every few months. Remove entries for sold, returned or stolen hardware, but do not delete a passkey merely because its label looks unfamiliar; first match the creation date and device. If a phone disappears, secure the platform account, use its lost-device controls and remove the relevant passkey from the service where possible. Changing a password alone may not invalidate every passkey, so review both lists.
Fix common passkey problems
If no passkey appears, confirm the correct account, screen lock, credential manager, browser version and sync status. Cross-device QR sign-in also depends on nearby devices and Bluetooth. If a prompt loops or times out, cancel it, reload the real sign-in page and try again. Use the site’s “try another way” route when available rather than repeatedly approving prompts. Managed devices may block creation even when personal devices support it.
Can you keep using a password? Many services currently allow both, but each provider controls its transition. Can someone copy your fingerprint from the website? Platform documentation describes biometric approval as local; the site receives cryptographic proof rather than the biometric image. Should you create every offered passkey immediately? Move gradually. Test storage, syncing and recovery on one account, then add higher-value accounts after you can explain where each passkey lives and how you would recover without your main phone.
Sources
- Use passkeys to sign in to websites and apps on iPhone
Apple Support | Checked
- Sign in with a passkey instead of a password
Google Account Help | Checked
- Create and save a passkey
Microsoft Support | Checked
Editorial disclosure
Prepared with AI assistance from official Apple, Google and Microsoft documentation checked September 15, 2026. Menu labels and availability can vary by device, operating-system version, browser, account type and administrator policy. The featured image is AI-generated and uses generic devices.


