How Do I Actually Set Up and Use Passkeys?

I want to replace passwords with passkeys, but I’m confused about how to set them up on my phone and computer. Can someone explain how passkeys work, where they’re stored, and how to use them securely across devices?

Don’t delete your passwords on day one. Passkeys only work on sites that support them, and many accounts still keep the password as a backup. Sign in normally, open that site’s security or sign-in settings, choose “Create passkey,” then approve it with your fingerprint, face, or device PIN. After that, signing in usually means selecting the account and unlocking your device.

The passkey is stored in whichever credential manager you choose, such as iCloud Keychain, Google Password Manager, Microsoft Password Manager, or a compatible password manager. If syncing is enabled, it becomes available on your other devices using that same account. When the passkey is on your phone but you’re signing in on an unrelated computer, choose the nearby-device option, scan the displayed QR code, and approve the login on your phone.

The easy-to-miss part is recovery. Before relying heavily on passkeys, secure your Apple, Google, Microsoft, or password-manager account with a strong device PIN, recovery information, and two-factor authentication. Keep at least two trusted devices or another recovery method available. A passkey protects you from phishing better than a typed password, but losing access to the account that syncs all your passkeys can still create a serious headache.

Don’t assume every passkey can be moved later. Some are device-bound, while others sync through your chosen credential manager, so check where it will be saved before creating it. If you use mixed platforms, test the passkey on each device before making it your main sign-in method.

Do not create your first passkey on a shared computer or under the wrong Apple, Google, Microsoft, or password-manager profile. The setup screen can look nearly identical, and it is easy to save the credential somewhere you did not intend.

A passkey is a pair of cryptographic keys. The website keeps the public half, while your device or credential manager keeps the private half. When you sign in, your device proves it has the private key. Your fingerprint, face scan, or PIN only authorizes the device to use that key. The biometric data is not sent to the website.

For a safe first attempt, use an account that would not be disastrous to lose. Sign in with your existing method, find the security settings, and create a passkey. Pay attention when your phone or computer asks where to save it. Then leave the original session open and test the passkey in a private browsing window. Do not remove the password, recovery codes, or other sign-in methods until that test works. This catches wrong-profile and sync problems while you still have an easy way back in.

Where the passkey works depends on where you saved it:

  • A synced credential manager can make it available on devices signed into that same manager account.
  • A hardware security key keeps it on the physical key, so you must have that key with you.
  • A device-bound passkey may remain on the original phone or computer.
  • A work-managed device may restrict syncing, exporting, or using outside credential managers.

That last point is why @olegthebit’s warning matters. “Passkey” does not automatically mean “available everywhere.” Mixed setups are where things get awkward. An iPhone, a Windows PC, and a work browser may not all be using the same credential store, even if each supports passkeys.

If the credential is on your phone and you are signing in on another computer, choose the option to use a phone or another device. The computer usually displays a QR code. Scan it with the phone, keep Bluetooth enabled and the devices nearby, then approve with the phone’s screen lock. This does not normally copy the passkey onto the computer. It authorizes that particular sign-in.

Treat your device PIN as seriously as an account password. Avoid weak PINs, require authentication when your password manager opens, and remove old phones from your sync account after replacing them. For important accounts, create a second passkey on another trusted device or hardware key when the site allows it. Save recovery codes somewhere separate from the devices holding your passkeys.

A passkey fixes the phishing problem of typing a reusable secret into a fake site, but it does not fix every account-security problem. An already-unlocked device, stolen browser session, compromised email account, or careless account recovery process can still cause trouble. Start with a few accounts, verify cross-device access, and only then expand the setup.

The annoying downside is that passkeys can pile up like old Bluetooth devices. A site may list “iPhone,” “Windows Hello,” and two mystery passkeys created months apart, with no obvious clue which one still works. When the site lets you name a passkey, use something specific like “personal iPhone, Aug 2026” or “home Windows laptop.” That makes cleanup much less risky later.

For setup, start on the device and browser you normally use. Sign in to the site the old way, open its security settings, and look for “Passkeys,” “Sign-in methods,” or “Passwordless.” Choose create, confirm where it will be saved, then approve with your face, fingerprint, or device PIN. That local check is permission to use the credential. The website never receives your fingerprint or learns your PIN.

Storage is where the terminology gets confusing. The passkey might live in your phone or computer’s built-in credential manager, a third-party password manager, or a physical security key. A syncing manager can make the same passkey available on your other signed-in devices. A passkey kept only on one device will not magically appear elsewhere. This is why @olegthebit’s advice to test mixed-platform setups matters more than the “passwordless” marketing makes it sound.

You do not necessarily need every device to hold a copy. If your passkey is on your phone and a computer shows a QR code, scan it and approve the sign-in from the phone. Keep Bluetooth on and the devices near each other, since proximity is part of the check. That is handy on a borrowed or rarely used computer because you are not typing a password or saving the credential there. Still, make sure the address in the computer’s browser is the real site before approving anything. Passkeys resist fake-site phishing, but blindly accepting unexpected prompts is never a good habit.

My practical order would be: create the passkey, test it in a different browser or private window, test it on your second device, and only then consider changing the account’s older sign-in options. Keep recovery codes offline and leave at least one fallback that you have actually verified. “Recovery email exists” is not the same as knowing you can still access that email.

There is maintenance involved too. Before selling, trading in, or factory-resetting a device, confirm that another device can sign in. Afterward, check the website’s passkey list and remove credentials tied to devices you no longer control. Do the same in the credential manager account’s trusted-device list. If a site shows the last-used date for each passkey, that can help identify stale entries.

I would treat passkeys as a gradual replacement rather than a weekend project. Move a few frequently used accounts first, preferably ones with decent recovery controls. Once you understand which manager is saving them and how cross-device sign-in behaves, the rest becomes pretty routine.

If your main email uses the same account that syncs your passkeys, that recovery plan everyone’s praising falls apart fast. Lock yourself out of that Google or Apple account and you lose your inbox and your passkeys in one shot, so put a separate, verified fallback on the email itself. The QR-code cross-device stuff is fine, but that single point of failure is the part I’d fix before anything else.

Using a passkey on your own laptop and approving a login on a borrowed computer are not the same risk. The QR method may keep the passkey off that computer, but the browser still receives a normal signed-in session that could remain active.

Passkeys secure the login step, not everything afterward. On an unfamiliar machine, avoid “remember me,” sign out when finished, and remove that session later from the account’s device or session list.

Don’t lean on being able to export passkeys from one manager into another. That migration story keeps getting promised and it’s still spotty in practice, so if you’re picking a credential manager, pick like you’ll be stuck with it for a while. On @socket.nerd’s cleanup point, agreed in spirit, but half the sites I’ve seen won’t let you name a passkey or show a last-used date at all, so you end up guessing which ‘Windows Hello’ entry is dead. My own take: the strongest fallback isn’t a second synced device, it’s a cheap hardware key registered separately and thrown in a drawer. @prime_daemon nailed the real risk. If your email and your passkeys ride on the same account, a physical key on the email itself is the thing that saves you when the sync account locks up.