The gist A passkey lets you sign in to a website or app with your face, fingerprint, or phone PIN instead of a password. It's made for that one account and won't work on fake websites. Start with one account you use often, like Google, and keep your old password while you get comfortable.
4 min read

Cindy keeps a little spiral notebook in the kitchen drawer. On the cover, in her neat handwriting, it says "RECIPES." Inside, there isn't a single recipe. It's four pages of passwords, most of them crossed out and rewritten, some with arrows pointing to other pages.

Last month she tried to log in to her Google account to see photos of our granddaughter's softball game. Wrong password. Then the right password with a capital letter she forgot. Then a locked account and a text code sent to a phone that was charging in the other room. Twenty-five minutes later she said something I won't repeat here, and I went and got the phone.

Well, folks, I'd been reading about something called passkeys, and that afternoon we set one up together. Now she signs in to her Google account with her face. No notebook required.

What is a passkey, in plain English?

A passkey is a way to sign in to a website or app without typing a password. Instead, you prove it's you the same way you already unlock your phone: your fingerprint, your face, or your phone's screen lock PIN.

Behind the scenes, your phone creates a special digital key for that one account and keeps it locked on your device. Apple explains that passkeys are made uniquely for each account and are less vulnerable to phishing, which is the trick where a fake website fools you into typing your password.

Password vs. passkeyPasswordYou remember itand type itCan be guessedor stolenWorks on fake sitesPasskeyFace, fingerprint,or phone PINMade just forthat one accountWon't work on fake sites
Same account, easier door, sturdier lock.

In plain words: a password is something you have to remember and type, it can be guessed or stolen, and you can accidentally type it into a fake website. A passkey is unlocked with your face, fingerprint, or phone PIN, it's made just for that one account, and it won't work on a fake website.

How do I set up my first passkey?

Start with one account you use often. Google is a good first choice because it walks you through it. The exact screens differ a little from site to site, but the steps usually look like this:

Your first passkey in 4 steps1Sign in as usualwith your password2Open security"Security" settings3Tap "Create a passkey"missing? Not supported yet4Confirm it's youface, finger, or PIN
Done once per account. After that, signing in takes a glance.

Here are those steps in words. Sign in the usual way with your password one last time. Open the account's security or sign-in settings. Tap the option to create a passkey, and if you don't see one, that site doesn't support passkeys yet. Then confirm it's you with your face, fingerprint, or screen lock.

A couple of practical notes. On an iPhone, Apple says iCloud Keychain and two-factor authentication need to be turned on, and your passkeys then work on your other Apple devices signed in to the same account. Google's help page on signing in with a passkey shows how to use one from your phone on a computer: the computer displays a QR code, you scan it with your phone, and you confirm on the phone.

Do I have to switch every account at once?

No, and please don't. Here's the thing: not every website offers passkeys yet, and you can keep a password and a passkey on the same account while you get comfortable. Pick one account this week. Use the passkey a few times. Then add another.

Keep your old records for now, too. Cindy's notebook still lives in the drawer, just with a lot fewer arrows in it.

Are passkeys actually safer than passwords?

For the most common tricks, yes. A scammer can talk you into typing a password on a fake login page. A passkey only works on the real website it was made for, so that trick doesn't work. If you ever did click a bad link, our guide on what to do after clicking a suspicious link covers the cleanup.

One rule doesn't change: never read a sign-in code or approve a sign-in request because someone called or texted and asked you to. Real companies don't do that. Our guide on how to spot a phone scam explains why.

What changed for Cindy

These days Cindy opens the photos app, glances at her phone, and she's in. The softball pictures load before her coffee cools. She says it feels like cheating. I told her it's the first time the computer has had to remember something instead of her.

Have you tried a passkey yet? Tell us in the comments which account you'd set up first.

Watch our video on this