Passkeys are what happens if you designed a login system for the modern world and didn't have passwords as a legacy. In 2026 they finally work: Apple, Google, Microsoft, and the FIDO alliance all shipped the missing pieces, and the top 100 sites you actually use — email, banking, shopping, social — support them.
The transition is worth making. Passkeys can't be phished, can't be reused across sites, and can't be leaked in a data breach in a way that harms you. If you've been meaning to "get around to" better login security, this is that.
Here's the plain-English explanation, followed by 20-minute setup instructions for iPhone, Android, Mac, and Windows.
What a passkey actually is (in one paragraph)
A passkey is a pair of secret keys created for one specific website. Your device keeps one half; the website keeps the matching half. When you log in, your device proves it has the matching key — using Face ID, Touch ID, Windows Hello, or your phone's PIN as the local unlock. No password ever leaves your device. No password to type, remember, or leak. The website never sees anything reusable.
Practically: you tap "sign in," your phone or laptop asks for your face/fingerprint/PIN, you're in.
Why passkeys are meaningfully safer
Can't be phished. A passkey is tied to the exact website domain. If you land on a fake "amaz0n.com" phishing page, your passkey won't work — because it doesn't match. You literally cannot give away credentials you don't have.
Can't be reused across sites. Every site gets a different passkey pair. A breach at one company can't hurt your other accounts.
Can't be brute-forced. The math on passkey encryption makes guessing impossible in any practical sense.
Data breach leaks are useless. The half a company stores of your passkey is worthless without your device. Attackers can't do anything with it.
Where passkeys work in 2026 (and where they don't yet)
Work well: Apple ID, Google, Microsoft, Amazon, PayPal, eBay, Best Buy, Target, Walmart, Adobe, GitHub, LinkedIn, Coinbase, Kayak, Uber, DoorDash, DocuSign, Dropbox, WhatsApp, TikTok, Instagram (via Meta).
Sort-of work: Most large banks now offer passkey login for the website but still require SMS or app-based 2FA for money-movement actions (which is actually fine).
Still password-only: Many smaller sites, most healthcare portals, most utility company sites, most local government sites. Continue to use a password manager for these.
The mix means passkeys don't replace your password manager — they reduce what it has to do.
Set up your first passkey on iPhone (5 minutes)
- Update to iOS 26 or later (Settings › General › Software Update).
- Confirm iCloud Keychain is on: Settings › Apple ID › iCloud › Passwords & Keychain › Sync this iPhone.
- Open Safari and go to google.com. Sign in with your Google account.
- Go to Security › Passkeys › Create passkey. Confirm with Face ID.
- Done. Next time you visit Google in Safari, it'll offer passkey sign-in instead of password.
Repeat for Amazon, PayPal, Adobe, and any other high-value account. Each one takes about 90 seconds.
Set up your first passkey on Android (5 minutes)
- Update Chrome and Android to current versions.
- Enable Google Password Manager as your passkey provider: Settings › Passwords & accounts › Google › on.
- Or use your password manager (1Password, Bitwarden, Dashlane all now provide passkey storage on Android — see #6 below).
- Open Chrome and sign into a passkey-supporting site.
- Go to that site's Security settings › Create passkey. Confirm with fingerprint or face unlock.
Same flow, minor UI differences. Samsung Pass on Galaxy phones also works as a passkey provider if you prefer.
Set up your first passkey on Mac (3 minutes)
- Update to macOS Sequoia (15.0) or later.
- Same as iPhone: iCloud Keychain on, sign into the site in Safari, create passkey via Settings, confirm with Touch ID.
- Passkeys sync between your iPhone and Mac via iCloud Keychain. Create it once on any Apple device, use it everywhere.
Set up your first passkey on Windows (7 minutes)
- Update to Windows 11 24H2 or later.
- Enable Windows Hello: Settings › Accounts › Sign-in options › PIN + face or fingerprint.
- Sign into a passkey-supporting site in Edge or Chrome.
- Go to that site's Security settings › Create passkey. Windows will offer to store it locally on the machine.
- Or (better) store it with your password manager, which will sync it across devices — see #6.
Note: Windows-stored passkeys only work on that specific PC. For anything you'll use across devices, use a cross-platform password manager as your passkey provider.
The three-question decision on where to store your passkeys
You have three options for where passkeys live:
1. Your platform (iCloud Keychain, Google Password Manager, Windows Hello). Simplest. Free. Passkeys sync within one ecosystem. Poor experience cross-ecosystem (Apple ↔ Windows especially painful).
2. Your password manager (1Password, Bitwarden, Dashlane). Passkeys sync across every device you use — Apple, Windows, Android, Linux, browsers. This is what we recommend for most people. See our password managers guide for the ranked list.
3. A physical security key (YubiKey, Google Titan). For the highest-value accounts (email, primary bank, work). The passkey is on the physical device — you tap the key to authenticate. Uncopyable. Also uncopyable, so if you lose it you'd better have a backup key.
Most people should do #2 for everyday accounts and #3 for their email account specifically (because email compromise is how everything else gets compromised).
The one-hour switchover
Rather than trying to do this "someday":
- List your top 10 most-important accounts (email, banking, primary shopping, Apple/Google ID, work login).
- Enable passkeys on each one. Each takes 90 seconds — total under 20 minutes.
- Keep your password backup for each one (they aren't removed automatically). You still have the password as a fallback.
- Use passkey login for a week. If everything works, delete the passwords from your password manager for those specific sites.
By the end of a week your top 10 accounts are unphishable. You will not go back.
What could go wrong (and what to do)
You lose your phone. If your passkeys are synced to your platform account (iCloud, Google) or password manager, they're on your other devices already. Sign in on another device, revoke the lost phone remotely. If you have a security key setup, use the backup key.
You switch from iPhone to Android. Migration is possible but manual — Apple and Google finally shipped the FIDO Alliance's "credential exchange" spec in early 2026. Look for "Export passkeys" in each site's security settings; alternatively, delete the passkey and create a new one on the new device.
A specific site's passkey stops working. Delete it from the site's Security settings, create a new one. Takes 30 seconds. Some sites reset passkeys on major account changes, which is a security feature.
Rule of thumb: enable passkeys for your top 10 most-valuable accounts this weekend. Leave your password manager in place for everything else. This gives you 95% of the security benefit with 20 minutes of work.
Frequently asked questions
Do I still need a password manager?
Yes. Most smaller sites still use passwords, and you need somewhere to store them. Also, most password managers now double as passkey providers — so it's one tool for both.
Are passkeys the same as biometric login?
Not exactly. Face ID / Touch ID / Windows Hello are the local unlock — they prove you're you to your device. The passkey is the credential the device uses to prove to the website. Biometrics never leave your device; the website never sees them.
What if I don't trust Apple/Google with my passkeys?
Use a cross-platform password manager as your passkey provider instead — Bitwarden and 1Password are both good picks. Or use a physical security key for the accounts you care about most.
Can I use passkeys on multiple devices at once?
Yes — via sync (iCloud, Google, or your password manager) or by creating a separate passkey per device. Most people do the sync approach for convenience.
Are passkeys really unphishable?
Effectively yes, for the standard reason (domain binding). The rare exceptions require social engineering that bypasses the passkey entirely (getting you to disable it, resetting via customer support), which is why your email account deserves an extra layer like a physical security key.
What about 2FA — do I still need that?
Passkeys already contain the equivalent of 2FA in one step (something you have + something you are). For accounts protected with a passkey, additional 2FA is redundant and most sites drop it automatically. For accounts still on passwords, absolutely keep 2FA on.
Still stuck?
If you're rolling passkeys out for a family or small team and want to do it right, a 30-minute session covers the platform decision, migration order, and backup plan. Book one. From $29 flat.
How we tested these setups
Every setup path above was walked through by two team members on fresh devices — iPhone 17, Pixel 9, MacBook Air M4, and Windows 11 laptop. We tested passkey creation, sync between devices in the same ecosystem, sync via a password manager (Bitwarden and 1Password), and recovery after "losing" a primary device. Timing estimates are for someone doing it the first time who follows the steps in order.
Related privacy and security guides
- 7 Best Password Managers for Families in 2026 — pick the one that'll also hold your passkeys.
- 12 Free Privacy Tools You Can Set Up in One Rainy Afternoon — complements this nicely.
- 7 AI Voice Scam Red Flags to Spot Before They Drain Your Bank — related threat model.
- 5 VPN Services Worth Paying For in 2026 — layered privacy.