The short answer
Passkeys can replace passwords on supported services. Losing your phone does not automatically lock you out—but you need to know where your passkeys are saved and how to recover access.
What changes when you use a passkey?
You approve a sign-in using your device unlock, such as a fingerprint, face scan or PIN. There is no password to type for that sign-in. Google explains the options.
Instead, a pair of cryptographic keys proves you can sign in. The website stores the public key; the private key is used to produce the proof. Apple explains how this works.
One sign-in, three steps
01 The website asks
It sends a fresh sign-in challenge.
02 You approve
Your device uses the private key to sign a response.
03 The website checks
It verifies the response with the public key.
Your private key and biometric data are not sent to the website. Source: Apple.
What if your phone goes missing?
Synced passkey
Your provider can make it available on compatible devices using the same provider account. Another device or the provider’s recovery process may help you regain access.
Device-bound passkey
It stays on one device or security key. Plan for another supported sign-in or recovery method before that device becomes unavailable.
FIDO’s FAQ explains these two types. A replacement phone alone is not a guarantee of access.
Apple’s iCloud Keychain can sync passkeys with end-to-end encryption. Apple also describes recovery after losing all your devices, subject to security checks. Recovery is possible, but not necessarily instant. Read Apple’s recovery guidance.
Do you need to delete your password?
Not necessarily. Adding a Google passkey does not remove your existing authentication or recovery methods. Other services may work differently. Check Google’s guidance.
The wider shift is already underway: on May 1, 2025, Microsoft announced passwordless defaults for new accounts. That did not remove every existing user’s password, and passwordless options are not all passkeys. Read the announcement.
What passkeys protect—and what they don’t
FIDO describes passkeys as phishing-resistant. They reduce reliance on passwords that can be entered into a fake sign-in page.
That protects authentication. It does not make an unfamiliar message, seller or investment offer trustworthy.
Before you switch
My recommendation: start with one account on a device you control. Check where the passkey is stored, read the recovery instructions, and test your backup route before removing existing methods.
Avoid creating passkeys on shared devices: someone who can unlock the device may be able to access your account. Google’s device warning.
