A passkey stays on the device. A password goes for a walk.

Websites have started asking you to “create a passkey.” The popup looks like a login, plus a fingerprint, plus a small lecture about the future. It is easy to assume they invented a fancier password and hid the letters.

They did not. A password is a secret you can type, paste, reuse, and accidentally hand to a fake page that looks like your bank. A passkey is a pair of mathematical keys. One half stays on your phone or computer. The other half is stored by the site. The half that matters never goes for a walk.

The handshake

When you create a passkey, your device makes two related numbers. Call them public and private if you like jargon. The site keeps the public one. The private one stays in a locked box on the device: a password manager, the phone’s secure chip, a hardware key. Login is not “send the secret again.” Login is “prove you still hold the half that can sign this random puzzle.”

The site sends a challenge. The device signs it. The site checks the signature against the public half it already has. If the math works, you are in. If someone stole a list of public keys from the company, they still cannot log in as you. The stolen file is not the door key. It is the lock’s serial number.

Why your face is in the popup

Face unlock and fingerprints are not being mailed to the website. They unlock the box on the device so the private half can sign the puzzle. The site learns “the device said yes.” It does not get a photo of you, a map of your fingerprint, or a reusable code it could try somewhere else.

If you use a PIN instead, same idea. Local gate, not a second password the internet gets to see.

The phishing part, without the TED talk

A password works anywhere you type it. That is the feature and the injury. A page that looks like your bank can collect the same string and use it on the real bank five seconds later. Browsers have tried to warn you. Humans click through warnings. Attackers know this.

A passkey is tied to the real site address at creation. A lookalike domain does not get the private half. The browser will not even offer the passkey for the wrong name. This is the part that is actually better, not just newer. You can still be talked into installing malware, or unlocking a phone you handed to a stranger. You cannot be tricked into typing the passkey into a form, because there is nothing to type.

Sync is convenience with a basket

Phone makers and password managers will copy passkeys across your devices so a new laptop is not a locked-out afternoon. That is useful. It also means the passkey is as wide as that account. If the vault syncs, the keys sync. Treat the vault password, the phone PIN, and the recovery path as the real perimeter. The passkey did not delete the concept of a master secret. It moved it.

Lose the only device and have no backup, and you meet the boring sequel: account recovery. Email codes, support chats, waiting periods. Companies advertise the fingerprint. They are quieter about the afternoon you buy a new phone in a hurry. Set up more than one device, or a password manager that you could open from a second place, before you delete the old login “because passkeys are the future.”

What this does not replace

Not every site offers passkeys. Some offer them and still keep a password as a trap door. Some wrap a passkey around an account that can still be reset with a text message, which is a weaker door next to a stronger one. A passkey on a site that will cheerfully email you a new login is only as serious as that email inbox.

Passkeys also do not mean the company is honest, the app is well built, or the data they already have will stay put. They mean the login secret is harder to steal in the usual ways: leaked databases, reused passwords, fake pages. That is a real improvement. It is not a personality transplant for the internet.

If a site offers a passkey, it is usually worth making one, then confirming you still have a recovery path you control. If it does not, a long unique password in a manager plus an authenticator app is still the adult version of “I used the same word plus the year.” The popup is not magic. It is a lock that finally stopped asking you to shout the combination across the room.