What Are Passkeys? Passwordless Login Explained
Passkeys replace passwords with a key pair stored on your device and unlocked with your fingerprint, face or PIN. How they work, why they can't be phished or leaked from a database, syncing across devices, and what adding passkey login to your own app involves.
A passkey is a way to sign in without a password. Instead of typing something you remember, you confirm with your fingerprint, face or device PIN, and your device proves who you are to the website.
Apple, Google and Microsoft all support passkeys, and many major sites (Google, GitHub, Amazon, PayPal) now offer them.
How passkeys work
Passkeys use public-key cryptography — the same idea behind HTTPS and SSH keys. (SSH keys explained)
- When you create a passkey for a site, your device makes a key pair:
- a private key, which stays on your device (or in your password manager), and
- a public key, which the website stores.
- When you sign in, the website sends a random challenge.
- Your device asks you to unlock it (Face ID, fingerprint, PIN), then signs the challenge with the private key.
- The website checks the signature with the public key. If it matches, you're in.
The private key never leaves your device and is never sent to the website.
The technical standard behind this is called WebAuthn (part of FIDO2).
Why they're safer than passwords
| Threat | Passwords | Passkeys |
|---|---|---|
| Weak or reused passwords | Common | Impossible — there's nothing to choose |
| Phishing | Fake sites collect real passwords | A passkey only works on the real site's domain |
| Database breach | Leaked hashes can be cracked | The site only stores public keys — useless to an attacker |
| Credential stuffing | Leaked passwords tried elsewhere | Each passkey is unique to one site |
| Brute force | Possible | Nothing to guess (Brute force attacks) |
The phishing resistance is the big one. Your device checks the website's domain itself; a lookalike site simply can't trigger your passkey.
Syncing and losing your phone
Passkeys are usually synced through your platform's password manager — iCloud Keychain, Google Password Manager, or third-party managers like 1Password and Bitwarden. Get a new phone, sign in to that account, and your passkeys come with you.
You can also use a passkey from your phone to sign in on another computer by scanning a QR code.
Sites should still offer a recovery route (another passkey, email recovery, backup codes) for people who lose all their devices.
Passkeys vs two-factor authentication
Passkeys combine something you have (the device) with something you are or know (biometric or PIN), so a passkey login is already multi-factor in one step. Many sites therefore don't ask for a separate 2FA code after a passkey. (Two-factor authentication)
Adding passkeys to your app
You don't need to implement the cryptography yourself.
- Auth providers — Clerk, Auth0, Supabase and others offer passkey support or plugins; often a setting plus a UI component. (Clerk vs Auth0 vs Supabase Auth)
- Libraries — SimpleWebAuthn (JavaScript) and similar libraries handle the WebAuthn protocol on the server and in the browser.
- Auth frameworks — Better Auth, Auth.js and others have passkey plugins.
Things to plan for:
- HTTPS is required (localhost is allowed for development). (What is HTTPS?)
- Passkeys are tied to your domain — decide your production domain before users create them.
- Keep another sign-in method during the transition; not every user or device is ready.
- Let users name and delete passkeys in their account settings.
Should your app use them?
If you're building login now, offering passkeys alongside email login is a strong choice — better security and a faster sign-in for users who adopt them. If you use an auth provider, check whether it's already a toggle away. (Add login to an AI-built app)
EasySpawn serves your app over HTTPS on your own domain from day one — the foundation passkeys need — with Claude Code on hand to add WebAuthn to your login. See how it works or join the waitlist.
Related: Two-Factor Authentication · Password Hashing Explained · Magic Link Login · Add Login to an AI-Built App
Keep reading
"Your Connection Is Not Private" on Your Own Site: Causes and Fixes
When visitors see NET::ERR_CERT_DATE_INVALID, ERR_CERT_COMMON_NAME_INVALID or ERR_CERT_AUTHORITY_INVALID on your site, the SSL certificate is expired, for the wrong name, or incomplete. How to tell which, and how to fix each one.
What Is HSTS? Strict-Transport-Security Explained
HSTS tells browsers to only ever use HTTPS for your site, closing the gap where a first HTTP request could be intercepted. How the header works, max-age, includeSubDomains and preload, how to roll it out safely, and how to set it in Nginx, Caddy, Express and Next.js.