Blog
3 min read

What Are Passkeys? Passwordless Login Explained

Passkeys replace passwords with a key pair stored on your device and unlocked with your fingerprint, face or PIN. How they work, why they can't be phished or leaked from a database, syncing across devices, and what adding passkey login to your own app involves.

A passkey is a way to sign in without a password. Instead of typing something you remember, you confirm with your fingerprint, face or device PIN, and your device proves who you are to the website.

Apple, Google and Microsoft all support passkeys, and many major sites (Google, GitHub, Amazon, PayPal) now offer them.

How passkeys work

Passkeys use public-key cryptography — the same idea behind HTTPS and SSH keys. (SSH keys explained)

  1. When you create a passkey for a site, your device makes a key pair:
    • a private key, which stays on your device (or in your password manager), and
    • a public key, which the website stores.
  2. When you sign in, the website sends a random challenge.
  3. Your device asks you to unlock it (Face ID, fingerprint, PIN), then signs the challenge with the private key.
  4. The website checks the signature with the public key. If it matches, you're in.

The private key never leaves your device and is never sent to the website.

The technical standard behind this is called WebAuthn (part of FIDO2).

Why they're safer than passwords

Threat Passwords Passkeys
Weak or reused passwords Common Impossible — there's nothing to choose
Phishing Fake sites collect real passwords A passkey only works on the real site's domain
Database breach Leaked hashes can be cracked The site only stores public keys — useless to an attacker
Credential stuffing Leaked passwords tried elsewhere Each passkey is unique to one site
Brute force Possible Nothing to guess (Brute force attacks)

The phishing resistance is the big one. Your device checks the website's domain itself; a lookalike site simply can't trigger your passkey.

Syncing and losing your phone

Passkeys are usually synced through your platform's password manager — iCloud Keychain, Google Password Manager, or third-party managers like 1Password and Bitwarden. Get a new phone, sign in to that account, and your passkeys come with you.

You can also use a passkey from your phone to sign in on another computer by scanning a QR code.

Sites should still offer a recovery route (another passkey, email recovery, backup codes) for people who lose all their devices.

Passkeys vs two-factor authentication

Passkeys combine something you have (the device) with something you are or know (biometric or PIN), so a passkey login is already multi-factor in one step. Many sites therefore don't ask for a separate 2FA code after a passkey. (Two-factor authentication)

Adding passkeys to your app

You don't need to implement the cryptography yourself.

  • Auth providers — Clerk, Auth0, Supabase and others offer passkey support or plugins; often a setting plus a UI component. (Clerk vs Auth0 vs Supabase Auth)
  • Libraries — SimpleWebAuthn (JavaScript) and similar libraries handle the WebAuthn protocol on the server and in the browser.
  • Auth frameworks — Better Auth, Auth.js and others have passkey plugins.

Things to plan for:

  • HTTPS is required (localhost is allowed for development). (What is HTTPS?)
  • Passkeys are tied to your domain — decide your production domain before users create them.
  • Keep another sign-in method during the transition; not every user or device is ready.
  • Let users name and delete passkeys in their account settings.

Should your app use them?

If you're building login now, offering passkeys alongside email login is a strong choice — better security and a faster sign-in for users who adopt them. If you use an auth provider, check whether it's already a toggle away. (Add login to an AI-built app)


EasySpawn serves your app over HTTPS on your own domain from day one — the foundation passkeys need — with Claude Code on hand to add WebAuthn to your login. See how it works or join the waitlist.

Related: Two-Factor Authentication · Password Hashing Explained · Magic Link Login · Add Login to an AI-Built App

Keep reading