Passkeys Are Here: How to Move Your Accounts Off Passwords
Passkeys are faster than passwords and can't be phished. A practical plan for switching your most important accounts this week.
Most account takeovers still start the same way: someone reuses a password, it leaks in a breach somewhere, and an attacker tries it everywhere else. Or someone types their password into a convincing fake login page.
Passkeys fix both problems. They've moved from "interesting standard" to "supported by most services you use," and switching is now mostly a matter of spending an afternoon on it.
What a passkey actually is
A passkey is a pair of cryptographic keys created for one specific website or app.
- The private key stays on your device or in your password manager. It never leaves.
- The public key is stored by the website.
When you sign in, the site sends a challenge, your device signs it with the private key after you unlock it with your fingerprint, face or PIN, and the site checks the signature with the public key.
Two consequences matter:
- There's nothing to steal from the website. A breach exposes public keys, which are useless to an attacker.
- Passkeys can't be phished. Each passkey is bound to the real website's domain. A fake site at a look-alike address simply can't request it.
Where your passkeys live
You'll store passkeys in one of three places, and it's worth choosing deliberately:
| Option | Good for | Watch out for |
|---|---|---|
| Your platform (Apple, Google, Microsoft) | People who stay in one ecosystem | Moving between platforms can be awkward |
| A password manager | People with mixed devices | Protect the manager itself with a strong method |
| A hardware security key | High-value accounts, admins | Buy two and register both |
Most people are best served by a cross-platform password manager, with a hardware key for the handful of accounts that would be catastrophic to lose.
The switching plan
Don't try to convert everything at once. Work in order of damage-if-compromised.
Step 1: Your email
Your primary email account can reset almost every other password you have. Add a passkey here first, and review the recovery options while you're there: a current phone number, a backup email you still control, and printed recovery codes stored somewhere safe.
Step 2: Your password manager and cloud accounts
If your password manager supports passkey sign-in, enable it. Do the same for your Apple, Google or Microsoft account.
Step 3: Money
Banks, payment apps, payroll and accounting tools. Support here is still uneven; where passkeys aren't offered, use an authenticator app rather than SMS codes.
Step 4: Work tools
Your company's identity provider, code hosting, cloud consoles, domain registrar and DNS provider. If you run a small business, the domain registrar is easy to overlook and devastating to lose.
Step 5: Everything else, as you go
Each time a site offers to create a passkey after you sign in, accept. Over a few months, most of your daily logins convert without a dedicated effort.
Keep these habits
Don't delete your password immediately. Many sites keep the password as a fallback. Once the passkey works reliably on all your devices, replace the old password with a long random one from your manager, and turn off SMS recovery where you can.
Register more than one authenticator. For important accounts, add a passkey on your phone and a second one in your password manager or on a hardware key. Losing a single device shouldn't lock you out.
Watch recovery flows. Attackers increasingly target "forgot password" and support desks instead of logins. Know how each important account can be recovered, and make sure those routes are as strong as the front door.
For teams
If you manage accounts for a company, passkeys are among the most effective security upgrades available:
- Turn on passkey or security-key sign-in in your identity provider and make it the default for administrators first.
- Issue hardware keys to anyone with access to production systems, finance or customer data.
- Retire SMS as a second factor wherever you can.
- Write down the recovery process for a lost device before you need it.
The short version
Passkeys remove the two most common ways accounts are stolen: reused passwords and fake login pages. Start with your email, then your money, then work tools. One afternoon of setup buys you years of not worrying about the next big breach headline.
Have something worth publishing?
We accept guest posts across all 8 topics, edited and published within days.