Passkeys let you sign in without typing a password. Your phone, computer, or security key protects the credential, and you approve the login with Face ID, a fingerprint, Windows Hello, or a device PIN. The result is faster sign-in and better protection against fake login pages.
This guide explains how to use passkeys with Google, Apple, Microsoft, and Amazon. It also covers where passkeys are saved, how to use one from another device, and what to do when a passkey disappears.
Quick answer: A passkey is a passwordless login credential stored on your device or with a passkey provider. To use one, open a supported account, choose the passkey option, and approve the sign-in with your device PIN, fingerprint, Face ID, Windows Hello, or another supported method.
In this guide: Google, Apple, Microsoft, Amazon, passkey storage, cross-device sign-in, lost-phone recovery, troubleshooting, and the practical differences between passkeys and passwords.
What I checked for this guide
I checked the current account-setting paths and sign-in instructions in the official Google, Apple, Microsoft, and Amazon documentation. I did not claim a personal device test where I did not have evidence of one. Screens can change with the operating system, browser, account type, region, password manager, and company policy, so use the linked official page if your menu is different.
The practical detail that matters most is where the passkey is saved. A credential stored only on one device behaves differently from one synced through Google Password Manager, iCloud Keychain, Microsoft Password Manager, or another provider.
Quick comparison: Google, Apple, Microsoft, and Amazon passkeys
| Service | Common storage | Typical approval | Cross-device behavior |
|---|---|---|---|
| Google Password Manager, device, or security key | PIN, fingerprint, or face unlock | Often available on compatible devices using the same Google Account | |
| Apple | Apple Passwords and iCloud Keychain | Face ID, Touch ID, or passcode | Available across compatible devices using the same Apple Account |
| Microsoft | Windows Hello, Microsoft Password Manager, phone, or security key | Windows Hello, PIN, biometric, or provider unlock | Depends on provider, account type, and organization policy |
| Amazon | Selected passkey provider | Device PIN, fingerprint, or face unlock | Depends on provider and Amazon marketplace |
This is a practical summary, not a compatibility guarantee. The provider selected during creation can matter more than the service name.
How a passkey works
Your device or passkey provider → unlock with PIN or biometrics → private key signs a challenge → website checks the matching public key → signed in
Important: the private key does not become a password and is not sent to the website during normal sign-in.
What is a passkey?
A passkey is a cryptographic sign-in credential created for a specific website or app. The service keeps a public key, while the private key stays on your device or in a passkey provider such as Google Password Manager, Apple iCloud Keychain, Microsoft Password Manager, or a compatible third-party manager.
You do not type or reveal the private key. When you sign in, your device unlock method approves the request. Your face or fingerprint is checked locally by the device; it is not sent to Google, Apple, Microsoft, Amazon, or the website.
Passkeys are also tied to the website where they were created. A fake site cannot normally use the passkey made for the real domain, which is why passkeys resist many phishing attacks.
For broader account protection, see our advanced password security tips and learn how to check whether your email was in a data breach.
Before you create a passkey
- Use a phone or computer that belongs to you.
- Turn on a screen lock, PIN, fingerprint, or face unlock.
- Update the operating system and browser.
- Make sure you can still access the account using its current recovery method.
- Keep another recovery method until you have tested the passkey.
Do not create a passkey on a public or shared computer. Anyone who can unlock that device may be able to use the passkey saved there.
How to use a passkey with Google
Google lets you create passkeys for your Google Account and use them on compatible phones, computers, browsers, and security keys.
Create a Google passkey
- Open Google Account passkey settings.
- Sign in and verify your identity if Google asks.
- Select Create a passkey.
- Approve the request with your fingerprint, face unlock, PIN, or device screen lock.
On Android and Chrome, Google may save the credential in Google Password Manager. That can make it available on other compatible devices where you use the same Google Account.
Sign in to Google with a passkey
- Open a Google sign-in page and enter your username.
- Select the passkey shown on the screen.
- Unlock your device to approve the sign-in.
If your passkey is on your phone but you are signing in on a computer, choose Try another way, then Use your passkey. Scan the QR code with your phone and confirm the request. Bluetooth may need to be enabled when your phone is used as a nearby device.
Google says that creating a passkey turns on a passkey-first sign-in experience by default. You can still use a password. To prefer passwords first, open your Google Account security settings and turn off Skip password when possible.
How to use a passkey with Apple
Apple saves passkeys in iCloud Keychain when you use compatible Apple devices and browsers. The same passkey can be available on your iPhone, iPad, and Mac when they are signed in to the same Apple Account and iCloud Keychain is enabled.
Create an Apple passkey
- Open a website or app that supports passkeys.
- Sign in and open its account or security settings.
- Select Create a passkey or Add a passkey.
- Choose Apple Passwords or iCloud Keychain when prompted.
- Approve the request with Face ID, Touch ID, or your device passcode.
Some websites offer to create a passkey while you register a new account. In that case, follow the prompt after entering your account name.
Use an Apple passkey on an iPhone or Mac
On an iPhone or iPad, open the supported app or website, choose the passkey option, and confirm with Face ID, Touch ID, or your passcode.
On a Mac with Touch ID, choose the passkey option and place your finger on the sensor. Apple also lets you use an iPhone or iPad to sign in on a Mac: choose Passkey from nearby device, scan the QR code, and approve the request on the phone. Bluetooth needs to be on for this nearby-device method.
Find or delete an Apple passkey
On iOS 18 or later, open the Passwords app, unlock it, and select the website or app. For earlier iOS versions, go to Settings > Passwords.
On macOS Sequoia or later, use the Passwords app. On older macOS versions, open Apple menu > System Settings > Passwords. Removing a passkey from Apple Passwords may not remove it from the website account, so check both locations when you want to revoke access.
How to use a passkey with Microsoft
Microsoft supports passkeys for personal accounts and, where an organization allows them, work or school accounts. You can save one through Windows Hello, Microsoft Password Manager, a phone, a compatible password manager, or a FIDO2 security key.
Create a Microsoft passkey
- Open Microsoft’s security options page.
- Sign in to your Microsoft account.
- Select Add a new way to sign in or verify.
- Choose Face, fingerprint, PIN, or security key.
- Select where to save the passkey and complete the device prompt.
On Windows, the credential may be saved locally through Windows Hello. Microsoft also lets you save it in Microsoft Password Manager, Google Password Manager, Apple iCloud Keychain, another compatible manager, a phone, or a security key.
Sign in to Microsoft with a passkey
- Open the Microsoft sign-in page and enter your email address.
- Choose the passkey option.
- Select the provider if more than one is available.
- Approve the request with Windows Hello, your phone, password manager, or security key.
For a work or school account, your organization may control whether passkeys are allowed. If the option is missing, check with the administrator rather than repeatedly creating new credentials.
How to use a passkey with Amazon
Amazon supports passkeys on many current phones, browsers, and computers. You can approve sign-in with your face, fingerprint, or the PIN used to unlock your device.
Create an Amazon passkey
- Open Your Account on Amazon.
- Select Login & security.
- Select Set up beside Passkeys.
- Select Set up again if prompted.
- Follow the device or password-manager instructions.
Amazon notes that you can create one passkey per passkey provider. A passkey saved through Apple may therefore be treated separately from one saved through Google Password Manager.
Sign in to Amazon with a passkey
- Open the Amazon sign-in page or app.
- Enter your email address or mobile number.
- Select the passkey option.
- Confirm with your device PIN, face unlock, or fingerprint.
If you use a different Amazon marketplace, such as Amazon.in or Amazon.co.uk, Amazon may ask you to create another passkey or sign in normally. Amazon may also request a passkey for some high-risk payment actions.
Where are passkeys stored?
Passkeys can be stored locally on a device, synced through a credential manager, or saved to a hardware security key. Common locations include Google Password Manager, Apple Passwords and iCloud Keychain, Microsoft Password Manager, Windows Hello, and third-party password managers.
This is important when you replace a phone. A passkey stored only on the old phone may not move to the new one. A passkey saved in a synced manager may return after you sign in to that manager on the replacement device.
How to use a passkey from another device
You can often sign in on a computer with a passkey saved on your phone:
- Open the website on the computer.
- Enter your username or email address.
- Choose Use a passkey, Try another way, or the phone option.
- Scan the QR code with your phone.
- Approve the sign-in on your phone.
The QR code helps establish the authentication session. It does not turn your private passkey into a password that the computer can read.
What happens if you lose the phone with your passkey?
The result depends on how the passkey was stored.
- Synced passkey: sign in to the same provider account on a replacement device. The credential may become available after syncing.
- Device-bound passkey: use the account password, recovery code, security key, or account-recovery process to regain access and create a replacement.
After recovering the account, remove the lost device’s passkey from the account security page and review active sessions. Removing a local copy is not always the same as revoking the credential at the website.
Passkey not working? Try these fixes
The passkey option is missing
Check that the service supports passkeys, your browser is current, your device has a screen lock, and your password manager is signed in. If the option is hidden, select Try another way.
The wrong passkey appears
Choose another provider, device, or password manager. This commonly happens when several passkey providers are installed on the same phone or computer.
You replaced or lost your phone
Sign in to your passkey provider on the new device if the credential was synced. If it was stored only on the old phone, use your password, recovery code, security key, or account recovery process to create a replacement.
After a device is lost, remove its passkey from the account security page. Review active sessions as well. Deleting a local copy from a password manager is not always the same as removing the credential from the online account.
Passkeys versus passwords
Passkeys are usually the better everyday sign-in option when a service supports them. They reduce password reuse, avoid typing secrets into login forms, and provide strong protection against many phishing attempts.
Keep recovery information current, however. Some services continue to retain passwords, one-time codes, or other recovery methods even after you add a passkey. Do not remove every fallback until you have confirmed how account recovery works.
Frequently asked questions
Final advice
Start with your primary email account, cloud storage, shopping accounts, and other services that would be difficult to recover. Create each passkey on a personal device, test it, and keep a second recovery method until you know the new sign-in works.
Passkeys do not eliminate the need for good account security. They change what you must protect: instead of memorizing another password, you must protect your devices, screen locks, and passkey providers.

No comments yet. Be the first to share your thoughts!