Passkeys Explained: A Plain-English Guide to Passwordless Login
Passkeys are the biggest change to how we sign in since the password itself, and they are quietly arriving on the sites you already use. Here is what they are, why they are safer, and how to start, without the jargon.
Passwords have a design flaw that no amount of advice can fix: they are a shared secret. You know it, the website knows it, and anything that sits between you, a fake login page, a breached database, a shoulder surfer, can learn it too. Every rule about length and symbols is just damage control around that one weakness.
Passkeys remove the shared secret entirely. This guide explains how, in plain terms, and what it means for you day to day.
Key takeaways
- A passkey is a key pair. The private half stays on your device; the site only ever sees the public half.
- There is no secret to type, so passkeys cannot be phished or reused, and cannot leak in a breach.
- You sign in with the same face or fingerprint you already use to unlock your phone.
- Store passkeys in an encrypted vault with a recovery plan so a lost device is not a lost login.
How a passkey works, without the math
When you create a passkey for a site, your device generates two matched keys. The private key stays locked on your device and never leaves it. The public key goes to the website. The names are the whole idea: the public key can be shared freely because, on its own, it cannot log anyone in. Only the private key can, and only you have it.
To sign in, the site sends a challenge. Your device answers it using the private key, after you approve with Face ID, Touch ID, or a fingerprint. The site checks the answer against the public key it stored. At no point does a secret travel across the network or get typed into a box. There is nothing to intercept.
With a password, you send the secret and hope no one is listening. With a passkey, you prove you hold the secret without ever revealing it.
Passkeys vs passwords, side by side
| Threat | Password | Passkey |
|---|---|---|
| Phishing site steals it | Possible | Not possible |
| Reused across sites | Common | Never, each is unique |
| Leaks in a server breach | Yes, if stored poorly | Nothing usable to leak |
| Guessed or brute-forced | Depends on strength | Not applicable |
| You have to remember it | Yes | No |
The reason a passkey cannot be phished is worth pausing on: even if a fake site perfectly imitates the real one, your device ties each passkey to the genuine site's identity and simply will not answer the impostor's challenge. The protection is built in, not dependent on you spotting the fake.
Where do passkeys live?
A passkey is only as available as the device that holds the private key. That raises a practical question: what happens across your phone, tablet, and laptop, and what happens if a device is lost? This is where a passkey manager comes in. Instead of a passkey being stranded on one device, it lives in an encrypted vault that you control, synced across your devices and protected by a recovery plan.
The important detail is that a good manager stores the private key zero-knowledge, encrypted so that even the maker cannot use it. You get the convenience of your passkeys everywhere without trusting a company with the keys themselves.
How to start using passkeys today
- Turn on a passkey manager as your system provider, so passkeys are offered everywhere you sign in.
- Create a passkey where it is offered. Many major sites now show a "set up a passkey" option in security settings.
- Keep your passwords for now. Adoption is growing but not universal, so a manager that holds both passwords and passkeys lets you move at each site's pace.
Passkeys in Kinship Vault
Kinship Vault creates and stores passkeys alongside your passwords and 2FA codes, all end-to-end encrypted with the same key that seals your documents. When you turn Kinship Vault on as your AutoFill provider, passkeys sign you in system-wide, in your browser and inside apps, with the same Face ID or Touch ID check as everything else. Because they live in the same vault, they inherit the same recovery paths, so a passkey is never trapped on a single lost device. See the passkeys documentation for setup.
Passwords and passkeys, filled where you need them.
Turn Kinship Vault on as your AutoFill provider and sign in with a tap, no password to type, all sealed in your device.
Explore the password manager