A passkey is a way to sign in to an account without typing a password. Instead of a secret you type (and can forget, reuse, or have stolen), a passkey is a cryptographic key pair: one half stays locked on your device (protected by your fingerprint, face, or PIN), the other half is registered with the website or app. Signing in just means proving you have the device — there’s no password to phish, leak, or guess.
How It’s Different From a Password + 2FA
A password can be stolen from a data breach and reused elsewhere. A passkey can’t — it’s generated per-device and per-account, and the private half never leaves your device or gets sent anywhere, so there’s nothing for a breach or a phishing site to capture.
Why It’s Everywhere in 2026
Google, Apple, and Microsoft have all been pushing users toward passkeys through 2026, partly in response to the scale of password theft — infostealer malware alone has been logging billions of stolen passwords a year. See the full account-by-account migration order and how to avoid getting locked out before switching over your accounts.
Try It Yourself
There’s no calculator for this one — but before switching any account to a passkey, make sure you’ve read the migration order and the lockout failure modes in the guide linked above, especially for your email account, since it’s the recovery hub for everything else.