Skip to content

How to enable passkeys on your accounts

A step-by-step for turning on phishing-resistant passkey sign-in — what a passkey is, how to add one, and how to keep a backup so you are never locked out.

IT & securityIntro5 min· Updated Jul 22, 2026
TL;DR

Passkeys replace the password with something un-phishable

A passkey is a FIDO2/WebAuthn credential tied to your device and unlocked by your fingerprint, face, or device PIN. There is no shared secret to steal or phish, so passkeys resist the attacks that beat passwords and one-time codes. Add a passkey, then register a second one as backup before you rely on it.

Steps to add a passkey

  • **1. Confirm the account supports it.** Look for 'passkey', 'security key', or 'sign in without a password' in the account's security settings.
  • **2. Open security settings.** Go to the account's security or sign-in section and choose to add a passkey.
  • **3. Authenticate to confirm it is you.** You will typically re-enter your current password or approve your existing MFA once to authorize the change.
  • **4. Create the passkey.** Follow the prompt and unlock with your fingerprint, face, or device PIN. The device generates the key pair and stores the private key securely; only the public key goes to the service.
  • **5. Name it.** Give it a recognizable name (for example 'work laptop') so you can manage credentials later.
  • **6. Register a backup.** Add a second passkey on another device, or use a passkey manager that syncs, so a lost device does not lock you out.
  • **7. Test sign-out and sign-in.** Sign out and sign back in with the passkey to confirm it works before you depend on it.
Decision

Synced vs device-bound passkeys

Synced passkeys (via a platform or password manager) follow you across devices and are the most convenient backup. Device-bound passkeys (like a hardware security key) never leave the hardware and are the strongest option for high-value accounts. Many people use synced passkeys for everyday accounts and a hardware key for the crown jewels.

Pitfall

Register a backup before you remove the password

The most common passkey mistake is enrolling exactly one, on one device, then losing that device. Always register a second passkey — or ensure yours sync — before you lean on passkeys for an important account, so a lost or broken device is an inconvenience and not a lockout.