Skip to main content
Authentication

Passkey

A FIDO2-based passwordless authentication credential stored on a device, using biometrics or a PIN to authenticate instead of a traditional password.

Passkeys are the next evolution of passwordless authentication, built on the FIDO2/WebAuthn standard. Instead of a password, a cryptographic key pair is generated: the private key stays on the user’s device (protected by biometrics or PIN), while the public key is registered with the service.

During login, the service sends a challenge that the device signs with the private key. The private key never leaves the device and cannot be phished: even a perfect replica of the login page can’t intercept a passkey because the cryptographic challenge is domain-bound.

Passkeys can sync across devices via cloud platforms (iCloud Keychain, Google Password Manager). While passkeys represent the future of authentication, the transition will take years. Teams will continue needing password managers for services that don’t yet support passkeys.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide