Sign in to a major account today and there is a decent chance you were never asked for a password. You tapped a fingerprint, or entered your laptop PIN, and you were in. That was a passkey, and the list of sites offering them has been growing steadily since Apple, Google and Microsoft committed to the standard.
The takeaway up front: passkeys change what your vault stores, not whether you need one. For years to come you will hold a mix — passkeys on the handful of large services that support them, passwords on everything else, plus recovery codes, licence keys and secure notes. The buying question is no longer "does this manager hold passwords well?" but "does it hold both well, on every device I actually use, and can I get my credentials out if I leave?"
What a passkey actually is
A passkey is a pair of cryptographic keys created by your device when you register with a site. The private key stays with you — in your phone's secure hardware, your operating system's keychain, a hardware security key, or your password manager. The public key goes to the website. When you sign in, the site sends a challenge, your device signs it with the private key after you approve with a biometric or PIN, and the site verifies the signature against the public key it already holds.
Two consequences follow, and they are the entire security argument:
- There is no shared secret to steal. The site never stores anything that can be replayed. A breach of its login database yields public keys, which are useless to an attacker.
- It is bound to the site's domain. Your browser will only offer the passkey to the origin that created it. A convincing lookalike domain gets nothing, because the credential simply does not appear. That is why passkeys are described as phishing-resistant — the resistance is structural, not a matter of the user being alert.
The underlying standard is WebAuthn, part of the FIDO2 work from the FIDO Alliance and W3C. "Passkey" is the consumer-friendly name for a discoverable WebAuthn credential that can be synced rather than locked to one piece of hardware.
Why the vault does not go away
Three reasons, in order of how soon you will hit them.
Coverage is partial and will stay partial for a long time. Large consumer platforms moved first. Your regional utility provider, your accountant's portal, the supplier extranet with the 2011 login form — these will ask for a password for years. Any manager you choose has to be good at the boring old job as well as the new one.
Passkeys do not cover the rest of the vault. Recovery codes, software licences, Wi-Fi credentials, card details, passport scans, the shared account your two-person business uses — none of that becomes a passkey. Those items are why people open the app daily.
Platform keychains create their own lock-in. Storing passkeys in Apple's or Google's ecosystem works beautifully until you sit down at a Windows machine or switch phones across ecosystems. A cross-platform manager exists precisely to be neutral ground. Whether you want your credentials tied to a device vendor is a real decision with real trade-offs, and it deserves the same weighing as any other criterion — the general method is in our guide to comparing software before you buy.
Five criteria that separate real support from a checkbox
Nearly every vault now lists "passkeys" on its feature page. The differences are underneath.
1. Where the private key lives, and who can reach it
Ask whether passkeys are held under the same zero-knowledge model as the rest of the vault. Zero-knowledge means the provider stores only data encrypted with a key derived from your master secret, so the provider cannot read it even if compelled to. If passwords are zero-knowledge but passkeys ride in a different store with different properties, that is a meaningful gap. The vendor's security white paper, not the marketing page, is where this is answered.
2. Genuine cross-platform reach
A passkey you cannot use on the device in front of you is a locked door. Check for a native app on every operating system you touch, extensions for the browsers you use, and support for cross-device sign-in — the flow where a site shows a QR code, you scan it with your phone, and a short-range Bluetooth exchange proves the phone is physically nearby. That proximity check is deliberate: it stops someone remotely relaying the prompt.
Also check whether the manager can act as a credential provider to the operating system, so its passkeys appear in the native autofill sheet rather than only inside its own browser extension. On mobile especially, that is the difference between smooth and irritating.
3. Portability and export
This is the criterion most buyers skip and most regret. Historically, passkeys could not be moved between managers, which made a switch mean re-registering every account by hand. The FIDO Alliance has published Credential Exchange Format (CXF) and Credential Exchange Protocol (CXP) specifications precisely to make secure, encrypted transfer between providers possible, and major vendors have signalled support. Whether your candidate has actually shipped it is a fair question to put to their support team before you subscribe. A manager that can import your existing credentials but never let them out is charging you a switching cost you have not seen yet.
4. Recovery that survives a lost phone
If your only passkey for an account lives on a device that ends up in a river, what happens? Look for a clear, documented account-recovery path for the vault itself, and check whether each important site lets you register more than one passkey — a phone plus a hardware key, for example — or keeps a fallback method. Recovery is where convenience and security pull hardest against each other, and it deserves its own examination; we treat it as a first-class criterion in how to evaluate account recovery options.
5. Sharing, teams, and the unglamorous admin
For a household or a small business: can a passkey be shared the way a password can, or does the account have to be re-registered per person? Sharing support for passkeys is less mature than for passwords. If four people need access to the same supplier account, find out how that works before it becomes an emergency at 6pm on a Friday.
A short checklist before you commit
- List every device and browser you sign in from. Confirm a native client or extension for each.
- Open the vendor's security documentation and find the sentence describing how passkeys are encrypted at rest.
- Search their help centre for "export" and "import". Note what is exportable and in what format.
- Register a passkey on one real account during the trial. Then sign in from a different device. That single test surfaces more than an hour of reading.
- Check the recovery path for the vault, and register a second factor or second passkey on your two or three most important accounts.
- If you share credentials with anyone, test sharing during the trial, not after.
The wider criteria — security model, ease of use, breach history, price over time — still apply, and are laid out in our password manager buyer's guide. Passkey handling is a new column in that table, not a replacement for it.
FAQ
Do I still need a password manager if I use passkeys?
For nearly everyone, yes. Most sites you use will still require passwords for the foreseeable future, and a vault also holds recovery codes, licences, cards and notes that passkeys do not address. Passkeys change the mix inside the vault rather than removing the need for one.
Are passkeys safer than a long password plus two-factor authentication?
Against phishing, meaningfully so, because the credential is bound to the site's domain and cannot be handed to a lookalike. A strong unique password with an authenticator app is still a solid setup — but it depends on the user not being fooled, and passkeys remove that dependency.
Can I move passkeys if I switch password managers?
That is improving. The FIDO Alliance's Credential Exchange specifications were created to allow encrypted transfer between providers, and vendors have been adopting them. Confirm with each candidate what it supports today, because until it ships, switching means re-registering account by account.
What happens if I lose the device holding my passkeys?
If your passkeys sync through a manager or platform account, you restore access by signing in to that account on a new device — which is why the vault's own recovery path matters so much. If a passkey was device-bound and not synced, you fall back to the site's recovery process. Registering a second passkey on critical accounts is the cheap insurance.
Should I store passkeys in my browser or in a password manager?
Browser and platform keychains are convenient and secure, but they tie you to one ecosystem. A cross-platform manager keeps credentials portable across Windows, macOS, Android, iOS and Linux. Choose based on how mixed your device life actually is, not how mixed you expect it to be.
Judge the vault on both jobs
Passkeys are a genuine improvement, and the sites that matter most to you will keep adopting them. But the tool you buy has to do the new job and the old one: hold passkeys under a strong encryption model, reach every device you own, let you take your credentials elsewhere, and get you back in when a phone disappears.
When you have your criteria straight and want the verdicts, see our criteria-scored shortlist of password managers at Top Fully.