How they work
When a user creates a passkey for a website, the device generates a pair of keys. The website stores the public key; the private key never leaves the user's device or password manager. To sign in, the website sends a challenge, the device signs it after the user unlocks it with biometrics or a PIN, and the website checks the signature. No shared secret travels over the network or sits in the website's database.
Why they resist phishing
Each passkey is bound to the exact domain where it was created. A fake login page, even a perfect copy relayed in an adversary in the middle attack, cannot use it because the domain does not match. There is also no password to reuse, guess or leak, which removes the basis of credential stuffing and brute force attacks.
Synced and device bound passkeys
Synced passkeys are backed up and shared across a user's devices through Apple, Google, Microsoft or a password manager, which makes them convenient and easy to recover. Device bound passkeys, such as those on hardware security keys, never leave a single device and suit administrators and other high risk accounts.
Adoption in companies
Microsoft 365, Google Workspace, the main identity providers and many SaaS applications support passkeys. A practical path is to enable them as an MFA method, require them first for administrators and finance, and then extend them to all staff through SSO. The FIDO Alliance publishes guidance on deploying them.




