aswad
Guide · 4 min read

What is a passkey?

A passkey is a login that replaces your password with the thing you already use to unlock your phone — your face or your fingerprint. It can't be guessed, reused, or phished.

How it actually works

When you create a passkey, your device generates a pair of cryptographic keys. The private key never leaves your device — it's protected by your biometric. The public key is the only thing the website stores. To sign in, your device proves it holds the private key without ever sending it. There's no shared secret to steal.

Your biometric
Unlocks the private key
Private key
Stays on device, always
Public key
All the site ever stores

Why it's safer than a password

Nothing to phish
A passkey is bound to the real site. Paste it on a fake one and it simply won't work.
Nothing to leak
There's no password database. A breach of the website exposes only useless public keys.
Nothing to remember
No resets, no manager, no reuse across sites. A glance or a touch and you're in.

Common questions

What if I lose my phone?

Passkeys sync through iCloud Keychain or Google, so a new device restores them. Paswad also lets you register several devices and keep one-time backup codes — and for verified accounts, re-confirm your identity to issue a fresh key.

Do passkeys work across browsers and devices?

Yes. Passkeys are an open standard (FIDO2 / WebAuthn) supported by Apple, Google, Microsoft, and every major browser.

Can a passkey approve a payment, not just a login?

Yes — the same passkey can cryptographically sign a specific transaction. Paswad emails you the details every time, so you always know what your key approved.

Try it in under a minute.

Create your first passkey — no password, no card.

Get Paswad — free

Passkey FAQs

Common questions about passwordless passkeys and how Paswad uses them.

What is a passkey and how is it different from a password?

A passkey is a cryptographic credential that replaces your password with the biometric you already use to unlock your phone — your face or fingerprint. Instead of a shared secret you type, your device holds a private key that never leaves it and proves your identity without sending anything that can be stolen.

That makes passkeys phishing-resistant and impossible to reuse, guess, or leak in a breach. See how it stays secure.

Are passkeys safe if my phone is lost or stolen?

Yes. A passkey is useless without your biometric or device PIN, so a thief who has your phone still cannot sign in. Passkeys also sync securely through iCloud Keychain or Google Password Manager, so a new device restores them.

With Paswad you can register several devices and keep one-time backup codes, and verified accounts can re-confirm their identity to issue a fresh key. Learn about the verified web passport.

Do passkeys work across different browsers, devices, and platforms?

Yes. Passkeys are built on the open FIDO2 and WebAuthn standards, supported by Apple, Google, Microsoft, and every major browser. You can sign in on a laptop using the passkey on your phone, and credentials sync across devices in the same ecosystem.

Because it is an open standard, Paswad never locks you in — any compliant authenticator works.

How do I switch from passwords to passkeys?

You create a passkey in under a minute: choose to sign in with a passkey, then approve the prompt with your face, fingerprint, or device PIN. There is nothing to memorise and no manager to configure.

With Paswad the same passkey can also approve payments and high-risk actions, not just logins. See transaction signing.

The Passwordless Dispatch

Plain-English passkey & identity writing from Muslih Ali — straight to your inbox. No spam, unsubscribe anytime.