Quick answer: A passkey is a password replacement that lets you sign in with your fingerprint, face or device PIN instead of typing a password. To switch without getting locked out: (1) pick one secure “home” for your passkeys (Apple, Google or a password manager), (2) set up account recovery first, (3) add a passkey to one account without deleting the password, (4) run a “lost-phone drill” to prove you can still get in, and (5) roll out to your other accounts, most important first. Keep your passwords until every test passes.
If you’ve seen a “Create a passkey?” pop-up lately and thought, “Sounds cool, but what if I lose my phone?”, you’re asking exactly the right question. Passkeys are safer than passwords for most people, but the switch can go sideways if you skip the backup plan. This guide walks you through the Lockout-Proof 5 plan, a step-by-step method built around one idea: never remove your old way in until the new way is proven.
What is a passkey, in plain English?
A passkey is a digital credential that replaces your password. Under the hood, it uses a pair of cryptographic keys: a public key that the website stores, and a private key that stays on your device. When you sign in, your device proves it holds the private key after you unlock it with a fingerprint, face scan or PIN. According to the FIDO Alliance, the industry group behind the standard, passkeys are phishing-resistant, are always strong, and are designed so that there are no shared secrets for a website to leak.
Translation: there’s no password to type, guess, reuse or get tricked into handing over on a fake website. A scammy login page can’t ask for your passkey the way it can ask for your password.
Are passkeys really taking over? (The numbers)
Yes, and quickly. The FIDO Alliance’s State of Passkeys 2026 report, based on a Sapio Research survey of 11,000 consumers and 1,400 enterprise decision-makers in ten countries (April 2026), found:
- About 5 billion passkeys are now in use worldwide (a FIDO estimate).
- 90% of consumers are aware of passkeys, and 75% have turned them on for at least one account.
- Roughly half of consumers say they use passkeys regularly.
Microsoft also reported that its passkey sign-ins succeed far more often than password sign-ins (98% vs. 32%, in the company’s own figures), and it made brand-new Microsoft accounts passwordless by default in 2025. Big tech is clearly all-in. But “everybody’s doing it” isn’t the same as “you’re set up safely,” which brings us to the real risk.
What’s the real lockout risk with passkeys?
The danger usually isn’t the passkey itself. It’s the home where your passkeys live. Synced passkeys are stored in a cloud account, such as your Apple Account (iCloud Keychain), your Google Account (Google Password Manager) or a third-party password manager. That means:
- Lose your phone? Usually no big deal. Your passkeys sync to your other devices, and you can restore them on a new phone after signing in to the same account.
- Lose access to the account that holds the passkeys? That’s the real problem. Every synced passkey becomes unreachable until you recover that account.
- Only one passkey and no backup? Some sites will leave you relying on their own account-recovery process, and that can be slow or stressful.
Heads-up: Passkeys synced through Apple’s system don’t automatically move to Android or Windows, and the same goes for the reverse. If you use an iPhone and a Windows PC, or an Android phone and a Mac, plan your “home” with that in mind (see the decision table below).
Author’s note: [PLACEHOLDER: add 2–4 sentences from your own experience, such as which account you switched first, what surprised you, and whether you ran the lost-phone drill. First-hand detail is the strongest trust signal on this page.]
What is the Lockout-Proof 5 plan?
This is the method. Do the steps in order, and don’t sweat it if it takes a weekend. Slow and steady beats locked out.
Step |
What you do |
Time |
|---|---|---|
1 |
Choose and secure your passkey “home” |
10 min |
2 |
Set up recovery before you need it |
10 min |
3 |
Add a passkey to one account (keep the password) |
5 min |
4 |
Run the Lost-Phone Drill |
10 min |
5 |
Roll out by tier, then tidy up passwords last |
Over 1–2 weeks |
Step 1: Which passkey “home” should you pick?
Your passkey home should be an account you can always get back into. Use this table to choose:
Your setup |
Good home |
Watch out for |
|---|---|---|
iPhone + Mac/iPad only |
Apple Passwords / iCloud Keychain |
Doesn’t sync to Android or Windows on its own |
Android phone + Chrome |
Google Password Manager |
Protected by your screen lock or a Google Password Manager PIN, so keep that PIN safe |
iPhone + Windows PC (or other mixed setups) |
A cross-platform password manager that supports passkeys, or Google Password Manager through Chrome |
Make sure you can recover that manager’s account |
You want extra-strong protection |
A hardware security key as a backup, plus your main home |
Keep a second key stored somewhere safe, in case you lose one |
A few facts that help you choose: Google says passkeys saved in Google Password Manager sync to devices where you’re signed in to Chrome or Android with the same Google Account, and Chrome can also save them on iPhone and iPad (iOS 17 and later). Apple says iCloud Keychain keeps passkeys and passwords up to date across your approved Apple devices. On Android 14 or later, you can also choose another password manager as your passkey provider.
Then lock down the home itself: use a long, unique password for that account, turn on two-factor authentication, and set a strong device passcode. If your iPhone offers Stolen Device Protection, switch it on. Anyone who can unlock your phone can potentially reach what it holds.
Step 2: How do you set up recovery before you need it?
This is the step most people skip, and it’s the one that saves you.
- Apple: add a Recovery Contact (Settings > [your name] > Sign-In & Security > Recovery Contacts). Apple says that if all your devices are lost, a recovery contact can help you recover your iCloud Keychain. Apple also supports recovery through iCloud Keychain escrow, which requires authenticating on a new device and answering a text message sent to a trusted phone number, with the record locking after several failed attempts. Pick a contact who doesn’t live with you, in case the same disaster hits both of you.
- Google: make sure your recovery phone number and email are current, and download your backup codes. Remember your Google Password Manager PIN or your phone’s screen lock, since you may need it to access passkeys on a new device.
- Password manager: save its recovery key or recovery code somewhere offline, such as a printed copy in a home safe or a safe deposit box.
- Your phone number: because recovery often involves a text message, lock down your cell account. Most major U.S. carriers let you add an account PIN or a number-lock setting to help block SIM-swap fraud, so check with yours.
Step 3: How do you add your first passkey safely?
Pick one low-stakes but real account, like a shopping site or a Google or Microsoft account you check often. Many major services support passkeys, but support varies, so look in the account’s security settings for “Passkeys” or “Sign in with passkey.”
- Sign in the normal way with your password.
- Open Security or Sign-in options and choose Create a passkey.
- Approve it with Face ID, Touch ID, your fingerprint or your device PIN.
- Confirm which home is saving it (iCloud Keychain, Google Password Manager or your password manager).
- Do not delete the password yet. At this stage you’re adding a second way in, not replacing the first.
- Sign out, then sign back in using the passkey to make sure it works.
Step 4: What is the Lost-Phone Drill?
This is the part nobody else bothers to test, and it’s the whole reason this plan works. You’re going to pretend your phone is gone and prove you can still get in.
- Use a second device (a laptop, a tablet or a family member’s phone, with their permission). Sign in to your passkey home there. For example, sign in to your Apple Account or Google Account in Chrome.
- Open the test account and sign in with the passkey from that second device.
- Check your recovery paths: can you find your recovery key or backup codes? Does your recovery contact know their role?
- Try the “no phone” path: if the site offers an alternative (a security key, backup codes, emailed link), confirm it works.
- Write down the result: date, what worked, what didn’t, and fix the gaps.
If anything fails, stop. Fix it before switching anything else. A failed drill on a test account is a free lesson; a failed login on your bank account is a bad Tuesday.
Step 5: In what order should you switch your accounts?
Switch in tiers. Start with accounts that hurt most if hijacked, but only after your drill passes.
Tier |
Accounts |
Why first |
Password plan |
|---|---|---|---|
Tier 1 |
Primary email, Apple/Google/Microsoft account, banking and payment apps, password manager |
Attackers use these to reset everything else |
Keep a strong password plus backup codes until you’ve tested twice |
Tier 2 |
Shopping, social media, cloud storage, work tools, streaming |
Common targets for scams and account takeover |
Keep password for a few weeks; remove it only if the site allows |
Tier 3 |
Everything else (forums, one-off signups) |
Lower risk, and many don’t support passkeys yet |
Leave as is, using unique passwords from your manager |
The golden rule: if a site lets you keep both a password and a passkey, keep both for now. Some sites do not yet offer account recovery that works well without a password, so removing it is a one-way door.
What can still go wrong with passkeys?
Passkeys are a big upgrade, not magic. Here’s the honest list:
Scenario |
What happens |
How to be ready |
|---|---|---|
You lose or replace your phone |
Synced passkeys come back when you sign in to your home account on the new phone |
Know your Apple/Google/manager login and have recovery set up |
You forget your Apple or Google password |
You can’t reach your synced passkeys until you recover the account |
Recovery contact, recovery key, backup codes |
Someone steals your unlocked phone or learns your passcode |
They may be able to use what’s on it |
Strong passcode, shield your screen in public, Stolen Device Protection (iPhone) or similar |
Your passkey home account gets hacked |
Attackers could reach your passkeys |
Long unique password, two-factor authentication, security alerts |
A site doesn’t support passkeys |
You keep using a password there |
Unique password from a password manager, plus two-factor authentication |
You switch from iPhone to Android (or vice versa) |
Passkeys may not transfer automatically between ecosystems |
Use a cross-platform manager or re-register passkeys on the new phone |
What are the most common passkey myths?
Myth |
Reality |
|---|---|
“If I lose my phone, I lose my accounts.” |
With synced passkeys and recovery set up, a lost phone is an inconvenience. The real risk is losing access to the account that stores them. |
“Passkeys store my fingerprint on the website.” |
Your fingerprint or face unlocks the private key on your device. It isn’t sent to the website. |
“I should delete all my passwords today.” |
Keep passwords until each passkey is tested, and keep them anywhere passkeys aren’t supported. |
“Passkeys make scams impossible.” |
They resist phishing, but scammers can still target your recovery steps, your phone number or you directly. See our guide on deepfake voice scams for the human side of this. |
“Only tech people use passkeys.” |
FIDO’s 2026 survey found that about three in four consumers have enabled at least one. |
Your Lockout-Proof checklist
- ☐ I chose a passkey home and secured it with a strong password, two-factor authentication and a strong device passcode
- ☐ I set up recovery (recovery contact or key, backup codes, current phone number)
- ☐ I added a passkey to one test account and kept the password
- ☐ I ran the Lost-Phone Drill on a second device and wrote down the result
- ☐ I’m switching accounts by tier, most important first
- ☐ I’m keeping a unique password anywhere passkeys aren’t supported
- ☐ I locked down my cell account with a carrier PIN or number lock
- ☐ I have a backup of my backup
Frequently asked questions
What happens to my passkeys if I lose my phone?
If your passkeys are synced through iCloud Keychain, Google Password Manager or a password manager, they’re available again once you sign in to that account on a new device. If you never set up sync or recovery, you may have to use each site’s own account recovery.
Are passkeys safer than passwords?
For most people, yes. Passkeys are phishing-resistant, can’t be reused across sites, and don’t send a shared secret to the website. They still depend on the security of your device and your passkey home account.
Can I use a passkey on my phone and my computer?
Yes. Synced passkeys work across devices that share the same account. You can also use your phone to sign in on a nearby computer, usually by scanning a QR code and confirming with your fingerprint or face.
Do I still need a password if I have a passkey?
Often, yes, at least for now. Many sites still keep passwords as a backup, and some services don’t support passkeys yet. Keep passwords until you’ve tested your passkey and recovery options.
Do passkeys work between iPhone and Android?
Passkeys saved in Apple’s system don’t automatically sync to Android, and Google’s work best inside Chrome and Android. Cross-platform password managers, or the cross-device QR-code sign-in, fill that gap.
What should I do if I lose my phone and my recovery options?
Contact the service’s account recovery or support team, use any backup codes or security keys you saved, and recover your Apple or Google account first. This is why Step 2 matters so much.
Which accounts should I switch to passkeys first?
Start with accounts attackers love most: your primary email, your Apple, Google or Microsoft account, and banking or payment apps. But only after you’ve tested your recovery plan on a lower-stakes account.
Are passkeys the same as two-factor authentication?
No. Two-factor authentication adds a second step to a password. A passkey replaces the password and, because it uses your device unlock, combines “something you have” with “something you are or know” in one step.








