Passkeys are a passwordless, phishing-resistant credential based on public key cryptography, usually unlocked with a device's built-in biometric or PIN. They are built on the WebAuthn standard and are designed to replace passwords for both convenience and resistance to credential-stuffing and phishing attacks.
Frequently asked questions
Do passkeys work across devices?
Yes, most platform implementations sync passkeys across a user's devices through their operating system or password manager account.
What happens if a customer loses the device with their passkey?
They can typically re-enroll a new passkey through an alternate authentication method, similar to recovering access after losing any other authenticator.
Are passkeys required, or can customers opt out?
Whether passkey enrollment is optional or mandatory is a policy decision the business configures; most implementations offer it as a recommended upgrade rather than a hard requirement.
.avif)