Local Tech Fix (626) 655-0020
All articles

What Is a Passkey — and What Happens If You Lose the Phone It Is Saved On?

September 7, 2026

A passkey is not a file that travels with you. It is a secret that stays on a device — which is why the useful question is never "what is a passkey" but "whose keychain did mine go into".

Somewhere in the last couple of years, signing in changed. Google, Microsoft, Amazon, PayPal, the bank, the airline — at some point in the middle of a perfectly ordinary sign-in, each of them has put up a screen offering to set up a passkey, usually with a picture of a fingerprint and a big blue button. Most people do one of two things. They tap the blue button without any idea what they have just agreed to, or they tap "Not now" and then keep tapping "Not now" for the next two years. Both reactions are completely reasonable, because nobody has ever told them what the thing is.

We should admit our own part in this. Our page on getting back into a locked Microsoft or Google account ends by suggesting you "consider a passkey, which both companies now prefer over SMS" — good advice that is useless on its own, because it never says what one is or what you are signing up for. This page is the missing explanation, written for the questions people actually ask us at the kitchen table rather than the ones the technology press asks.

Our honest position first, so you know where this is going: for most of our customers a passkey is a genuine improvement, and the strongest reason has nothing to do with convenience — it is that a passkey cannot be read out over the telephone to a stranger, which is how most of the money in Southern California actually gets lost. The one real gotcha is not security at all. It is household mix, and specifically the very common combination of an iPhone in your pocket and a Windows PC on the desk. That section is the one to read if you read only one.

What a passkey actually is, in one paragraph you only have to read once

When you create a passkey, your device makes two matching halves of a mathematical key and gives one of them away. Microsoft's own documentation puts it as plainly as anyone: "When a user registers with an online service, their client device generates a new key pair. The private key is stored securely on the user's device, while the public key is registered with the service." The half the website keeps cannot be used to sign in as you. The half that can never leaves your device.

That is the whole trick, and everything else follows from it. There is no password stored on the company's servers that a thief can steal in a breach, because there is no password. When you sign in, the site sends a challenge, your device signs it with the private half, and the site checks the signature against the public half it already has. Nothing secret crosses the internet in either direction.

Your face or fingerprint is not the passkey either — it is only the way you unlock the device so the device will use the passkey on your behalf. Microsoft states the privacy side directly: "any biometric information used in the authentication process remains on the user's device and isn't transmitted across the network or to the service." We get asked about this constantly, usually as "I don't want Google having my fingerprint," which is a perfectly sensible worry aimed at the wrong thing. Google never receives it. The fingerprint sensor talks to your phone and nothing else.

One more property worth knowing, because it matters later: "passkeys are unique to each website or application, preventing their reuse." You do not have "a passkey" the way you have a favourite password you have used on eleven sites since 2011. You have one per account, generated fresh, and reusing them is not merely discouraged — it is not possible.

The sentence that clears up most of the confusion about passkeys

Here it is: a passkey is not a file that travels with you. It is a secret that lives in a keychain, and almost every confusing thing that happens later is explained by which keychain it went into.

When you tapped that blue button, something decided where to save it. Sometimes it asked you in a small dropdown you did not read; often it simply picked the obvious default for the device you were holding. There are five realistic answers. Apple's iCloud Keychain, on an iPhone, iPad or Mac. Google Password Manager, on an Android phone or in Chrome. Windows Hello, saved onto that specific Windows computer. A password manager app you already pay for. Or a physical security key on your keyring, which is a niche choice but a real one.

Practically nobody notices making that choice, and practically everybody runs into its consequences. "Why is my passkey on my phone but not on my computer?" is not a bug report. It is the answer to a question you were asked and did not know you were answering.

So which keychain has yours — and why one of them behaves completely differently

If it went into iCloud Keychain, it spreads across your Apple things. Apple's security documentation is one sentence on the point: "Passkeys sync across a user's devices using iCloud Keychain." Create it on the iPhone and it is on the iPad and the Mac, without you doing anything.

If it went into Google Password Manager, the same is true across the places you are signed into that Google account — an Android phone, another Android phone, Chrome on a computer where you are signed in.

If it was saved to Windows Hello on a particular PC, it behaves completely differently, and this is the one people get caught by. Microsoft calls this "a device-bound passkey (a passkey stored to your Windows device)". It does not sync. It is on that computer, and it is nowhere else on earth. Microsoft describes the alternative in the same breath: "If you save a passkey to a synced credential manager (such as Microsoft Password Manager), your passkeys sync through your cloud account allowing you to sign in using a different device."

The consequence is worth writing on a sticky note, because it is the difference between a mild inconvenience and a bad afternoon. A device-bound passkey on a desktop whose drive has died is gone. Not "recoverable with effort," not "restorable from a backup" — gone, permanently, by design. That is not a flaw in passkeys. It is precisely the property that makes them impossible to steal remotely. But it does mean the machine in the corner of the home office is a single point of failure in a way your old written-down password never was.

What actually happens if you lose the phone

This is the question everybody asks first and it has no single answer, because it depends entirely on which keychain you landed in.

On an iPhone, the honest answer is: probably nothing bad. The passkeys are in iCloud Keychain, which Apple describes as "end-to-end encrypted with strong cryptographic keys not known to Apple" — meaning Apple itself cannot read them — and which is nonetheless, in Apple's words, "recoverable even if the user loses all their devices." Sign into your Apple Account on a replacement iPhone and your passkeys come back with everything else.

The step worth taking before you need it takes about two minutes. Apple notes that "optionally, a user can set up an account recovery contact to make sure that they always have access to their account." A recovery contact is a person you trust — an adult child, a sibling — who can help you back in if the usual routes fail. Nobody sets this up in the middle of a crisis, which is exactly why it should be done on a quiet Sunday. It is under Settings, your name, then Sign-In & Security.

On Android, a new phone signed into the same Google account gets there the same way. But there is a housekeeping step almost everyone skips, and Google states it plainly: "If you lose a device with your passkey, or created a passkey on a shared device by mistake, remove the passkey on your Google Account." Do that from any other device, the same afternoon. It is a two-minute job that closes a door.

And if the passkey was device-bound on a Windows machine that has died, it is gone, and you get back in the ordinary way — with your password, or your recovery codes, or your authenticator app — and then you make a new one.

Which produces the rule that covers all three cases and is really just our standing advice about two-factor authentication wearing a new hat: never let a passkey be the only way into an account. Keep a second route open. A second passkey on a second device is the neatest version. An authenticator app is fine. The account's printed recovery codes in a drawer are the oldest trick and still the one that saves people. The failure we are called out to fix is almost never "the security was too weak." It is "there was exactly one way in and it stopped existing."

Can I sign in on a computer that is not mine? Yes — and the mechanism explains its own limits

You can, and it is one of the better-designed things in modern computing. Google's own instructions for using a phone passkey on a computer run like this: on the sign-in page, enter your username, click "Try another way" and then "Use your passkey"; a QR code appears on the computer screen; scan it with your phone's camera; and on the phone, "tap Use passkey to sign in."

The genuinely interesting part is what the QR code is not doing. Microsoft spells it out: "For passkey cross-device authentication scenarios, both the Windows device and the mobile device must have Bluetooth enabled and connected to the Internet. This allows the user to authorize another device securely over Bluetooth without transferring or copying the passkey itself."

Read that last clause twice. The passkey does not move onto the borrowed computer. Nothing is copied there, and so nothing is left behind on it when you walk away. Your phone simply vouches for this one sign-in, once. That is why doing this on a hotel business-centre machine or a library computer is safe in a way that typing your password into one never has been — the password would still be in that machine's memory, its browser and possibly its keystroke log after you leave. The passkey was never there at all.

The Bluetooth requirement is not bureaucracy either; it is the security model. The two devices have to prove they are physically in the same room. That explains every limitation people run into with this feature, and none of them are faults. It will not work if Bluetooth is switched off on either device. It will not work on a locked-down work laptop where Bluetooth is disabled by company policy. And you cannot walk your son through it over the telephone from three states away, because the phone holding the passkey has to be next to the screen showing the code.

That same constraint is quietly protecting you. Nobody in a call centre overseas can put a QR code in front of you and have you approve their sign-in on a computer in another country, because their computer is not in your kitchen.

The awkward household: an iPhone and a Windows PC

This is the single most common setup we walk into across the San Gabriel Valley, Orange County and the desert: an iPhone in a pocket or handbag, and a Windows desktop or laptop on the desk. And passkeys behave worse in that exact combination than in any other, which neither company will tell you, because each one's help pages describe only its own half of the house.

Here is what happens. You set up the passkey on the iPhone, because that is where the prompt appeared. It goes into iCloud Keychain and syncs beautifully to the iPad. Then you sit down at the Windows PC, open Chrome, go to sign in — and it is not there. Nothing is broken. It was never going to be there.

Apple does publish software that brings iCloud things to Windows, which is why people expect this to work. But look at what those pages actually describe: using iCloud Passwords "to access your passwords in Google Chrome, Microsoft Edge, or Firefox using a browser extension," and managing "your passwords in the iCloud Passwords app on your Windows computer." Passwords, and verification codes. Apple's own instructions for the Windows app do not list passkeys among the things it does. We are not going to tell you it is impossible in every future version — but do not plan your household around your iPhone passkeys turning up on the PC, because right now Apple does not say they will.

So there are three things that actually work, and the second is the one we set up for people nine times out of ten.

The first is to just do the QR-code-and-Bluetooth handshake each time, as described above. It works. It is completely fine for an account you touch twice a year. It is tedious for the email you open every morning, and it fails on the mornings the phone is charging in the other room.

The second is to give the PC its own passkey. This is the bit almost nobody realises: an account is not limited to one passkey. You can have several, on several devices, all valid at once. So sign into the account on the Windows PC however you normally do, go into that account's security settings, and add a passkey while you are sitting there. It saves to Windows Hello on that machine. From then on the PC signs you in with your face or your PIN and never asks for the phone at all, and the iPhone keeps its own passkey for when you are out. Two devices, two passkeys, one account, no handshake, nothing to remember. That is the answer.

The third is for people who want one keychain covering everything: a password manager that registers itself with Windows as a passkey provider. Windows 11 supports a plugin model for passkeys, and providers you have installed show up under Settings, then Accounts, then Passkeys, then Advanced options, where you switch them on. This is a good route if you already pay for a password manager and use it on both the phone and the PC. It is not, in our view, a good reason to go and adopt one from scratch — the second option above is free and takes ninety seconds.

One caution before you commit to a keychain. The FIDO Alliance, the standards body behind all of this, has published credential exchange specifications intended to let people move passkeys between providers. That is a standards effort in progress, not a button you can press today. So do not choose your keychain on the assumption that moving later will be easy. Choose the one that matches the devices actually in your house.

Do I still need my password?

For nearly every account, yes, and that is fine. The passkey is an additional, faster door into the same house. The password stays where it was, as the way in when you are on a strange device, or when you have replaced everything at once.

Microsoft is the exception worth knowing about, because it will let you get rid of the password entirely. In their words: "Going passwordless refers to removing your password and using a passwordless method to sign in instead." You do it from your Microsoft account's Additional security options, under "Passwordless account," and turning it on. Afterwards you sign in with, again quoting Microsoft, "the Microsoft Authenticator app, Outlook for Android, Windows Hello, physical security keys, or SMS codes." It is reversible — the same page has a "Turn off" that lets you add a password back.

Before anyone in a house with older equipment does this, read Microsoft's own warning: "Some older versions of Windows, apps, and services still need a password." The incompatible list they publish includes Xbox 360, Office 2010 or earlier, and Windows 8.1 and earlier.

Our advice for most of the homes we visit is therefore simple and slightly boring. Add the passkey. Keep the password. If there is a working older laptop in the spare room, an Office install from 2010 that still opens the accounts spreadsheet, or a games console the grandchildren use, removing the password will strand it, and you will not connect the two events three weeks later when it stops working. You get essentially all the benefit from having the passkey; deleting the password is the last five percent and it can wait a few years.

Where to find the passkeys you already have, and how to remove the wrong ones

On Windows, they are in Settings, then Accounts, then Passkeys. Microsoft notes that "starting in Windows 11, version 22H2 with KB5030310, Windows provides a native experience for passkey management," so this page exists on anything reasonably current. To get rid of one: "To delete a device-bound passkey (a passkey stored to your Windows device), select Delete passkey next to the passkey name."

There is a second Windows page worth knowing about, because it causes a support call we have started to see. "Starting in Windows 11 version 24H2, users are prompted for privacy consent before applications can access passkeys." If someone tapped "no" on a consent box they did not read, passkeys will silently stop working in that one application, with no obvious explanation. The fix is in Settings, then Privacy & security, then Passkey access, where you can allow or block each app individually. If passkeys work everywhere except in one program, that is the page to check first.

On an iPhone, iPad or Mac, they live in the Passwords app: "The Passwords app makes it easy to access your account passwords and passkeys, Wi-Fi passwords, and verification codes all in one place." That app arrived in iOS 18, iPadOS 18, macOS Sequoia and visionOS 2. On anything older, the same list is under Settings, then Passwords.

For a Google account, the list is in the account's security settings, and removing individual entries is the same instruction Google gives for a lost device.

A good annual habit, and one we do as part of a tune-up: walk that list and delete the entries for hardware you no longer have. The laptop you sold on Craigslist. The phone you traded in. The work computer you handed back when you retired. Each stale entry is a door you have stopped watching.

The real reason we recommend them: a passkey cannot be read out over the telephone

Most of what we write about security comes back to the same small group of cons. The full-screen "your computer is infected, call this number" pop-up. The fake bill-payment site that outranked the real one. The search result that was an advert for a fake support line. They differ in the details and they all end identically: a person is talked into typing something, or reading something aloud, to a stranger who sounded official.

A passkey removes the material the con needs. There is nothing to read out. There is no six-digit code arriving by text that a caller can talk you into repeating. There is no "just confirm your password so I can verify the account." The secret never leaves the device and cannot be spoken.

And the site-matching is done by machine rather than by judgement, which is the part we would underline if we could. Microsoft: "Passkeys are enforced by the browsers or operating systems to only be used for the appropriate service, rather than relying on human verification." In plain English: the reason intelligent people fall for a convincing fake login page is that a human being has to squint at an address bar and make a decision, usually while distracted and slightly worried. A passkey does not ask you to make that decision. It simply will not offer itself on a site that is not the real one. A pixel-perfect copy of your bank's sign-in page gets nothing at all, because the passkey is not fooled by what the page looks like.

We spend a great deal of time cleaning up after the other outcome — and it is worse than a lost password, because by the time somebody calls us the intruder has usually been in the email for a week and set up forwarding rules. That is why, when we set up a machine for someone, the passkeys go on the accounts that matter.

What we would actually do, in order

Start with email, and do not start anywhere else. Whoever controls your email controls every other account you have, because every other account resets through it. If you only ever add one passkey in your life, add it there.

Add it on the device you use most, and leave the password alone for now. You want the fast door; you do not yet want to brick the old laptop.

Then add a second passkey on your second device — and if that is an iPhone plus a Windows PC, this is the step that makes the whole thing pleasant instead of annoying. Both devices, one account.

Now check that your fallback still works, before you need it. Are the account's recovery codes saved somewhere physical? Is the recovery phone number one you still own — not the landline you gave up, and not the mobile number of somebody who has moved out? Is there an Apple recovery contact? Ten minutes here is worth more than any of the rest of it.

Then move on to the accounts with money behind them: the bank, PayPal, Amazon, the brokerage. Same pattern each time — add the passkey, keep the password, verify the fallback.

And once a year, prune the list of devices. It takes five minutes and nobody ever does it.

The short version

A passkey is a secret that stays on one of your devices and proves who you are without anything being typed, sent or spoken. Losing your phone is not a disaster if the keychain syncs, and it is a genuine disaster if the only copy was device-bound and you had left yourself no second way in. The household with an iPhone and a Windows PC needs two passkeys rather than one, and setting up the second one takes about ninety seconds. Keep your password for now unless you are certain nothing old in the house still needs it.

If that is more decisions than you want to make, this is exactly the kind of thing we sit down and do with people — patiently, at the kitchen table, on the accounts that actually matter, and without rushing anyone through a screen they did not understand. A great deal of our work across the desert and the retirement communities we serve is getting people back into accounts after something like this went wrong; setting it up properly in the first place is the cheaper half, and the half we would rather do. If you would like a hand with it, give us a call.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →