Set Up Passkeys Without Locking Yourself Out

Matthew Leo · September 22, 2026 · Guides

A person uses biometric sign-in on a phone beside a laptop, security key and recovery envelope.

Passkeys are easier to use than passwords and much harder to phish. They replace a typed secret with a cryptographic credential stored on your phone, computer, password manager or hardware security key.

The part people often skip is recovery. A passkey is convenient while your device works. Before making it your main sign-in method, make sure losing that device will not also lock you out of the account.

What a passkey changes

A passkey is created for one website or app. The private part stays in your credential provider, while the service keeps the public part needed to verify it. Because the passkey is tied to the real site, a fake sign-in page cannot collect and reuse it the way it can steal a password.

You normally approve sign-in with Face ID, a fingerprint, your device PIN or another screen-lock method. Your fingerprint or face data is not sent to the website. It is used locally to unlock access to the credential.

Many accounts still keep the password and other recovery methods after you add a passkey. Google, for example, says adding one does not automatically remove existing authentication or recovery factors.

Check recovery before creating the passkey

Open the account's security settings and confirm the basics first:

For an important account, do not rely on one phone as the passkey, the recovery number and the only signed-in device. One theft or broken screen could remove every route at once.

If you use two-step verification codes as a fallback, move them safely before replacing your phone. Mapletechie's authenticator transfer guide explains what to check.

Create a passkey only on a device you control

When a site offers “Create a passkey,” confirm where it will be saved. That may be Apple Passwords and iCloud Keychain, Google Password Manager, Windows, a third-party password manager or a hardware security key.

Do not create a passkey on a shared family computer, a workplace machine you do not control, a library computer or a borrowed phone. Google warns that anyone who can unlock a device containing its passkey may be able to access the associated Google Account.

On iPhone, passkeys saved through Apple require iCloud Keychain and two-factor authentication. They appear in the Passwords app and can sync to devices using the same Apple Account.

For a Google Account, open Passkeys and security keys, verify your identity and choose to create a passkey. Google supports recent versions of Chrome, Safari, Edge and Firefox, along with Android 9, iOS 16, Windows 10, macOS Ventura, ChromeOS 109 or later.

Add a second way to use the account

A second passkey can remove a single point of failure. The right backup depends on the account and your devices.

Two passkeys stored in the same bag are not much protection against theft. Separate the backup physically.

Test it before signing out everywhere

After creating a passkey, open a private browser window or another trusted device and try to sign in. Confirm which credential provider appears and whether you can choose another sign-in method.

Do not delete the password, remove recovery factors or sign out every other device until the test works. Some organizations also restrict passkey-only sign-in on work or school accounts, so the process may differ from a personal account.

If a passkey from your phone is used to sign in on a nearby computer, the computer may show a QR code. Scan it with the phone and approve the request. Bluetooth may be used to confirm that the phone is physically nearby.

Know what happens when you change phones

Synced passkeys can appear on a replacement device after you sign in to the same Apple Account, Google Account or password manager and complete that provider's recovery process. Device-bound passkeys and hardware keys do not work that way.

Before erasing the old phone:

  1. Confirm the passkey is available on the new device.
  2. Test a real sign-in.
  3. Check that your recovery email, phone and backup codes still work.
  4. Remove the old device from the account after the transfer succeeds.

This is separate from moving an eSIM or erasing the device. Use Mapletechie's guides to transfer an eSIM before erasing a phone and remove old devices from Apple or Google accounts.

If the phone is lost or stolen

Use another trusted device or the account's recovery flow to sign in. Remove the passkey associated with the lost device, sign the device out and use the platform's lost-device service to lock or erase it.

Removing an entry from the website may not remove a copy stored in a third-party password manager. Check both the account's security page and the credential manager.

Change the account password if the password still exists and may have been exposed. Also review recent sessions and security events rather than assuming the device lock solved everything.

Common passkey mistakes

Start with one important account, add a passkey, create a separate recovery route and test both. Repeat the process for other accounts only after you know where the credential is stored and how you would recover without your main phone.

Sources

Tags: passkeys, account security, passwords, recovery, security keys

Read on Mapletechie