The FIDO Alliance counted roughly five billion passkeys in use worldwide as of May 2026. Its 2026 consumer survey also found that 69% of people have passkeys on at least some accounts — and 93% still type a password every single day.
Both things are true at once, and together they describe where we actually are. Nearly everyone has started. Almost nobody has finished. Here's how to do the next stretch without locking yourself out.
What a passkey is, in one paragraph
Passkeys run on the FIDO2/WebAuthn standard. Rather than a secret you type, your device holds a cryptographic key pair: the private half never leaves your phone, laptop or hardware key, and the public half sits with the website.
Two things fall out of that. You can't be phished, because there's no secret to hand over to a convincing fake login page. And your credential can't leak in a breach, because the site never held it.
Turn on sync before you add anything
This is the step people skip, and it's the one that bites.
On Apple, that's iCloud Keychain with Face ID or Touch ID. On Google, it's Google Password Manager — Android 9 and up, plus desktop through Chrome. Microsoft has had passkeys as the default sign-in for new accounts since May 2025, wired into Windows Hello.
Sync is what lets a passkey survive a dropped phone. Skip it and your credential lives on one device and dies with it.
Do them in this order
Email first. It's the reset path for everything else you own, which makes it both the biggest prize for an attacker and the account whose loss unravels all your other precautions. Then your password manager. Then your platform account.
For each: sign in however you normally do, open security settings, pick "Add a passkey," confirm with your face or thumb. The whole thing takes about fifteen seconds, which is genuinely the easy part.
Sort out recovery first, not later
Here's where passwordless setups actually fail, and why the sequencing matters so much.
Generate your recovery codes and store them somewhere real before you delete the password. Once passwordless is your only way in, recovery gets much harder to trigger — that's deliberate, and it cuts both ways.
Then apply the two-device rule: every account that matters gets at least two independent ways to prove you're you. A second passkey on another device. A printed recovery code in a drawer. A spare hardware key. A recovery contact. A verified backup email. Pick any two, as long as they don't both live on the phone you're about to leave in a taxi.
One more distinction worth knowing: synced passkeys come back on a new device once you sign in to your platform account and pass a biometric check. Device-bound ones don't. Lose that device and the credential's gone for good.
Don't delete your passwords yet
After you've set up three or four passkeys there's a real temptation to go clean house. Don't, not for a while.
Keep one backup sign-in method on every account until you've actually tested recovery once and watched your passkeys show up on a second device. Yes, running both systems at once is untidy. It's also what 93% of people are doing right now, and tidiness is a worse reason to get locked out of your email than almost any other.
The point isn't to be fully passwordless by some date you set yourself. It's to make the most common attack — someone stealing a credential you typed into the wrong box — structurally impossible, without inventing a brand new way to lose access to your own life.
Image: I'm Zion, via Pexels





