How to Use a Passkey Without Getting Locked Out of Your Account
Passkeys are easier to manage when you understand which credentials sync, which stay on one device, and how recovery works. I’ll explain the choices to make before replacing or losing a phone, including backups, security keys, and cross-device sign-in.
Passkeys can make sign-in faster and more resistant to phishing, but they change what “having access” means. Your account may depend on a passkey stored on a phone, synced through a password manager or platform account, or held on a separate security key. If you replace or lose the wrong device without preparing, the sign-in problem can be harder to solve than a forgotten password.
The sensible approach is to treat a passkey as one part of an account-access plan. Before relying on it, find out where it is stored, whether it can sync, and which recovery methods the service accepts.
Understand what kind of passkey you have
A passkey is a cryptographic credential. During registration, your device creates a key pair: the private key stays protected by your device or credential manager, while the service receives the corresponding public key. When you sign in, your device proves that it has the private key after you unlock it with a fingerprint, face scan, device PIN, or another local method. The service doesn't receive your biometric data.
That basic process is similar across passkeys, but storage differs. A passkey saved in a platform credential manager may sync through your Apple, Google, or Microsoft account, depending on the device and service. A passkey stored in a password manager may sync through that manager instead. Some passkeys are deliberately device-bound, such as those created on certain hardware security keys. A device-bound credential generally won’t appear automatically on a replacement phone.
This distinction matters more than the word “passkey.” Two passkeys registered to the same account can have very different recovery implications. One might be available on several of your devices; another might exist only on a security key in a drawer.
Open the account’s security or sign-in settings and inspect the registered passkeys. The wording varies: a service might show a device name, credential provider, creation date, or a label such as “phone,” “password manager,” or “security key.” If the service allows you to rename credentials, use names that will still make sense when you are troubleshooting months later.
Check your passkey’s home: Before you depend on a passkey, confirm whether it syncs through a platform or password manager, or remains only on the device where you created it. Also note whether the account offers another usable sign-in method.
Passkey syncing is useful, but it isn’t the same as account recovery
A synced passkey can reduce the risk of losing access when you move to a new phone. After you sign in to the same platform or password-manager account and complete its security checks, the passkey may become available on the new device. The exact behavior depends on the provider, operating systems, account settings, and the service where the passkey is registered.
Syncing is also protected. Credential managers typically encrypt passkeys, and some use end-to-end encryption or an additional recovery process. That protection is valuable, but it means the sync account itself must be recoverable. If you lose access to the account that stores your passkeys, the passkeys may not help you regain access to the service.
A recovery code, backup code, alternate authenticator, trusted device, or support-assisted account recovery is a separate mechanism. It may let you regain the account when no passkey is available, but it doesn't necessarily restore the missing passkey. After recovering the account, you may need to register new passkeys and remove credentials associated with a lost device.
For important accounts, aim for two independent paths rather than two copies of the same path. For example, a synced passkey plus a printed recovery code stored securely is more resilient than two passkeys that both depend on a phone you no longer have. Don't store recovery codes in an unprotected note or photograph if someone else could access them.
Prepare before replacing your phone
The safest time to test recovery is while your old phone still works. Sign in to the account’s security page and identify every available option. Look for passkeys, passwords, recovery codes, authenticator apps, backup methods, trusted devices, and security keys. Some services let you download recovery codes only after re-authentication, so do this before wiping or trading in the old phone.
Next, set up the replacement phone without immediately removing the old one. Sign in to the relevant platform or password-manager account, install required updates, and confirm that your passkeys appear where expected. Then sign in to one or two important services using the new phone. A passkey appearing in a credential manager doesn't by itself prove that the destination service will accept it in the situation you care about.
If your old phone contains an authenticator app, transfer its accounts according to that app’s instructions. Some authenticator apps sync codes; others require an export, transfer process, or fresh enrollment. Keep the old phone available until you’ve tested the replacement and recorded any account-specific recovery requirements.
Only after testing should you erase the old phone or remove it from your accounts. Removing a device from a service can be sensible when you no longer control it, but removing the wrong credential too early can eliminate a working route while you are still setting up the new one.
Sign in on another device with your phone
A passkey doesn't have to be stored on the computer where you’re signing in. Many services support a cross-device option, often labeled “use a passkey from another device” or something similar. You typically select that option on the computer, scan a QR code with your phone, and approve the sign-in on the phone.
The phone and computer may need Bluetooth enabled so the devices can establish that they are near each other. This doesn't mean the private passkey is transmitted to the computer. The phone performs the authentication, while the computer receives the result needed to continue signing in. Menus and proximity requirements differ, so follow the prompts shown by the service and operating system.
Cross-device sign-in is helpful when you use a shared or temporary computer, or when a passkey is available on your phone but not yet on the computer. It isn't a replacement for preparing account recovery. You still need the phone, its unlock method, and a working connection for the sign-in flow. If the phone is lost, the QR-code option can't magically retrieve its passkey.
Avoid approving an unexpected sign-in request just because a QR code or prompt appears. Start the process from the genuine website or app, check the address carefully, and cancel anything you didn't initiate.
Decide whether to add a security key
A hardware security key can provide another passkey or another form of strong authentication. It is useful for accounts where losing a phone would have serious consequences, such as your primary email, password manager, financial accounts, or an administrator account. Depending on the model and service, the key may connect through USB, NFC, or another supported interface.
The main trade-off is responsibility for the physical device. A security key is often device-bound, so it generally doesn't sync to a replacement key. If you register only one and lose it, you may need a recovery code, another registered authenticator, or the service’s account-recovery process. If the account supports it, registering two keys is more robust: keep one available and store the spare somewhere separate and secure.
Label keys by purpose rather than location alone. “Primary account key” and “Spare account key” are more useful than “desk key,” especially if you move or change computers. Test each key after registration, and confirm that the account still offers a recovery option you can use if both keys are unavailable.
A security key isn't automatically necessary for every account. For many people, a synced passkey, a protected recovery code, and a second registered device provide a reasonable balance. The right choice depends on how damaging account loss would be and how reliably you can store and maintain extra hardware.
What to do if the phone is lost
Use a device-finding service to lock or erase the phone when appropriate, and contact your mobile carrier if your number or SIM could be misused. These actions involve current service settings and local procedures, so use the official controls for your device and carrier rather than relying on a generic sequence.
Then try the account’s remaining access routes: a synced passkey on another device, a security key, an authenticator, a recovery code, or a previously trusted device. If you regain access, review the account’s security page. Remove the lost phone or its passkey if the service provides that control, change credentials that may have been exposed, and register a replacement passkey.
If no alternate route works, use the service’s official recovery process. Be cautious with anyone offering to “recover” the account for a fee through unofficial channels. Legitimate support won't need your recovery codes, private key, device PIN, or one-time authentication codes.
A resilient setup in practice
For an account you can't afford to lose, begin with a passkey you understand and can use today. Add a second passkey on another device or in a separate credential manager only if you can protect and recover that provider account. Generate recovery codes when the service offers them, store them offline in a secure place, and test your fallback method before an emergency.
If the account is especially important, add two compatible security keys or another independent authentication method. Keep your device operating systems, browsers, and credential managers current, but don’t treat updates as a substitute for recovery planning.
The goal isn't to collect every possible authenticator. It is to avoid a single point of failure. Know where each passkey lives, keep at least one independent recovery route, and verify the arrangement before replacing or discarding a phone. That small amount of preparation lets you keep the convenience of passkeys without making one lost device the key to your entire digital life.