Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
News

How to Set Up Passkeys on Windows, Android, iPhone and Mac

|Author: Viacheslav Vasipenok|9 min read| 14
How to Set Up Passkeys on Windows, Android, iPhone and Mac

To create a passkey, sign in to a website or app that supports it, open the account’s security settings, choose the passkey option, verify the account and storage destination, then approve with your device PIN, fingerprint or face recognition. Labels vary, but Google’s registration instructions confirm this basic sequence.

Before approving the prompt, decide whether the passkey should remain on one device, synchronize through a password manager or be stored on a hardware security key. Keep another working sign-in or recovery route until you have tested the credential on every device you expect to use.

Understand what a passkey creates

A passkey belongs to one account at one website or app. It is not a universal credential, and you cannot create one unless that service supports passkey registration.

Registration creates a public-private key pair. The service stores the public key, while the private key remains under the control of your device or passkey provider; Apple’s passkey security explanation confirms that the server never learns the private key. Your biometric check or device PIN authorizes use of the credential locally rather than being sent to the website.

Passkeys are based on shared standards rather than being exclusive to one operating system. The FIDO Alliance’s passkey overview describes them as FIDO credentials built on cross-platform specifications.

Choose where the passkey will be stored

Choosing between local, synchronized, mobile-device and hardware-key storage for a new passkey.

The storage destination determines where the passkey is available and what happens when you replace a device. Read the creation dialog carefully, especially on a computer with several browser profiles or credential providers.

  • Synced password manager: The provider encrypts and synchronizes the passkey to supported environments where you have signed in and completed its security checks.
  • Local device: The passkey remains on that computer or phone and will not automatically appear on its replacement.
  • Phone or tablet: The mobile device holds the credential and can approve sign-in on a nearby computer.
  • Hardware security key: The physical key stores a device-bound credential and must be available when you authenticate.

Synchronization follows the selected provider, not simply the operating system or browser name. Google’s platform documentation explains that Google Password Manager synchronizes passkeys across Android and supported Chrome environments, while provider choices vary by platform.

For critical accounts, keep a private inventory containing the service name and the provider holding its passkey. Do not try to record a private cryptographic key; the useful recovery information is which provider account or physical key you need.

Set up a passkey on Windows

  1. Sign in to the supported website, app or service with its existing method.
  2. Open its account, security or sign-in settings and select the option to add a passkey.
  3. At the save prompt, accept the suggested password manager or choose another destination, such as a phone, security key or Windows Hello.
  4. Approve creation with the requested Windows Hello PIN, fingerprint, face recognition, phone confirmation or security-key action.
  5. Return to the service’s security settings and confirm that the new passkey is listed.

Microsoft’s Windows instructions distinguish synchronized password-manager storage from Windows Hello storage, which keeps the passkey locally on the Windows device. They also list a phone or tablet and a physical security key as possible destinations.

For a Microsoft personal account, open Advanced Security Options, select Add a new way to sign in or verify, then choose Face, Fingerprint, PIN, or Security Key. Work and school accounts may offer fewer destinations because the organization can restrict permitted options, as the same Microsoft instructions note.

If you choose local Windows Hello storage, register another passkey or retain another recovery method. A local credential will not appear automatically on a replacement PC merely because you use the same Microsoft account.

Set up a passkey on Android

  1. Enable a secure screen lock on the phone or tablet.
  2. Sign in to the supported app or website and find its account security settings.
  3. Select Create a passkey and check the displayed account and password manager.
  4. Choose another enabled provider if you do not want the suggested destination.
  5. Approve creation with the Android screen lock, then confirm that the service lists the credential.

Google Password Manager is enabled by default as a passkey provider on Android. On Android 14 or later, compatible alternatives can be selected in system settings, although Google’s Android compatibility notes warn that some manufacturers’ devices may not reflect this behavior.

If you use Google Password Manager, verify the Google Account shown in the prompt. Google’s synchronization documentation states that its synchronized passkeys are end-to-end encrypted and that decrypting them in a new environment requires the relevant Google Account plus an Android screen lock or Google Password Manager PIN.

Set up passkeys on iPhone and Mac

If you intend to use Apple’s synchronized storage, first enable iCloud Passwords & Keychain. On iPhone, open Settings > your name > iCloud > Passwords and enable synchronization; on Mac, open System Settings > your name > iCloud > Passwords and select Sync this Mac, following Apple’s iCloud Keychain setup paths.

Next, sign in to the supported website or app, open its security settings and choose to create a passkey. Check the Apple Account and credential provider shown in the prompt, approve with the available local authentication method, then verify that the service lists the new credential.

Passkeys stored in iCloud Keychain synchronize between approved Apple devices signed in to the same Apple Account. Apple’s iCloud Keychain security overview says keychain items are encrypted end to end while travelling through Apple’s servers, preventing Apple and unapproved devices from reading them.

Enabling a different credential provider can change where a newly created passkey is offered or saved. Check the provider name rather than assuming that using Safari, Chrome, an iPhone or a Mac guarantees a particular storage destination.

Verify the first sign-in before removing a fallback

After registration, sign out of the service and begin a new session rather than relying on an already authenticated tab. Select the passkey, check the account name and complete the local unlock prompt.

Then inspect the service’s security page again. Keep the existing password, recovery code, trusted device or other supported recovery route until this clean sign-in succeeds and you understand whether the passkey is local or synchronized.

If the passkey does not appear, check the active browser profile, password-manager account and provider selected in system settings. Creating another credential in the intended provider is generally safer than deleting the only working passkey while diagnosing the mismatch.

How QR and Bluetooth cross-device sign-in work

A phone approves nearby computer sign-in through a passkey QR and Bluetooth proximity flow.

A cross-device flow lets a phone holding the passkey approve sign-in on a nearby computer without copying the private key to that computer. On the computer, choose an option such as Passkey from nearby device, display the QR code, scan it with the phone and approve the expected account and website.

The FIDO flow uses Bluetooth Low Energy to establish that the devices are physically close. FIDO’s cross-device authentication guidance explains that the hybrid CTAP transport adds cryptographic protection and does not depend on Bluetooth’s security properties alone.

The credential remains with the phone or its provider. The phone signs the authentication challenge and returns the result to the other device, so scanning the QR code does not migrate the passkey into the computer’s password manager.

Enable Bluetooth on both devices, keep them nearby and scan only a QR code from a sign-in page you intentionally opened. Read the approval prompt before unlocking the phone; it should identify the service and account you expect.

Switch devices or password managers safely

Do not erase the old device or remove the old provider first. Establish and test access in the new environment before retiring the previous route.

  1. Confirm that the service still offers a working password, recovery code, trusted device, security key or another account-recovery method.
  2. Install or enable the existing passkey provider on the new device and complete its account and decryption checks.
  3. Test a fresh sign-in without relying on an authenticated browser session.
  4. If the passkey does not synchronize, use the old device for cross-device sign-in or use another recovery method.
  5. Create a new passkey directly in the new provider and test it in a separate browser profile or private window.
  6. Remove obsolete credentials from the service’s account settings only after the replacement works.

Changing a browser’s default password manager does not necessarily move existing passkeys. FIDO’s platform-switching guidance recommends configuring a cross-platform provider on the new device or using the old device to sign in and register a new passkey with the new provider.

For iCloud Keychain users, an Apple Account recovery contact can help restore access to the Apple Account but is not a replacement passkey for an individual website. Apple’s recovery-contact instructions explain that the contact can provide a recovery code but cannot access the account.

Avoid shared-device and business-account mistakes

Do not save a local passkey in a Windows account, browser profile or device profile that another person can unlock. On a borrowed or public computer, prefer a nearby-phone flow or a security key and avoid any option that saves the credential locally.

Sharing a passkey grants account access. Apple permits trusted groups to share passwords and passkeys, but Apple’s shared-group guidance notes that other members retain access to credentials already shared with them if the original user later leaves or loses access to the group.

For a business account, document the approved provider, account owner, recovery route and offboarding process. Avoid making one employee’s personal phone or cloud account the only path into a critical service; use organization-controlled identities and hardware where individual accountability or rapid revocation is required.

Complete a safe setup

Start with an important but recoverable account. Create its passkey in the provider you intend to keep, verify the displayed destination and complete a clean sign-in on the same device.

Next, test synchronization on another approved device or complete the QR and Bluetooth flow with your phone. Remove an older credential only after both routine access and a separate recovery route work.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0