Passkey
A passwordless sign-in method using cryptographic key pairs, tied to a device and biometric or PIN unlock, that resists phishing by design.
Definition
A passkey is a passwordless authentication credential based on public-key cryptography, where a private key stays securely on a user's device and a corresponding public key is registered with the online service. Signing in requires unlocking the device with a biometric factor or PIN, and because there is no shared secret to type or steal, passkeys are inherently resistant to phishing.
When a user creates a passkey for a service, their device generates a unique cryptographic key pair, keeping the private key protected in the device's secure hardware and sending only the public key to the service. To sign in later, the service sends a challenge that only the correct private key can answer, and the user simply unlocks their device with a fingerprint, face scan, or PIN to authorize the response, without ever transmitting a password or secret over the network. Passkeys can sync across a user's devices through platform providers or be tied to a single physical security key, depending on the configuration chosen.
Passkeys matter because they directly eliminate the weaknesses that make passwords and even some multi-factor authentication methods vulnerable: there is no password to phish, reuse, or leak in a data breach, and no one-time code that can be intercepted or approved by mistake through MFA fatigue. Major platforms including Google, Apple, and Microsoft have adopted passkeys broadly, and adoption is accelerating across banking and enterprise applications as organizations look for phishing-resistant authentication. For sectors handling sensitive financial or personal data in Indonesia, passkeys represent a meaningful upgrade over password-based login.
Organizations adopting passkeys should provide clear guidance on backup and recovery, since losing the device holding a passkey without a backup method can lock a user out of their account. A gradual rollout that offers passkeys as an option alongside existing authentication, rather than an abrupt mandatory switch, helps employees and customers adjust to the new sign-in flow. Combining passkeys with continued password manager use for services that have not yet adopted them provides strong protection across an organization's full range of accounts.
At a glance
- Type
- Authentication method
- Also known as
- FIDO2 credential, WebAuthn
How it works
- 1
Key pair creation: the device generates a unique cryptographic key pair when a passkey is set up for a service.
- 2
Private key storage: the private key stays protected in the device's secure hardware and never leaves it.
- 3
Public key registration: only the public key is sent to and stored by the online service.
- 4
Sign-in challenge: the service sends a challenge that only the correct private key can answer.
- 5
Local unlock: the user unlocks their device with a fingerprint, face scan, or PIN to authorize the response.
Key points
- There is no shared secret to type or steal, making passkeys inherently resistant to phishing
- The private key never leaves the user's device
- Passkeys eliminate weaknesses in passwords and even some MFA methods, such as one-time codes intercepted through MFA fatigue
- Major platforms including Google, Apple, and Microsoft have adopted passkeys broadly
- Backup and recovery guidance matters, since losing the device can lock a user out without one
Best practices
- Offer passkeys as an option alongside existing authentication rather than an abrupt mandatory switch
- Provide clear guidance on backup and recovery in case a device is lost
- Continue using a password manager for services that have not yet adopted passkeys
- Prioritize passkey rollout for high-value accounts such as banking and email first
- Educate employees and customers on the new sign-in flow before requiring it
Real-world example
A digital bank in Indonesia rolls out passkeys for its mobile app alongside the existing password login. Customers who switch can no longer be phished for their login, since there is no password to type into a fake page, only a fingerprint unlock on their own device that a remote attacker cannot replicate.
How Claro helps
Claro's awareness content introduces passkeys in accessible terms so employees understand this emerging technology and adopt it confidently as their organizations roll it out.
Frequently asked questions
What is Passkey?
A passkey is a phishing-resistant login credential that replaces the password, using a cryptographic key pair tied to your device and unlocked with your fingerprint, face, or PIN. There is no secret to steal or type, so it cannot be phished.
Why are passkeys considered phishing-resistant?
There is no password or shared secret to type or steal. The private key never leaves the user's device, so a fake login page has nothing to capture.
Do passkeys replace multi-factor authentication?
Passkeys are inherently strong since they combine possession of the device with a biometric or PIN unlock, achieving what MFA aims for in a single, phishing-resistant step.
What happens if I lose the device holding my passkey?
This is why backup and recovery guidance matters. Passkeys can sync across a user's devices through platform providers, or organizations should provide an alternative recovery method.
Are passkeys widely supported yet?
Adoption is accelerating. Major platforms including Google, Apple, and Microsoft support passkeys broadly, and banking and enterprise applications are increasingly offering them.
Related terms
Password Manager
A tool that securely generates, stores, and autofills unique passwords for every account, so users never need to reuse or memorize them.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo