Log inGet Vallkey

Search the help center, features, guides and more.

Guide

Passkeys: how to use them, and why they're safer

What passkeys are, why they can't be phished or leaked in a breach, and how to create and use them on every device.

A passkey replaces a password with a pair of keys. The website keeps the public half; your device keeps the private half and uses it to sign you in. There’s nothing to type, so nothing to phish, and nothing a breach of the website can leak.

Why they’re safer

  • Can’t be phished. A passkey only works on the site it was made for. A fake site gets nothing.
  • Can’t leak. The site stores only a public key, useless to anyone who steals it.
  • Can’t be reused. Each site gets its own.

Creating one

When a site offers a passkey, usually in its security settings, choose to create one. Your password manager or device asks where to keep it. Vallkey keeps it with your login, encrypted like everything else.

Using one

Next time, the site offers to sign in with a passkey. Confirm, and you’re in.

Passkeys on every device

Passkeys kept by Apple or Google stay inside their ecosystem. A cross-platform password manager like Vallkey syncs them to every device you use: iPhone, Android, Windows, Linux, and every major browser.

Keep your password too, for now

Many sites still let you sign in with a password as a fallback. Keep it strong and unique, in your password manager.

Last updated October 3, 2026