The pitch for passkeys has always been that they kill the password. The more useful way to think about them in 2026 is narrower: they kill the password you type, but not the password-shaped hole underneath your account when something goes wrong. That gap, not the login screen, is the part of this story most coverage skips.
Key takeaways
- The FIDO Alliance says 5 billion passkeys are now in active use worldwide, with 75% of people having enabled one on at least one account, as of its May 2026 State of Passkeys report.
- A passkey is a public-key credential: your device holds a private key that never leaves it, and the service only ever stores a public key, which is why passkeys resist phishing in a way passwords cannot.
- Account recovery, not day-to-day login, is the unresolved weak point: FIDO2 has no built-in recovery flow, so losing every device still routes you back to an email reset link.
- Passkeys do not yet move cleanly between Apple, Google and Microsoft ecosystems; the cross-platform Credential Exchange Protocol that would fix this is still a draft spec.
How Passkeys Actually Work
A passkey replaces the shared secret model of a password with public-key cryptography, built on the WebAuthn standard. When you register a passkey for an account, your device generates a matched pair of cryptographic keys: a private key that stays on your device and a public key that gets sent to the service, according to Apple's own support documentation. Logging in later means your device uses the private key to answer a challenge from the server, confirmed locally by your fingerprint, face scan, or device PIN. The server never sees a secret it could leak in a breach, and there is no password string for an attacker to phish out of you by email.
That is the core security win: a passkey cannot be guessed, reused across sites, or typed into a fake login page, because there is no string of characters to steal in the first place. Apple notes that passkeys on its platforms sync through iCloud Keychain, which it describes as end-to-end encrypted with keys Apple itself cannot read. Google and Microsoft run equivalent systems through Google Password Manager and Windows Hello, each tied to its own account ecosystem.
Adoption Crossed a Real Threshold in 2026, Not Just a Marketing One
For a few years, passkeys were a feature vendors talked about more than people used. That changed this year. The FIDO Alliance's State of Passkeys 2026 report, released on World Passkey Day (May 7, 2026) and based on a survey of 11,000 consumers and 1,400 enterprise decision-makers across ten countries conducted by Sapio Research, puts the installed base at 5 billion passkeys in active use worldwide. Awareness has reached 90% of people surveyed, and 75% say they have enabled a passkey on at least one account. Regular, repeated use is lower but still substantial at 49%, which tells you the gap now is habit formation, not unfamiliarity with the technology.
On the enterprise side, 68% of organizations report they have deployed or are actively deploying passkeys for employee sign-ins, and 82% call full passwordless authentication an eventual goal, though only 28% say they have actually reached it. The honest number in the whole report is this one: 57% of organizations still rely on phishable authentication methods for employees' primary day-to-day sign-in. Passkeys are spreading, but they are mostly spreading alongside passwords, not instead of them.

The Part Every Pitch Deck Skips: Account Recovery
Here is the honest counterpoint that most passkey coverage glosses over. The FIDO2 protocol that underlies passkeys was designed to make authentication phishing-resistant; it was not designed to solve account recovery. If you lose every device that holds your passkeys at once, your fallback is still, in practice, an email reset link, the exact mechanism passkeys were supposed to make obsolete.
Never miss a story
Tools, tutorials and AI deep-dives - straight to your inbox, every week.

"Account recovery is definitely the weak link," says Anna Pobletts, Head of Passwordless at 1Password, discussing passkey limitations for small and medium businesses. "I don't think there's a great answer for that right now."
This is not a fringe complaint. It is why Apple's own recovery process for iCloud Keychain requires two-factor authentication on the account, a password plus a six-digit code when a new device first signs in, and caps recovery attempts at 10 before the escrow record protecting your synced keys is destroyed permanently. That is a reasonable security tradeoff, but it means passkeys shift risk from "someone steals your password" to "you lose access to your own recovery chain," which is a different failure mode that users are not yet used to planning around.
Passkeys Don't Travel Between Ecosystems Yet
The second honest limitation is portability. A passkey created in iCloud Keychain, Google Password Manager, or a password manager's own vault stays in that vault. These systems do not currently hand credentials to each other, so switching from an iPhone to a Windows PC, or from one password manager to another, can mean re-registering passkeys on every site rather than carrying them over. The industry's answer, the Credential Exchange Protocol, is meant to let passkeys move between vendors the way you can export a password list today. As of the most recent coverage, it remains a draft specification rather than something shipping broadly across platforms. Until that changes, picking an authentication ecosystem is a stickier decision than picking a password manager used to be, since password managers like Bitwarden, 1Password and Proton Pass now double as passkey vaults and the one you choose affects how easily you can move later.

What Happens If You Lose Your Phone?
If your passkeys are synced through iCloud Keychain or Google Password Manager, losing one device is not catastrophic: your other signed-in devices still hold working copies, and you can sign in on a replacement device using your account password plus two-factor verification to rebuild the sync chain. The real risk is losing or being locked out of every synced device at once, which forces most services back onto an email-based or support-ticket recovery flow, the same fallback passwords always had.

Who Should Switch Now, and Who Should Skip It
Passkeys are worth adopting now if you already keep your phone and laptop logged into the same Apple, Google, or Microsoft account, use a password manager that supports them, and your highest-value accounts (email, banking, your password manager itself) offer passkey login. For that group, the phishing resistance is a real, measurable upgrade with essentially no added friction once set up.
- Switch now if: you use one consistent device ecosystem, you keep backup authentication methods (a security key or printed recovery codes) for your most critical accounts, and the sites you care about most already support passkeys.
- Wait if: you frequently share accounts across household devices from different ecosystems, you rely on an employer-managed device you don't fully control, or the specific services you use most still treat passkeys as a secondary option rather than a primary one.
- Do this regardless: keep at least one non-device-dependent recovery method (a physical security key or stored recovery codes) for your email and password manager accounts, since that is the account whose loss cascades into everything else.
What to Watch Next
The next twelve months will tell you more than the last two years did. Watch whether the Credential Exchange Protocol moves from draft to shipping support in Apple, Google and Microsoft products, since that is what would finally make passkeys portable rather than ecosystem-locked. Watch the enterprise numbers too: if the share of organizations still relying on phishable sign-in methods for employees drops meaningfully below the current 57%, that is a sign passkeys are displacing passwords rather than just running in parallel with them. And watch for any vendor actually solving account recovery without quietly reintroducing a password-shaped weak link, because right now, none of them have.
Sources