Passkeys and Sign-In
Master Password vs Passkey: What Should Unlock Your Vault?
Master password vs passkey, explained simply: what each one protects, why many password managers use both, and how to get back in if you forget or lose one.
Last updated October 4, 2026 · 8 min readThe master password vs passkey question has a simple answer: they do two different jobs. A passkey proves it's really you when you sign in. A master password (or master phrase) is the secret your device uses to unlock the encryption that protects your saved items, and many password managers use both on purpose.
Sign-in and encryption are two different jobs
Forum threads about using a passkey instead of a master password often go in circles because they mix up these two jobs. Picture a house with a safe inside it.
- Sign-in is the front door. It answers one question: "Is this person allowed into this account?"
- Encryption is the safe. It scrambles your saved items so only someone with the right key can read them, even if a stranger copies the files.
In most dedicated password managers, that scrambling happens on your own device before anything is stored online. A passkey is excellent at guarding the front door, while a master password has traditionally been the key to the safe.
What a master password actually does
The meaning of "master password" is simple: it's the one secret you remember so you don't have to remember all the others. In many password managers it does double duty, signing you in and unlocking the encryption, which is a big reason the two jobs get mixed up.
Because your device uses it to work out the key to your vault, the company typically never sees it and can't reset it. That protects you, but it also means there's no quick "forgot password" email to fall back on.
Its strength really counts if stored vault data is ever stolen, because thieves can then make guesses on their own computers with no login screen to lock them out. A long, random master password is what makes that guessing impractical.
A master phrase is simply a master password made of several random words, so it's easier to remember and still very hard to guess. Here's why four random words work so well.
What a passkey does in a password manager
A passkey is a sign-in method that replaces typing a password. Your phone or computer holds a secret digital key and unlocks it with Face ID, a fingerprint, or your screen lock. Your face or fingerprint stays on the device, and the website never receives anything a thief could reuse.
Passkeys also work only on the real website they were made for, so a fake look-alike page can't capture one. That makes them resistant to phishing, the trick of stealing logins through fake sites and messages. The FIDO Alliance, the industry group behind passkeys, explains the standard, and our plain-English guide to passkeys covers the basics.
In a password manager, a passkey login usually handles one or more of these jobs:
- Signing you in without a typed password that could be phished.
- Approving sensitive actions, such as revealing a saved password.
- Proving it's you during account recovery.
Whether a passkey also unlocks your encrypted data depends on the design. In many password managers it doesn't: signing in gets you to the safe, and a master password or another secret still opens it.
Is there a password manager without a master password? Yes: tools built into phones and browsers generally rely on your screen lock and your account instead, and some apps can unlock the vault with a passkey. The catch is recovery: if your devices hold the only keys, you need a plan for losing one.
Master password vs passkey: why many vaults use both
Using both gives you two layers that cover different risks.
- The passkey guards the door. It's practically impossible to guess, and fake sites can't capture it.
- The master phrase guards the safe. A long, random one keeps copied data scrambled.
There's a practical reason too. Passkeys live on your devices or in the account that syncs them, and devices get lost. A phrase you know by heart, plus a saved backup, keeps a lost phone from becoming a lost vault.
Using both doesn't have to mean more typing: good designs skip the phrase on devices you've already approved.
Tradeoffs for families
In a family, the person who set things up often isn't the one who needs help later. A grandparent who rarely types a long phrase may forget it, and a teenager may lose a phone. Each option has a weak spot:
- A master phrase works on any device, but it can be forgotten.
- A passkey is fast and very hard to phish, but it's tied to devices, and devices get lost.
- Using both, plus a backup, takes a little more setup, but it covers the most "what if" moments.
Forgetting a master password
For many families, this is the biggest worry. A company that can't read your master password can't hand it back to you either, so prepare before it happens:
- Save whatever recovery file or codes your password manager offers.
- Keep a copy somewhere private, such as a printout or USB drive in a locked drawer.
- Tell one trusted person where to find it in an emergency.
- Check once that you can find and open it.
Our guide on what to do if you forgot your master password walks through each recovery path.
Losing the device that holds your passkey
Some passkeys live on one device, such as a hardware security key (a small USB or tap-to-use key). Others sync through the account that comes with your phone and usually return when you sign in on a new one.
Set up a second way in before you need it, such as a passkey on another device, a hardware security key, or another sign-in option. Then read what happens to passkeys if you lose your phone so the steps feel familiar.
How Pinzen handles sign-in, unlock, and approvals
Pinzen is the family password manager we build, and it keeps these two jobs separate.
Sign-in. You sign in with a passkey (Face ID, a fingerprint, your device screen lock, or a hardware security key), with Google, or with a one-time email sign-in link. There's no account password to forget or to be tricked into typing on a fake site.
Setup takes three steps:
- Create a master phrase. The app can suggest four random words.
- Save your Recovery Kit, a backup file that works as a spare key.
- Turn on approval with Face ID or a fingerprint (a passkey), or with an authenticator app, an app on your phone that makes short one-time codes.
Everyday use. A trusted device, one you've already set up, reopens without your master phrase. Revealing a password, PIN, or card number needs approval, such as Face ID or an authenticator code, and one approval keeps reveals open for 10 minutes on that unlocked device. Adding or removing a passkey on an existing vault requires a fresh approval.
Encryption. Your vault is encrypted in your browser. Your master phrase is processed on your device with Argon2id, a method built to make guessing slow and costly. It's then combined with a random 256-bit Account Secret, a long computer-made key stored in your Recovery Kit and on your trusted devices.
Neither your phrase nor that secret is ever sent to us. Our servers store only encrypted data, and even a copy of our database and server secrets isn't enough to decrypt your vault. The one exception is if you turn on optional Google email recovery, which is why we label that option a tradeoff.
Recovery. We can't see or reset your master phrase. Your ways back in are the Recovery Kit, a trusted device (which can download a fresh Kit), or optional Google email recovery.
The Kit is a complete spare key: with Face ID, a passkey, an authenticator code, or one of its own one-time codes, it can reset a forgotten phrase. Keep it as safe as a spare house key. With extra-secure recovery turned on, the Kit alone can't reset your phrase; a passkey or authenticator is also required.
Read the full details on our security page, or create a free vault and try the three setup steps yourself.
Choosing a master phrase you'll remember
How long should a master password be? For most people, aim for at least four random words, or five or six if you can remember them. Length and true randomness matter far more than clever symbols.
- Let a generator pick the words. Lyrics, quotes, and family names are much easier to guess.
- Make it unique. Never use it anywhere else.
- Skip swaps like "@" for "a". They add little strength and make the phrase harder to remember.
- Practice it. Type it daily for the first week until it sticks.
- Write it down once, and keep the paper somewhere private, never in a phone note or email.
Frequently asked questions
Can a passkey replace a master password?
For signing in, often yes. Unlocking your encrypted data is a separate question: some password managers can use a passkey for that too, while others still rely on a master password. Pinzen lets you use a passkey for sign-in and approvals, and a master phrase protects the encryption.
Is a passkey safer than a master password?
For signing in, yes: a passkey is much harder to phish because it only works on the real site. But a long, random master phrase does a different job, keeping your stored data scrambled if someone copies it. Using both covers more ground, though no method removes all risk.
How long should a master password be?
Aim for at least four random words, or five or six if you can remember them. Length and true randomness matter far more than symbols or number swaps, because they multiply the guesses an attacker would need. Let a generator choose the words instead of using lyrics or names, and never reuse the phrase anywhere else.
Do I need to type my master password every time?
Usually not. Many password managers let you reopen the vault with Face ID, a fingerprint, or your screen lock on a device you've already set up. In Pinzen, a trusted device reopens without your master phrase; you just approve with Face ID, a passkey, or a code before revealing a password, PIN, or card number.