Pinzen
GuidesUse casesFAQSupportOpen Pinzen
  1. Home
  2. Guides
  3. Passkeys Explained: A Plain-English Guide for Families

Passkeys and Sign-In

Passkeys Explained: A Plain-English Guide for Families

Passkeys explained in plain English: what a passkey is, how Face ID replaces your password, where it's stored, and how to set up passkeys for your family.

Last updated October 4, 2026 · 8 min read
On this page
  1. Passkeys explained: what a passkey is, in one minute
  2. How do passkeys work? The no-jargon version
  3. Why passkeys stop most phishing
  4. Where your passkeys are stored
  5. What changes for your family
  6. How to set up passkeys, step by step
  7. Which accounts to switch to passkeys first
  8. Signing in to Pinzen with a passkey
  9. Frequently asked questions

A passkey is a way to sign in to an account with Face ID, a fingerprint, or your phone's screen lock instead of typing a password. Your device keeps a secret that is never sent to the website, and the site holds only a matching "lock" that is useless to a thief. You can't mistype a passkey, forget it, or be tricked into handing it to a fake website.

Below, you'll find passkeys explained without the jargon, plus what they change for a household: shared accounts, kids, older relatives, and lost phones.

Passkeys explained: what a passkey is, in one minute

Think of a passkey as a key that lives on your phone or computer. You never see it or type it. You unlock it the same way you unlock the device itself.

A password is different. It's a secret you share with the website, so anyone who learns it, through a scam or a data breach, can use it. A passkey is never shared with the website, which can confirm you have it without ever receiving it.

"Passkey" is the everyday name for sign-in keys built on open standards from the FIDO Alliance, an industry group that includes Apple, Google, and Microsoft. That's why passkeys work on iPhone, Android, Windows, and Mac alike.

How do passkeys work? The no-jargon version

When you create a passkey, your device makes a matching pair of keys. The private key is the secret half, and it stays with you. The public key works like a lock that only your private key fits, and the website keeps it.

When you sign in, the website sends a challenge, a one-time puzzle only your private key can solve. You approve on your device, which sends back the answer but never the key itself. The website checks the answer against its lock and lets you in.

Day to day, it looks like this:

  1. You choose to sign in with a passkey on a site or app.
  2. Your phone or computer shows a prompt with your account name.
  3. You approve with Face ID, a fingerprint, or your screen lock.
  4. You're in, without typing a password.

Your face or fingerprint never leaves your device; it only unlocks the passkey.

Why passkeys stop most phishing

Phishing is when a scammer sends a fake message or website that looks real, hoping you'll type your password into it. It's one of the most common ways accounts get taken over.

A passkey is tied to the exact website it was made for, so on a lookalike page your device has nothing to offer. No one can talk you into reading one out, either. And if a real website is hacked, thieves get only the public "lock," which can't sign anyone in.

That's a real advantage, but it isn't magic. A passkey can't stop someone who has your phone and knows its passcode. And if an account still accepts a password or text-message code as a backup, scammers can target that instead.

So keep your screen lock private, keep any backup password strong and unique, and never approve a sign-in you didn't start.

Where your passkeys are stored

Your passkeys are usually kept in one of three places:

  • Your device's built-in password manager. When your iPhone offers to save a passkey, it usually goes into Apple's Passwords app (in Settings on older versions). With iCloud Keychain on, passkeys sync, or copy automatically, to your other Apple devices. Android phones usually use Google Password Manager, which syncs across your Google account, and Windows computers can use Windows Hello.
  • A password manager app. Some password managers can store passkeys alongside your logins.
  • A hardware security key. This small device, which you plug in or tap, holds the passkey itself.

You can even use your passkeys on a borrowed computer. Choose the option to use a phone, scan the QR code, and approve on your phone; Bluetooth must be on for both devices, since your phone has to be nearby. Sign out when you're done.

The tradeoff is that synced passkeys rely on your Apple or Google account, so protect it with two-step verification, a second check at sign-in. In return, they aren't lost with your phone, unlike passkeys saved on just one device. Our guide on what happens to passkeys if you lose your phone covers what to do.

What changes for your family

Signing in gets quicker. The bigger shift is that a passkey belongs to one person's account and devices, which changes a few household habits.

The family rule of thumb: anyone who can unlock your phone can use your passkeys, whether they know your passcode or have their fingerprint or face set up on it.

If you're deciding whether to switch everything now, our passkey vs password comparison weighs the tradeoffs.

Shared accounts and kids' accounts

Some accounts belong to the whole household, like streaming, the electric bill, or the school portal. You can't text a passkey to a partner or teenager, so try this:

  • Where a site allows more than one passkey, each adult who needs access can add their own, on their own device.
  • Otherwise, keep a strong, unique password for the shared login and share it through a family vault in a password manager such as Pinzen, not by text.
  • Keep the account's recovery email and phone number current, so you can get back in if a device is lost.

Our guide on whether you can share passkeys with family covers more options.

For kids, it depends on age. Younger children usually do best with a parent-managed account, where a parent handles sign-in and the recovery email. Teens can have their own passkeys on their own phone, protected by their own screen lock.

Either way, don't give kids your passcode or add their fingerprint to your phone, since that also opens your passkeys. The same goes for a shared family tablet: keep grown-up passkeys off it.

Older relatives and older phones

Passkeys can be a gift for older relatives: no long password to remember, and nothing for a fake login page to steal. Check these first:

  • A screen lock. The phone needs a passcode, fingerprint, or face unlock, because that's what approves a passkey.
  • A recent enough system. Passkeys need iOS 16 or later on iPhone, or Android 9 or later. If the option never appears where it should, an outdated phone or browser is the likely reason.
  • A helper at setup. Sit together the first time and do one account, such as their email.
  • A fallback. Keep the old password and recovery options until the passkey has worked several times.

Then teach two simple rules: only approve a sign-in you started yourself, and never read a code to anyone who calls. Our guide to verification code scams shows what those calls sound like.

How to set up passkeys, step by step

Most sites follow the same pattern:

  1. Make sure your phone or computer has a screen lock.
  2. Sign in to the account the usual way, with your password.
  3. Open the account's security or sign-in settings and look for "Passkeys" or "Create a passkey." Many sites also offer one right after you sign in.
  4. If asked where to save it, choose one of the three places above.
  5. Approve with your face, fingerprint, or screen lock.
  6. Sign out, then sign back in with the passkey to make sure it works.

Not every site offers passkeys yet; if you can't find the setting, search its help pages for "passkey." On a computer you use often that doesn't sync with your phone, add a second passkey there.

Which accounts to switch to passkeys first

You don't need to switch everything at once. Start where a break-in would hurt most, with this first-week plan:

  1. Day 1: Your Apple or Google account. It syncs your passkeys, so give it two-step verification, a current recovery phone number, and a passkey where offered.
  2. Day 2: Your main email, if it's a separate account. Whoever controls your email can reset most of your other passwords.
  3. Day 3: Banking and payments, where passkeys are offered. Keep any extra checks your bank requires.
  4. Day 4: Shopping and delivery accounts that store your card.
  5. Day 5: Test each new passkey on a second device, such as a laptop.
  6. Days 6 and 7: Help one family member set up a passkey for their email.

Signing in to Pinzen with a passkey

Pinzen, a family password manager, has no account password to forget or phish. You sign in with a passkey (Face ID, a fingerprint, your screen lock, or a hardware security key), with Google, or with a one-time email link.

Setup takes three steps:

  1. Create a master phrase, which helps lock your vault. The app can suggest four random words.
  2. Save your Recovery Kit file, a complete spare key for your vault.
  3. Turn on approval with Face ID or a fingerprint (a passkey), or with an authenticator app, which shows short-lived codes.

Your master phrase is processed in your browser and never sent to Pinzen, so no one there can see or reset it. If you forget it, your Recovery Kit or a trusted device gets you back in. Our guide to master password vs passkey explains how the phrase and your passkey work together.

After setup, a trusted device reopens without the master phrase, and revealing a saved password or PIN takes a quick approval, such as Face ID. Adding or removing a passkey later needs a fresh approval, too.

Passkeys are included in the free plan, so you can create a free vault and try passkey sign-in yourself.

Frequently asked questions

What is a passkey in simple terms?

A passkey lets you sign in without a password. Your device keeps a secret key for each account and unlocks it with your face, fingerprint, or screen lock. The website holds only a matching public key, so neither a hacked site nor a fake one gets anything that can sign you in.

Where are passkeys stored on my phone?

On an iPhone, passkeys are usually saved in Apple's Passwords app and sync through iCloud Keychain when it's on. On Android, they usually go to Google Password Manager. You can also save them in a password manager app that supports passkeys, or on a hardware security key.

Can I use passkeys on multiple devices?

Usually, yes: passkeys saved to your Apple or Google account sync to your other devices on that account. On a computer without your passkey, choose the option to use a phone, scan the QR code, and approve on your phone. Passkeys on a hardware security key work wherever you use that key.

Do I still need a password if I have a passkey?

Often, yes, for now. Many sites keep your password as a backup, and some let you remove it once a passkey works. Until then, keep that password strong, unique, and stored safely, and keep your recovery email and phone number current, so a lost phone is easier to recover from.

Keep your family's passwords in one safe place

Pinzen is free to start. Sign up with Face ID, save your Recovery Kit, and share only what you choose.

Create a free vault

Keep reading

Passkeys and Sign-InAuthenticator App vs SMS Codes: Which 2FA Should Families Use?8 min readPasskeys and Sign-InPasskey vs 2FA: Are Passkeys Two-Factor Authentication?8 min readPasskeys and Sign-InPassphrase vs Password: Why Four Random Words Work So Well8 min read
Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesGuidesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen