A passkey replaces a password with a pair of keys. The website keeps the public half; your device keeps the private half and uses it to sign you in. There’s nothing to type, so nothing to phish, and nothing a breach of the website can leak.
Why they’re safer
- Can’t be phished. A passkey only works on the site it was made for. A fake site gets nothing.
- Can’t leak. The site stores only a public key, useless to anyone who steals it.
- Can’t be reused. Each site gets its own.
Creating one
When a site offers a passkey, usually in its security settings, choose to create one. Your password manager or device asks where to keep it. Vautir keeps it with your login, encrypted like everything else.
Using one
Next time, the site offers to sign in with a passkey. Confirm, and you’re in.
Passkeys on every device
Passkeys kept by Apple or Google stay inside their ecosystem. A cross-platform password manager like Vautir syncs them to every device you use: iPhone, Android, Windows, Linux, and every major browser.
Keep your password too, for now
Many sites still let you sign in with a password as a fallback. Keep it strong and unique, in your password manager.
Last updated October 3, 2026