Passwords have been the gateway to our accounts for decades, but also one of the weakest links in digital security. Every day millions of keys are leaked in cyberattacks and yet we keep using the same combinations over and over again. To change this situation, the big technology companies have promoted in recent years an alternative that promises to retire the password once and for all: access keys, known in English as passkeys.
What exactly a passkey is
A passkey is, in essence, a method for entering an application or website without typing any password. Instead of typing a combination of letters and numbers, your device generates a pair of cryptographic keys: one private, which never leaves your phone or computer, and one public, which is stored on the service’s server. To log in you only have to identify yourself with your fingerprint, your face or a PIN.
It is a system similar to the one we use to unlock the phone or pay with the mobile, but applied to any internet account. And its great advantage is that, since there is no password to memorize or to be stolen, impersonation attacks and mass key thefts stop making sense.
How the login works
Imagine you want to log into your email account from a new computer. Instead of typing your password, a QR code will appear on the screen. You scan it with your phone and, after unlocking it with your fingerprint, the access is confirmed automatically. You do not even need to type anything.
That is possible thanks to an open standard called FIDO2, which allows browsers and operating systems to talk to each other securely. Behind this standard are companies such as Apple, Google and Microsoft, which have integrated it directly into their phones, computers and browsers. That is why, today, almost any modern device is already compatible with passkeys without needing to install anything extra.
Why they are more secure than the password of a lifetime
The password has a fundamental problem: it is information that someone can steal. With a well-crafted phishing email, a security flaw on a page or simply reusing the same key on several sites, an attacker can get hold of it without you noticing.
With passkeys this changes completely. The private key is never shared or stored on any server, so there is nothing to steal in a mass attack. In addition, each key is linked to a specific site, so a key created for your bank does not work to enter another page. And, since access depends on your fingerprint or your face, an attacker cannot get in even if they know your personal data.
What happens if I lose my phone
It is one of the most common questions and the answer reassures almost everyone: losing your phone does not mean losing access to your accounts. Passkeys sync securely with the manufacturer’s cloud, just as photos or contacts sync today. If you buy a new phone, your keys go with you.
In addition, most services allow you to save several keys for the same account, for example one on the phone and another on the computer. That way, if you lose one device, you can always recover access from the other. And in the worst case, the classic recovery methods such as the backup email or SMS verification always remain.
Where are they already used?
Although many people still have not tried them, passkeys are already a reality in the most used services in the world. Google, Apple and Microsoft offer them in their accounts, and platforms such as WhatsApp, Amazon, PayPal, eBay or the most popular social networks have been incorporating them over the last few months.
The pace of adoption is growing quickly. In just over a year, millions of people have activated their first access keys, and security experts consider it is only the beginning. Every time an app offers you “sign in with passkey”, what it is giving you is a faster and more secure alternative than the password of a lifetime.
The future of passwords
Nobody expects passwords to disappear overnight. There are old services, corporate accounts and a whole ecosystem that will take years to migrate. But the direction is clear: the goal is that, over time, the password becomes the exception and not the rule.
For now, the experts’ recommendation is simple: if your favourite service offers you the option to activate passkeys, try them. Not only will you save time logging in, but you will be protecting your accounts with a method that is, today, the most secure that exists for the average user. And that, in a world where more and more important things happen over the internet, is good news for everyone.






