EXPATINTEL
Support this project
Early Preview: Data may be incomplete or inaccurate.

Passkeys, sync, and recovery

A passkey signs you in with your face, fingerprint, or PIN instead of a password. It also holds the key to your saved profile, which we cannot read and cannot recover, so where it is stored and whether it syncs matters.

Last reviewed 2026-08-15. Every dated claim below links to its source.

What a passkey actually is

A passkey replaces a password. Instead of you remembering a secret and typing it in, your device holds the secret and proves you own it when a site asks. You approve that with whatever already unlocks your device: your face, your fingerprint, your PIN, or your screen lock pattern.

Nothing you can read, write down, or be tricked into typing ever leaves your device. There is no password to reuse, no password to leak in the next data breach, and nothing useful for a fake site to capture, because a passkey only works on the exact website it was created for.

Passkey
A pair of matched keys. The private one stays on your device or in your password manager and never comes to us. The public one is the only part we hold, and on its own it cannot sign in as you.
Authenticator
Whatever actually holds the passkey and does the unlocking: your phone, your laptop, a password manager app, or a small USB security key.
Platform authenticator
The one built into the device you are using, driven by Face ID, Touch ID, Windows Hello, or your Android screen lock.
Credential manager
The thing that stores passkeys and decides whether they sync to your other devices: iCloud Keychain, Google Password Manager, Windows Hello, 1Password, Bitwarden, and so on. Which one you use is the single biggest factor in whether a passkey shows up on your other computer.
Recovery key
A one time code we show you once. It is the only way back into your saved profile if you lose every passkey.

How signing in works here, and what we can and cannot see

The whole flow, start to finish:

  1. Register a passkey. Your device creates it and keeps the private half. We store only the public half.
  2. Optionally add more passkeys. One per device you actually use. This is the step that prevents most lockouts.
  3. Save your recovery key. Shown once, at that moment, and never again.
  4. Sign in with a passkey, or with an emailed magic link. The magic link proves who you are; it does not, on its own, unlock an encrypted profile.
  5. Delete a passkey when you retire a device.
  6. Delete the account and everything we hold, whenever you want.

If none of that appeals, you do not need an account at all. Everything on the site works without one; see using the site without an account.

Register more than one passkey

This is the single most useful thing on this page. One passkey is one point of failure: a lost phone, a wiped work laptop, or a password manager subscription that lapses can each take it out. Two passkeys on two different devices means losing one is an inconvenience rather than an incident.

To add another one:

  1. Sign in on the device you want to add, using an existing passkey, the cross device QR flow, or an emailed magic link.
  2. Open your account settings and choose to add a passkey. The new device creates its own; the first one is untouched.
  3. Approve it with the unlock on that device, its face unlock, fingerprint, PIN, or screen lock.
  4. Give it a name you will recognise later, so that when you retire the device you can tell which entry in the list to delete.

The recovery key

When you first set up an account we show you a recovery key: a long random string that can decrypt your saved profile without a passkey. It is shown exactly once, at that moment. We do not keep a copy we can show you later, because a copy we could show you is a copy we could be compelled to hand over, and then your profile would not be end to end encrypted at all.

  • What it does recover: your saved profile. With the recovery key you can get back into your account and decrypt what you had saved, from any device, with no passkey at all.
  • What it does not do: it does not restore a lost passkey, it does not recover data you never saved to your account, and it does not help with anything held in your browser on a device you no longer have.

Where to keep it, in rough order of preference:

  1. In a password manager, as a secure note. This is the best option for most people: it is encrypted, backed up, and searchable a year from now when you have forgotten what it was called.
  2. Printed and filed with your passport and birth certificates. Paper does not get wiped, corrupted, or locked behind the very account you are trying to recover.
  3. Written by hand and kept somewhere you would keep a spare key. Less durable, still fine.

Something is not working

Find the line that sounds like what you are seeing. These are ordered roughly by how often they happen.

It is not asking me for Face ID, Touch ID, or my fingerprint
What is going on: Either this device has no built in unlock that the browser can use, or the browser is offering a different way in first, or the site is not being served over a secure connection. Passkeys only work over HTTPS.
What to do: Look for a "more options", "other ways to sign in", or key icon in the prompt; that is usually where the phone and security key options are. If the panel at the top of this page says there is no built in unlock, use your phone by QR code instead.
My other laptop does not see my passkey
What is going on: A passkey only appears where its credential manager put it. Some managers sync across your devices; some deliberately keep the passkey on the one device it was made on. This is by far the most common surprise, and which case you are in depends on the manager, not on us. See the short sync table lower down this page.
What to do: Short term: sign in on the second machine using the QR code flow with the phone that has the passkey, or ask for a magic link by email. Long term, and this is the real fix: register a second passkey on the second machine so it stops needing the first one.
It says this browser is not supported
What is going on: The browser has no WebAuthn support, the page is not on HTTPS, or you are inside an app that opens links in its own cut down browser rather than in a real one.
What to do: If you tapped a link inside a chat or social app, look for the "open in browser" option in that app and try again there. Otherwise use the site without an account, which works everywhere.
The QR code scan does nothing, or it spins forever
What is going on: Cross device sign in needs Bluetooth switched on and working on BOTH devices, and both devices online, at the same time. It is not just a QR code.
What to do: Turn Bluetooth on on both the computer and the phone, keep them close together, and make sure both have internet. On a work machine, Bluetooth is often disabled by policy, in which case this flow cannot work at all and you should register a passkey directly on that machine or use a magic link.
I deleted a passkey on my phone and the site still lists it
What is going on: Deleting the stored credential on your device does not, in most setups, tell the website. Only a narrow combination of browser and credential manager reports deletions back automatically.
What to do: Delete the entry in your account settings here as well. The two lists are separate and both need clearing.
It worked yesterday and today it is asking me to set up again
What is going on: Usually a different browser profile, a private window, or browser data that was cleared. Occasionally a credential manager that was signed out.
What to do: Check that you are in the same browser profile and not in a private window, and that your password manager or platform account is still signed in. If it genuinely is gone, sign in with your other passkey or your recovery key.
I am on a work computer and it will not let me create one
What is going on: Managed devices commonly block passkey creation, block the credential manager, or disable the Bluetooth that cross device sign in needs. That is your IT policy, not a fault.
What to do: Register the passkey on a personal device or on a hardware security key you own, and use that to sign in at work. Never make your only passkey live on a machine your employer can wipe.
It says my security key is full
What is going on: Hardware keys can only hold a limited number of discoverable passkeys, and older firmware holds far fewer than current firmware.
What to do: Remove passkeys you no longer use from the key with your vendor management tool, or use a second key. Check your key vendor documentation for the limit on your model.
I never saved the recovery key and now I want one
What is going on: The original was shown once and is not stored anywhere we can reach.
What to do: While you can still sign in, generate a new recovery key. That invalidates the old one and gives you a fresh one to store properly. Do it now rather than later.

The detail, if you need it

Everything below is collapsed on purpose. Open only what applies to you; a link that points inside one of these opens it for you.

Does it sync? The short table

One row per credential manager: does the passkey follow you to your other devices.

Every claim in this table is sourced and dated at the bottom of this page. This area changed a great deal between 2024 and 2026 and will change again, so if a date looks old, believe the vendor over us.

Passkey storage and sync by credential manager
Where the passkey livesSyncs to your other devicesWhat that means for you
iCloud Keychain (iPhone, iPad, Mac)Yes, across your Apple devicesTwo factor authentication on your Apple Account is required. Apple cannot read the contents.
Google Password Manager (Android, and Chrome on desktop)Yes, since September 2024 on desktop Chrome tooNeeds a signed in Chrome profile and a Google Password Manager PIN or your Android screen lock.
Chrome profile store on macOS (only if you pick it)NoChrome on macOS can put a passkey in the Chrome profile instead. Those do not sync.
Windows HelloNo, device boundA Windows Hello passkey stays on that PC. Each PC needs its own registration.
Microsoft Password Manager, through EdgeYes, but only in Edge and only where it has rolled outThis is newer and is being rolled out gradually. Do not assume it is on for you; check.
1Password, Bitwarden, DashlaneYes, through the manager accountThey sync wherever you can install and sign into that manager, which is what makes them the best answer to mixed Apple and Windows households.
Hardware security key (YubiKey and similar)No, and that is the pointThe passkey cannot be copied off the key. Lose the key and that passkey is gone; carry a second key or keep a second passkey elsewhere.

iPhone, iPad, and Mac

iCloud Keychain syncs passkeys across your Apple devices, if it is turned on.

On Apple devices, passkeys are normally stored in iCloud Keychain and sync to your other Apple devices signed into the same Apple Account. Apple encrypts them end to end, so Apple cannot read them either. Synced passkeys need iOS or iPadOS 16 or later, or macOS 13 or later.

If iCloud Keychain is switched off, passkeys have nowhere to sync to. The setting is under Settings, then your name, then iCloud, then Passwords and Keychain. We could not confirm from an Apple source exactly what happens when iCloud Keychain is disabled, so treat this as a strong recommendation to check the setting rather than a precise description of what your device will do.

Since iOS 17 and macOS 14 you can also use a third party manager such as 1Password or Bitwarden as your passkey provider instead of iCloud Keychain, which is what you want if half your devices are not Apple.

To delete a passkey: on iOS 18 and later, open the Passwords app, choose Passkeys, tap the entry, and delete it. On iOS 17 and earlier it is Settings, then Passwords. On a Mac it is the Passwords app. Deleting there removes it from iCloud Keychain, so it disappears from every Apple device at once.

Android

Google Password Manager syncs by default; other managers work from Android 14.

On Android, passkeys go to Google Password Manager by default and sync to your other environments signed into the same Google account, including Chrome on your desktop. They are protected by your screen lock or a Google Password Manager PIN, and Google states it cannot access them.

From Android 14 you can use a third party credential manager such as 1Password, Bitwarden, or Dashlane instead, through the Android Credential Manager. One documented limitation: on Android, a passkey held by a third party provider can be used as your main way in, but Android does not let third party providers supply passkey based second factor authentication.

To manage or delete passkeys, open Google Password Manager, either from the app or from your phone settings, and look under Passkeys. The same list appears at passwords.google.com.

Chrome on a desktop computer

Chrome desktop passkeys sync through Google Password Manager now; the old device bound behaviour is the exception, not the rule.

You need to be signed into Chrome and to have set a Google Password Manager PIN, or to use your Android screen lock. That PIN is what makes the passkeys end to end encrypted, which is also why Google cannot recover them for you if you forget it.

  • On macOS, Chrome can also store a passkey in the Chrome profile if you choose that. Those do not sync anywhere. If your Mac passkey is not showing up elsewhere, this is the likely reason.
  • On Windows, Chrome can save a passkey into Windows Hello instead. Google documents that those are neither synchronised nor backed up.
  • On ChromeOS, saving passkeys to Google Password Manager needs ChromeOS 129 or later.

Per passkey deletion happens in Google Password Manager, at passwords.google.com or through Chrome settings, not in the Chrome page that offers to delete all Google Password Manager data.

Windows

Windows Hello passkeys stay on that PC. Sync exists, but through Edge and Microsoft Password Manager, and it is still rolling out.

Microsoft has since added passkey saving and syncing through Microsoft Password Manager in Edge, which needs a recent Edge, a Microsoft Account, and a Microsoft Password Manager PIN. Microsoft described it as a gradual rollout that would reach more platforms later, so whether you have it depends on your Edge version and on the rollout. Check rather than assume, and note this is the single fastest moving claim on this page.

Windows 11 also supports third party passkey providers system wide, so 1Password or Bitwarden can hold your passkeys for every browser and app rather than just inside one browser extension. You switch that on under Settings, then Accounts, then Passkeys, then Advanced options, and confirm with Windows Hello.

To see and delete passkeys stored on the PC itself: Settings, then Accounts, then Passkeys. That list covers the device bound Windows Hello passkeys only; passkeys held by another credential manager are managed in that manager.

1Password, Bitwarden, and Dashlane

The best answer if you mix Apple and Windows: one passkey store that follows you everywhere.

All three store passkeys in your encrypted vault and sync them to every device where you can sign into that vault. That is what makes them the practical answer to a household with an iPhone and a Windows PC: the passkey follows the vault, not the operating system.

  • On iPhone and iPad they work as the system passkey provider from iOS 17, and on Android from version 14, through the system credential manager.
  • On Windows 11 they can act as a system wide passkey provider, so they work in any browser and in apps, not only in a browser extension.
  • In browsers they also work as an extension, which is often the quickest way to get going on a desktop.

Hardware security keys (YubiKey and similar)

Device bound by design: the passkey cannot leave the key, and cannot be synced.

A hardware key holds the passkey in the key itself. It cannot be copied off, which is exactly why people use them, and it also means there is no sync and no backup. If you lose the key, the passkey on it is gone.

  • They hold a limited number of passkeys. Yubico documents 25 discoverable credentials on YubiKey firmware 5.0 to 5.6.x and 100 on firmware 5.7 and later. When the slots are full, new registrations fail or fall back.
  • Buy two and register both. This is the standard advice from every vendor and it is right: one on your keyring, one in a drawer at home.
  • On iPhone and iPad, an external key can sign you in but cannot unlock an encrypted profile, because iOS does not pass the necessary extension data to external keys. Use it on a computer for that.

Made it on an iPhone, now I am on a Windows PC

The QR code flow, why it needs Bluetooth on both devices, and the proper fix.

This is the classic mixed household problem: the passkey is in iCloud Keychain on your phone, and the Windows PC in front of you cannot see it. There is a built in answer, and it works.

Signing in on a computer using the phone that holds the passkey:

  1. Choose to sign in with a passkey on the computer, then pick the option for using a phone or tablet. A QR code appears.
  2. Scan the QR code with your phone camera.
  3. Approve on the phone, with Face ID, your fingerprint, or your screen lock.
  4. The computer signs in. The passkey itself never moves to the computer; the phone just vouches for you this once.

Where this will not fully work, and what we offer instead

Old browsers, in app browsers, insecure connections, and locked down machines.

The panel at the top of this page tells you what your current browser can actually do. In general terms, these are the cases that fail:

Not on HTTPS
Passkeys require a secure connection. On a plain http page the whole feature is missing rather than broken, and there is nothing you can do from your side.
In app browsers
Links opened inside a chat or social app often load in a cut down browser that does not do passkeys reliably. We could not verify the current behaviour of every one of these, and it changes often, so the practical advice stands regardless: use the "open in browser" option and try again in a real browser.
Older browsers and older operating systems
Synced passkeys need roughly iOS 16 or macOS 13 on Apple, and a current Chrome, Edge, Firefox, or Safari elsewhere. Anything much older will not offer them.
Managed devices with passkey creation blocked
Corporate policy can switch off the password manager that would hold the passkey, restrict the Bluetooth the QR flow needs, or gate whether an application may use passkeys at all behind an administrator decision. In each case the block is on the device, not on our side.
Firefox, and third party managers
Firefox supports passkeys, but its coverage of the surrounding features differs from that of Chrome and moves quickly, and it does not integrate with third party credential managers the way the mobile platforms do. If something in Firefox does not behave as described here, try a Chromium browser before concluding the account is broken.

The full picture of what that costs you is in using the site without an account.

Private windows, shared devices, and work machines

Where you should and should not create a passkey, and why.
Private or incognito windows
Behaviour differs between browsers and has changed repeatedly, and we could not find a clear vendor statement for any of them, so we will not tell you it works. Treat a private window as a place to sign in, not a place to create a passkey, and expect anything stored only in that window to vanish when you close it.
A shared or family computer
A passkey saved into a shared browser profile or a shared platform account is available to whoever else uses that profile or account. Use your own browser profile, or use your phone by QR code and create nothing on the shared machine.
A device belonging to someone you are helping
Sign in with the QR flow from your own phone and do not create a passkey there. When you are done, sign out. Nothing of yours is left behind.
A work laptop
Assume it can be wiped without warning and that its passkeys go with it. Create your passkey on something you own, and if you want one on the work machine too, make it the second one, never the only one.

What happens if you lose things

Every combination, honestly: one device, all devices, the recovery key, the lot, plus deleted passkeys, lapsed subscriptions, and wiped work laptops.

Read the row that matches you. "Recoverable" here means you can get back into your account and decrypt your saved profile.

What you can recover, by what you still have
SituationCan you get back inWhat to do
Lost one device, still have another with a passkeyYes, straightforwardlySign in on the device you still have, delete the passkey belonging to the lost device, and add a passkey on its replacement.
Lost all devices, still have the recovery keyYesSign in on any device using the recovery key, immediately register a passkey on the new device, then generate a fresh recovery key. The old one should be treated as spent.
Still have a device with a passkey, lost the recovery keyYes, and fix it todayYou are fine right now and one failure away from not being fine. Sign in and generate a new recovery key, which invalidates the lost one, then store it properly.
Lost every passkey AND the recovery keyNo. Permanently.Your saved profile cannot be decrypted by anyone, including us. You can sign in by magic link and start a new profile from scratch; the old encrypted data is unreadable and you should delete it.
Deleted a passkey by accident, still have anotherYesNothing is lost. Sign in with the other one and register a replacement.
Deleted your only passkey by accidentOnly with the recovery keyUse the recovery key to sign back in, then register a passkey immediately. If the recovery key is also gone, this is the permanent case above.
Password manager subscription lapsedUsually yes, but act quicklyMost managers drop to a read only or export only state rather than deleting your data, but the specifics differ per product and per plan. Before it lapses, register a second passkey somewhere else, or export your data as that product allows. Do not assume the passkeys are still usable after the lapse; check.
Corporate device wiped by ITOnly if the passkey was not solely on that deviceA remote wipe takes the device bound passkey with it, and a managed device may also have blocked syncing in the first place. This is the strongest single argument for keeping a passkey on a personal device or a hardware key you own.
You still have the device but it will not unlock (broken screen, forgotten PIN)Depends on the credential managerA synced passkey can be reached from another device signed into the same account. A device bound passkey cannot; treat it as lost and use the recovery key.

Deleting a passkey, and deleting your account

How to remove one passkey, and how to remove everything we hold.

A passkey exists in two places at once, and removing it from one does not remove it from the other. Removing it from your account settings here stops it being accepted as a way in. Removing it from your device or password manager deletes the stored credential. Do both, in that order.

To retire a passkey:

  1. Confirm you have another way in first, another passkey or your recovery key. Deleting your last passkey without one is how people lock themselves out.
  2. Delete it in your account settings here, which is what actually stops it working.
  3. Delete the stored credential on the device, so the entry stops appearing in your sign in prompts. The exact place differs per platform; see the platform sections above.

Deleting the account. Account deletion removes everything held on our side: your encrypted profile, the public halves of your passkeys, and your email address. It is immediate and it is not reversible, because there is no backup we can read to restore from. It does not touch the passkeys stored on your devices; those become dead entries that you can remove at your leisure, and it does not touch anything saved locally in your browser, which you clear separately.

What the site keeps in your browser, separately from any account, is listed in full on the privacy policy, and is cleared with the "Clear My Data" button there.

Common questions

What is a passkey?

A passkey replaces a password. Your device holds a private key and proves you own it when a site asks, and you approve that with your face, your fingerprint, your PIN, or your screen lock. Nothing you could be tricked into typing ever leaves your device.

Why is my passkey not on my other computer?

Because a passkey only appears where its credential manager put it. iCloud Keychain syncs across your Apple devices, Google Password Manager syncs across Chrome and Android, and third party managers such as 1Password, Bitwarden, and Dashlane sync wherever you can sign into the vault. Windows Hello passkeys are device bound and stay on the PC that made them, and Chrome on macOS can optionally store a passkey in the Chrome profile, which also does not sync.

Do I need Bluetooth to sign in using my phone?

Yes. Cross device sign in by QR code needs Bluetooth turned on and working on both devices, and both devices connected to the internet. Bluetooth is what proves the two devices are physically near each other, so the flow cannot complete without it.

What happens if I lose my phone?

If you have a passkey on another device, sign in there, delete the passkey belonging to the lost phone, and add one on its replacement. If you have no other passkey, use your recovery key and register a new passkey immediately afterwards.

Can you recover my saved profile if I lose everything?

No. Your saved profile is encrypted with a key derived from your passkey that never reaches our servers, so if you lose every passkey and your recovery key, nobody can decrypt it, including us. You can still sign in by emailed magic link and start a new profile, but the old data is permanently unreadable.

Do I have to create an account at all?

No. The whole site works without one. Everything you enter is saved in your browser on the device you are using and is never sent to us. What an account adds is an encrypted copy that follows you to your other devices.

How do I delete a passkey?

Delete it in your account settings here, which is what stops it working, and then delete the stored credential on the device: the Passwords app on iPhone and Mac, Google Password Manager on Android and Chrome, or Settings then Accounts then Passkeys on Windows. Check you have another way in before deleting your last one.

Sources and verification

Platform behaviour changes, so every claim on this page that can expire is listed here with the page it came from and the date a human read it there. If a date looks old, trust the vendor page over this one and tell us.

  • iCloud Keychain syncs passkeys between a user Apple devices and encrypts them end to end, so Apple cannot read them.https://support.apple.com/guide/security/icloud-keychain-security-overview-sec1c89c6f3b/webVerified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • Any Apple Account using iCloud Keychain requires two factor authentication, and a user who tries to register a passkey without it is prompted to set it up.https://support.apple.com/en-us/102195Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • With iCloud Keychain switched off, Apple devices have nowhere to sync passkeys to, and the setting lives under Settings, your name, iCloud, Passwords and Keychain.https://support.apple.com/en-us/102195Verified on 2026-08-15. Re-check every 90 days. Status: not yet re-verified at primary source.What may change: Could not be confirmed from a rendered Apple page; Apple support articles do not serve their body text to a fetcher. The picture is further complicated by third party passkey providers on iOS 17 and later, which can create passkeys with iCloud Keychain off. The page text is hedged accordingly. Re-verify on a device.
  • Synced passkeys need iOS or iPadOS 16 and later or macOS 13 and later; third party credential providers need iOS or iPadOS 17 and later or macOS 14 and later.https://passkeys.dev/device-support/Verified on 2026-08-15. Re-check every 120 days. Status: verified at primary source.What may change: A community maintained matrix, updated frequently. It is the best single overview available but it is not a vendor page, and its Firefox and cross device rows have disagreed with vendor sources.
  • The Passwords app introduced in iOS 18 and macOS Sequoia is a new interface over the same iCloud Keychain data, not a separate store.https://support.apple.com/en-us/120758Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • A passkey is deleted on iOS 18 and later in the Passwords app under Passkeys, on iOS 17 and earlier under Settings then Passwords, and on macOS in the Passwords app, which also removes it from iCloud Keychain.https://support.apple.com/guide/passwords/remove-a-password-mchl77e2cb66/macVerified on 2026-08-15. Re-check every 90 days. Status: not yet re-verified at primary source.What may change: Read from search results rather than a rendered Apple page. Apple has reorganised these menus at least once in the last two years, so treat the exact wording as approximate.
  • Since September 2024, Chrome on the desktop saves passkeys to Google Password Manager and syncs them across Windows, macOS, Linux, ChromeOS, and Android, protected by a Google Password Manager PIN or the Android screen lock.https://developer.chrome.com/blog/passkeys-gpm-desktopVerified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.What may change: This is the claim most third party guides still get wrong. If anything moves here it will be toward more sync, not less.
  • Google documents that Chrome on macOS can optionally store a passkey in the Chrome profile, and that those are not synchronised to other environments; Android stores to Google Password Manager by default and synchronises; third party providers on Android need version 14 or later; ChromeOS needs version 129 or later.https://developers.google.com/identity/passkeys/supported-environmentsVerified on 2026-08-15. Re-check every 120 days. Status: verified at primary source.
  • Google documents that a passkey Chrome saves into Windows Hello is neither synchronised nor backed up.https://support.google.com/chrome/answer/13168025Verified on 2026-08-15. Re-check every 120 days. Status: verified at primary source.
  • Passkeys held by Google Password Manager are managed and deleted in Google Password Manager itself, reachable from Android settings, from Chrome settings, or at passwords.google.com.https://support.google.com/chrome/answer/13168025Verified on 2026-08-15. Re-check every 120 days. Status: not yet re-verified at primary source.What may change: Google documents deleting all Google Password Manager data but does not document per passkey deletion step by step, so the exact click path here is inferred from the product rather than quoted.
  • Microsoft documents Windows Hello passkeys as stored in the local Windows Hello container, device bound, and not synced, so each device needs its own registration.https://learn.microsoft.com/en-us/entra/identity/authentication/passkey-faqVerified on 2026-08-15. Re-check every 90 days. Status: verified at primary source.What may change: Microsoft is clearly moving toward synced passkeys, so the flat statement that Windows does not sync is the claim on this page most likely to be wrong within six months.
  • Microsoft added passkey saving and syncing through Microsoft Password Manager in Edge, requiring a recent Edge, a Microsoft Account, and a Microsoft Password Manager PIN, and described it as a gradual rollout that would reach further platforms later.https://blogs.windows.com/msedgedev/2025/11/03/microsoft-edge-introduces-passkey-saving-and-syncing-with-microsoft-password-manager/Verified on 2026-08-15. Re-check every 60 days. Status: verified at primary source.What may change: A staged rollout announcement. Which users have it, and whether it stays Edge only, will both have changed by the next review. The short review interval is deliberate.
  • Windows 11 supports third party passkey providers system wide, switched on under Settings, Accounts, Passkeys, Advanced options, and confirmed with Windows Hello.https://learn.microsoft.com/en-us/windows/apps/develop/security/third-partyVerified on 2026-08-15. Re-check every 120 days. Status: verified at primary source.
  • Windows 11 lists and deletes device bound passkeys under Settings, Accounts, Passkeys, and asks the user to consent before an application may use passkeys under Settings, Privacy and security, Passkey access, which an administrator can control.https://learn.microsoft.com/en-us/windows/security/identity-protection/passkeys/Verified on 2026-08-15. Re-check every 90 days. Status: verified at primary source.What may change: Microsoft has said the enterprise policies for these consent prompts were still reaching general availability during 2026, so the administrator side of this is actively changing.
  • Cross device passkey sign in requires both the computer and the mobile device to have Bluetooth enabled and to be connected to the internet; the passkey itself is never transferred or copied.https://learn.microsoft.com/en-us/windows/security/identity-protection/passkeys/Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • Google documents that cross device sign in needs Bluetooth on both the device performing the action and the device holding the passkey, that the devices should be close together, and that they do not need to be paired.https://support.google.com/accounts/answer/13548313Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • Bitwarden syncs passkeys through its encrypted vault, works as a provider on iOS 17 and later and Android 14 and later, and documents that on Android a Bitwarden held passkey can only be used as a primary login credential, not for passkey based second factor authentication.https://bitwarden.com/help/storing-passkeys/Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • 1Password stores and syncs passkeys and can act as a system wide passkey provider on Windows 11, enabled under Settings, Accounts, Passkeys, Advanced options.https://support.1password.com/save-use-passkeys-windows/Verified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • Dashlane stores passkeys and syncs them across the devices signed into the account, acting as a provider on iOS 17 and later and Android 14 and later.https://support.dashlane.com/hc/en-us/articles/7888558064274-Passkeys-in-DashlaneVerified on 2026-08-15. Re-check every 180 days. Status: not yet re-verified at primary source.What may change: Listed from the vendor help centre index rather than a rendered article read end to end.
  • Yubico documents a maximum of 25 discoverable credentials on YubiKeys with firmware 5.0 to 5.6.x and 100 on firmware 5.7 and later, and states that a passkey in a YubiKey is not copyable and is bound to that key.https://docs.yubico.com/hardware/yubikey-guidance/best-practices/sp-bestpractices-passkeys.htmlVerified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • iOS and iPadOS do not pass WebAuthn extension data, including prf, to external roaming authenticators, so a security key plugged into an iPhone cannot produce the value used to derive an encryption key.https://developers.yubico.com/WebAuthn/Concepts/PRF_Extension/Developers_Guide_to_PRF.htmlVerified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.
  • Client support for a WebAuthn extension can be queried statically, but that reports what the browser implements and not what the authenticator the user chooses will do; whether prf actually worked is only known from getClientExtensionResults after a real create or get call.https://developer.mozilla.org/en-US/docs/Web/API/PublicKeyCredential/getClientCapabilities_staticVerified on 2026-08-15. Re-check every 180 days. Status: verified at primary source.What may change: The static query itself, PublicKeyCredential.getClientCapabilities(), shipped across browsers during 2025. Whether real browsers actually emit an extension:prf key could NOT be verified, which is why lib/passkey/capabilities.ts treats its absence as unknown rather than as a negative answer.
  • The Web Authentication API is available only in a secure context, and inside a cross origin iframe it requires the publickey-credentials-get or publickey-credentials-create permissions policy, which default to self.https://developer.mozilla.org/en-US/docs/Web/API/Web_Authentication_APIVerified on 2026-08-15. Re-check every 365 days. Status: verified at primary source.
  • Passkey behaviour in private and incognito windows differs between browsers and has changed repeatedly, and no vendor publishes a clear statement of it.https://developer.mozilla.org/en-US/docs/Web/API/Web_Authentication_APIVerified on 2026-08-15. Re-check every 90 days. Status: not yet re-verified at primary source.What may change: This is a genuine documentation vacuum, not a gap in our research: Apple, Google, and Mozilla do not document it. The page therefore tells readers not to rely on private windows rather than describing behaviour we cannot source.
  • Passkey support inside application embedded browsers (webviews) is inconsistent and is a common real world failure, and current per platform behaviour is not documented in one place.https://developer.mozilla.org/en-US/docs/Web/API/Web_Authentication_APIVerified on 2026-08-15. Re-check every 90 days. Status: not yet re-verified at primary source.What may change: We could not verify current behaviour for Android WebView, WKWebView, or the in app browsers used by the major social applications. The page gives the advice that holds regardless (open the link in a real browser) rather than asserting which ones fail.
  • Deleting a passkey on a device does not usually tell the website, because the WebAuthn signal API that would report it is implemented only in a narrow combination of browser and credential manager.https://developer.chrome.com/docs/identity/webauthn-signal-apiVerified on 2026-08-15. Re-check every 120 days. Status: verified at primary source.What may change: Support for the signal API is expanding. As more browsers and credential managers implement it, the advice to delete the entry in two places will gradually become unnecessary.