Passkeys are now supported by all the major platforms and services: Google (personal and Workspace), Apple ID, Microsoft, GitHub, Amazon, eBay, PayPal, Adobe, Cloudflare, Coinbase, Dropbox, and X among many others. This guide walks through setup on iOS, macOS and Windows, with the official steps from each provider.
Quick answer: to create a passkey, open the sign-in or security settings of the account (Google Account > Security, Apple ID > Sign-In & Security, or Microsoft account > Security), pick "create a passkey", and confirm with your device biometric (Face ID, Touch ID or Windows Hello) or PIN. The private key stays in your device's secure chip, and you then sign in with your fingerprint or face instead of a password. Per-platform steps for iOS, macOS and Windows are below.
01 - What Exactly Is a Passkey?
A passkey is a cryptographic key pair (public + private) generated by your device for each site:
- Private key: never leaves your device. Stored in the secure enclave (Apple Secure Enclave, Google Titan chip, Microsoft TPM). Unlocked by biometrics (Face ID, Touch ID, Windows Hello) or PIN.
- Public key: sent to the site when the passkey is created.
How login works:
- You click "Sign in"
- The site sends a cryptographic challenge to your browser
- Your device requests your biometrics or PIN
- The private key signs the challenge
- The site verifies with your registered public key
- Signed in - no password ever transmitted
Why it's phishing-resistant: the signature is tied to the exact site origin (domain + protocol). A fake site g00gle.com receives a different challenge that google.com can't verify. Unlike TOTP, a passkey cannot be replayed on a fake site.
Software vs hardware passkeys: the passkeys you create on Google, Apple, and Microsoft are software passkeys - stored in the OS key manager and synced to the cloud. Hardware keys like YubiKey store the private key in an inextractable physical chip. For everyday multi-account use, software passkeys are the right choice. See our complete YubiKey FIDO2 guide for high-security profiles.
02 - Google Passkey Setup
Google is the simplest provider to configure. Passkeys sync via Google Password Manager across all your Android devices + Chrome (Windows, macOS).
Steps on Desktop (Chrome)
- Go to myaccount.google.com
- Click Security in the left menu
- Under "How you sign in to Google," click Passkeys and security keys
- Click Create a passkey
- Chrome prompts you to confirm - click Continue
- Authenticate with your computer's biometrics (Windows Hello, Mac Touch ID)
- ✅ Passkey created and stored in Google Password Manager
Typical time: around 2 minutes from the myaccount.google.com homepage.
Sync to Android
Your Google passkey syncs automatically to all Android devices signed into the same Google account. No additional steps needed. The next Google sign-in on Android will offer the passkey by default.
Sync to iOS/Safari
Google Password Manager doesn't integrate natively with Safari. On iPhone, you have two options:
- Chrome for iOS: Google passkeys work via Chrome (it uses the Google passkey provider)
- Bitwarden: if you store the passkey in Bitwarden instead of Google PM, it'll be available everywhere
Google Troubleshooting
| Issue | Solution |
|---|---|
| "Feature not available on this device" | Verify Chrome is updated (v108+) and 2FA is enabled on the account |
| Passkey not showing on Android | Wait 2-3 min, force sync in Settings → Google → Passwords |
| "You already have a passkey on this device" | Normal - Google detects the device. Delete the old one via myaccount.google.com → Security → Passkeys if you want to recreate it |
InvalidStateError | Clear Chrome cache (Ctrl+Shift+Delete), reopen session |
03 - Apple Passkey Setup (iCloud Keychain)
Apple has the smoothest passkey support on its own devices. Passkeys are stored in iCloud Keychain and synced across all your Apple devices via iCloud.
Prerequisites
- iOS 16+ / macOS Ventura (13)+ / iPadOS 16+
- iCloud Keychain enabled: Settings → [your name] → iCloud → Passwords & Keychain (toggle on)
- Two-factor authentication enabled on Apple ID
Steps on iPhone (iOS 17)
On a site that supports passkeys - example: GitHub:
- Go to github.com in Safari
- Sign in with your regular password
- GitHub → Settings → Password and authentication → Passkeys → Add a passkey
- Safari displays a prompt: "Do you want to save a passkey for github.com using iCloud Keychain?"
- Tap Continue then authenticate with Face ID
- ✅ Passkey saved in iCloud Keychain
For Apple sites (Apple ID): Settings → [your name] → Password & Security → Passkeys. Your Apple ID is the first account to secure.
Steps on Mac (macOS Sonoma, Safari)
On Safari for macOS, the flow is identical. Safari automatically offers iCloud Keychain when a site enables passkey enrollment. Note: Chrome on Mac doesn't offer iCloud Keychain by default - it offers Google Password Manager. If you want to store in iCloud Keychain, use Safari on Mac.
iOS AutoFill (Frictionless Sign-In)
Once the passkey is saved, iOS offers biometric AutoFill directly from the native keyboard:
- You open the app or site
- A banner appears at the bottom: "Sign in as [account name] ↑"
- Tap the banner + Face ID
- Sign-in in <2 seconds
In practice: iOS AutoFill sign-in is among the fastest passkey flows. With iCloud Keychain, passkeys sync automatically across an iPhone and a Mac signed into the same Apple ID, without any reconfiguration.
Apple Troubleshooting
| Issue | Solution |
|---|---|
| iCloud Keychain greyed out | Verify Apple ID 2FA is enabled (Settings → [name] → Password & Security) |
| Passkey prompt doesn't appear in Safari | Safari Settings → Passwords → AutoFill Passwords (enable) |
| Passkey visible on iPhone but not Mac | Wait a few minutes, force sync: System → Apple ID → iCloud → Sync Now |
| "This device doesn't support passkeys" | iOS too old (needs iOS 16+) or device too old |
04 - Microsoft Passkey Setup
Microsoft has had solid passkey support since November 2023 with Microsoft Authenticator + Windows Hello. Sync happens via your Microsoft Account.
Via Microsoft Account (Web)
- Go to account.microsoft.com
- Click Security in the top menu
- Then Advanced security options
- Under "Passkeys (FIDO2)," click Add a new way to sign in
- Select Passkey
- Choose where to store: on this device (Windows Hello) or in Microsoft Authenticator (mobile app)
Via Windows Hello (Windows 11)
Windows Hello stores passkeys locally in your PC's TPM:
- Windows Settings → Accounts → Sign-in options → Windows Hello Face/Fingerprint
- On your next sign-in to account.microsoft.com via Edge, Windows automatically offers to create a Windows Hello passkey
- Confirm with Face or fingerprint Windows Hello
- This passkey is tied to this device only - no cross-device sync for local Windows Hello passkeys
Via Microsoft Authenticator (iOS/Android)
Microsoft Authenticator can act as a cross-platform passkey provider:
- Install Microsoft Authenticator (iOS App Store / Google Play)
- Sign in with your Microsoft Account in the app
- On account.microsoft.com → Security → Advanced options → Add passkey
- Select Another device or Security key
- A QR code appears - scan it with Microsoft Authenticator
- Authenticator generates the passkey (synced via your Microsoft Account)
Typical time: about 3 minutes including Authenticator install; under 90 seconds if it's already installed.
Microsoft Services Supporting Passkeys in 2026
- Microsoft Account (Outlook.com, Hotmail)
- Xbox
- Microsoft 365 (with Azure AD/Entra ID configured by admin)
- Teams (personal)
- Outlook.com
Azure AD / Entra ID: in enterprise environments, configuration is done by the admin (Entra ID portal), not the end user. Check with your IT team.
Microsoft Troubleshooting
| Issue | Solution |
|---|---|
| "Passkey not supported on this device" | Verify Windows is updated (22H2+) and TPM is enabled in BIOS |
| Microsoft Authenticator not offering passkeys | Update app (version 6.8+) and reconnect your Microsoft Account |
| Error during QR scan | QR expires after 2 min - refresh the page and rescan |
| Passkey created but sign-in fails | Verify system clock is synchronized (drift >30s can break auth) |
05 - Cross-Provider and Limitations in 2026
This is the most confusing topic. As of June 2026, here's the exact state of affairs:
What Works
| Scenario | Works? |
|---|---|
| Google passkey → Chrome Windows | ✅ Yes, native |
| Google passkey → Chrome macOS | ✅ Yes, native |
| Google passkey → Chrome Android | ✅ Yes, native |
| Apple passkey → Safari macOS | ✅ Yes, native |
| Apple passkey → Safari iOS | ✅ Yes, native |
| Apple passkey → Chrome macOS | ⚠️ Partial (Chrome requests iCloud Keychain via OS prompt) |
| Microsoft passkey → Edge Windows | ✅ Yes, native |
| Microsoft passkey → Authenticator iOS/Android | ✅ Via app |
| Google passkey → Safari iOS | ❌ No (Google PM not integrated with native Safari) |
| Apple passkey → Chrome Android | ❌ No (iCloud not available on Android) |
Cross-Ecosystem Bridges
The CTAP2.2 cross-device passkey sharing standard (Apple-Google-Microsoft) is being finalized in 2026. The promise: a passkey created in iCloud Keychain could be exported to Google Password Manager. In practice, June 2026: this interoperability is not yet natively deployed across the 3 providers.
Pragmatic solution: use Bitwarden as a unified passkey provider. When creating a passkey, instead of letting the browser choose iCloud or Google PM, you select Bitwarden as the provider. The passkey then lives in your vault, synced across all OS. This is the most practical approach for managing many passkeys across platforms - see Bitwarden vs 1Password 2026.
06 - Backup and Recovery
Golden Rule: Never Rely on a Single Device
Loss scenarios:
- You lose your iPhone → Your Apple passkeys are in iCloud Keychain → they automatically restore on your new iPhone when you sign into your Apple ID. Recovery time: 15 min.
- You lose your Android → Google PM passkeys restore via Google Account on new phone. Time: 10 min.
- You lose your Windows PC → Windows Hello passkeys are gone (local). Microsoft Authenticator passkeys survive (cloud sync). You'll need to recreate Windows Hello passkeys on the new PC.
Recovery Procedure
For each account where you have a passkey:
- Go to the account's security settings
- Sign in with password + 2FA (fallback always active)
- Delete the passkey from the lost device
- Create a new passkey on your new device
Time per account: 3-5 min. For 10 accounts: expect 30-45 min.
Security Backup Tips
- ✅ Keep your password in Bitwarden for every account with a passkey - it's your real safety net
- ✅ TOTP 2FA on critical accounts (Bitwarden Authenticator or Aegis) - second fallback
- ✅ Recovery codes: download and store the one-time codes most services generate during 2FA setup (Google, GitHub, etc.)
- ✅ Bitwarden export: make a monthly encrypted export of your vault (Tools → Export)
- ❌ Never disable your password on critical accounts until passkeys are 100% mature
For details on 2FA backup apps, see our best authenticator app 2FA 2026 comparison.
07 - Which Provider to Choose for Your Ecosystem
| Profile | Recommendation |
|---|---|
| All Apple (iPhone + Mac) | iCloud Keychain - smoothest, native iOS AutoFill, zero friction |
| All Google/Android | Google Password Manager - native Chrome sync, multi-device Android |
| Microsoft / Windows 11 environment | Windows Hello + Microsoft Authenticator |
| Multi-platform (iOS + Windows or Android + Mac) | Bitwarden Premium ($10/year) - cross-platform, open source, unified passkeys |
| High-security profile | YubiKey hardware + OS passkeys as backup (see YubiKey FIDO2 guide) |
A typical cross-platform setup: in a mixed iPhone + Mac + Windows environment, iCloud Keychain works well for Apple-first accounts, but a cross-platform manager like Bitwarden is more practical for accounts you use everywhere. The concrete advantage: you can sign into a service such as GitHub from any OS without friction, using the same passkey managed by Bitwarden.
For new users starting from scratch: begin with Google Passkeys on your Google accounts (the fastest setup, <2 min), then evaluate whether you need cross-platform before investing in Bitwarden Premium.
If you want to understand why passkeys outperform traditional passwords technically, the passkeys vs passwords 2026 article covers the comparison in detail.
To choose the password manager that also handles your passkeys, our best password managers 2026 comparison does a complete tour.
Try Bitwarden Premium →Manage passkeys across Google/Apple/Microsoft in one place · open source · $10/year→
Based on the documented passkey setup flows on iOS 17.5, macOS Sonoma 14.5 and Windows 11 23H2. Times are indicative, June 2026.
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
A manager with built-in 2FA & passkeys → NordPassStore TOTP & passkeys · XChaCha20 · free tier→Frequently asked questions
Do Google passkeys sync to Apple/iOS?
Not natively. Google passkeys are stored in Google Password Manager - they sync across Chrome on Windows, Android, and macOS, but not into iCloud Keychain. To use a Google passkey from an iPhone on Safari, you'll need to use Chrome for iOS or a third-party manager like Bitwarden. In 2026, the CTAP2.2 cross-provider sharing standard is in progress but not yet finalized.
What happens if I lose my phone?
It depends on the provider. **Apple**: your iCloud Keychain passkeys automatically restore when you set up a new iPhone with your Apple ID. **Google**: same via Google Password Manager on Android. **Microsoft**: your Microsoft Account passkeys restore on a new device when you sign in. In all cases, keep your password + TOTP 2FA enabled as a fallback during restoration.
Are passkeys safer than TOTP?
Yes, on two critical points. **Anti-phishing**: a passkey only works on the exact site URL (origin-bound). A TOTP code can be entered on a fake site. **Anti-credential-stuffing**: no shared secret is transmitted - you can't steal what's never sent. The only weakness of software passkeys vs hardware (YubiKey): the private key is stored in a software enclave, theoretically vulnerable to root malware. In practice, security is far superior to TOTP for the vast majority of use cases.
Should I keep my password after enabling a passkey?
**Yes, absolutely**. In 2026, very few services allow you to completely delete your password after enabling a passkey. Even Google and Apple keep the password as a fallback method. Store it in Bitwarden and keep your TOTP 2FA active on critical accounts.
Do passkeys work on Linux?
Partially. Chrome and Firefox on Linux support WebAuthn/FIDO2 with hardware passkeys (YubiKey). For synced software passkeys (Google Password Manager, Apple Keychain), native Linux support is nonexistent or experimental as of June 2026. The most practical solution on Linux: Bitwarden (native Linux app + Chrome extension) which stores and auto-fills passkeys cross-platform.
Can I manage Google, Apple, and Microsoft passkeys from one place?
Yes, with Bitwarden Premium ($10/year) or 1Password. These third-party managers have supported passkeys since 2024 and act as a cross-platform passkey provider. You create the passkey via Bitwarden instead of iCloud Keychain or Google Password Manager - it's then synced across iOS, Android, Windows, macOS, and Linux in the same vault as your passwords.
How long does it take to set up passkeys on all 3 providers?
Typical setup times: **Google** ~2 min (clear Chrome prompt, immediate sync). **Apple** ~2 min on iPhone (a couple of extra steps in Settings). **Microsoft** ~3 min (Authenticator install + 2-step enrollment). All three providers: under 8 minutes.
Do passkeys work in all browsers in 2026?
Chrome (108+), Firefox (122+), Safari (16+), and Edge (108+) all support WebAuthn/FIDO2 passkeys. Internet Explorer is dead. Opera also supports them. Limitations remain on the platform side (sync) rather than the browser side: Google Password Manager syncs via Chrome/Google, iCloud Keychain via Safari/Apple, Microsoft via Edge/Authenticator.