Passkeys: what they are and why we use them

A plain explanation of passkeys, how signing in with one works, why they are safer than passwords, and what a business owner needs to know before using them.

If you have signed in to a bank or a large website recently and were asked to use your fingerprint, your face or your phone’s unlock instead of typing a password, you have used a passkey. The owner portal for PageKept websites signs you in the same way. This article explains what is going on, why we chose it, and what it means for you day to day.

What a passkey is

A passkey is a pair of keys created for one website on one of your devices. The public half is stored by the website. The private half never leaves your device, and your device only uses it after you unlock it, with a fingerprint, your face, a PIN or a hardware key. When you sign in, the website sends a challenge, your device signs it with the private half, and the website checks the signature against the public half it holds.

Nothing you can type is involved. There is no password to choose, remember, reuse or write on a sticky note, and nothing that a person at the other end can be tricked into handing over.

Why passkeys are safer than passwords

Most account break-ins come from three things: a password reused from another site that leaked, a password guessed because it was weak, and a password typed into a fake sign-in page. Passkeys remove all three.

  • They cannot leak from us. We store only the public half, which is useless on its own. If our database were stolen, no passkey in it could be used to sign in anywhere.
  • They cannot be reused. Each passkey works for exactly one website. Your portal passkey does not exist anywhere else.
  • They cannot be phished. A passkey is tied to the real address of the site it was made for. A look-alike page at a similar address gets nothing, because your device refuses to sign for it. This is the property that password managers and one-time codes do not fully give you.

The United States government’s guidance for digital identity treats this kind of device-bound, phishing-resistant sign-in as the strongest level available to ordinary users.

What it is like to use

Signing in takes a few seconds: open the portal, choose your account, unlock your device the way you always do. On a phone that is a fingerprint or face; on a laptop it is the same, or a PIN; with a hardware security key it is a touch.

Passkeys can live in more than one place. Apple, Google and Microsoft accounts can sync them between your own devices, so a passkey made on your phone is available on your laptop. A password manager can hold them too. You can also register more than one passkey on the portal, for example one on your phone and one on a hardware key kept in a drawer, and either signs you in.

What you need to know as a business owner

  • Set up two. Register a passkey on your everyday device and a second one somewhere else, so losing a phone is an inconvenience rather than a lockout. The portal lets you add and remove passkeys at any time.
  • Losing a device is not losing the account. Remove the lost device’s passkey from the portal and carry on with the other. If you have only one and lose it, we verify who you are and issue a new enrollment link; that takes a conversation rather than a click, which is the point.
  • Staff get their own. Anyone who manages your website gets their own passkey under their own name, so you can see who changed what and remove one person without affecting another. Sharing a sign-in is the habit passkeys are designed to end.
  • Your email apps still use app passwords. Mail programs on phones and computers do not sign in with passkeys yet, so business email uses a separate random password per device, created in the portal and revocable one at a time. The two systems do the same job in the place each one fits.
  • Older devices. Passkeys work on current phones and computers and on browsers released in the last few years. If a device you rely on cannot use them, tell us and we will find a way that works for you.

Why we chose them

The owner portal changes what is on your website. A stolen sign-in would let someone change your prices, your hours or your contact details, and you might not notice for a while. Passkeys close the most common ways that happens, and they are easier to use than what they replace. That combination is rare enough in security that when it is available, using it is the sensible default.

If you would like help setting up a second passkey, or a hardware key for the office, get in touch.

Sources

  1. FIDO Alliance: Passkeys
  2. NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management
  3. passkeys.dev: Device support

If this is on your list

We build websites with an owner portal and look after them. If you would like help with any of this, tell us about your business.

All articles

Let’s talk

Tell us a little about your business. We’ll reply by email.

If you have one, for example example.com.

What can we help with?

Choose any that apply.

Anything you would like us to know.

How would you like us to reach you?

Only needed if you would like a call or a text.

For example, weekday mornings.

See how we handle your details in our privacy policy.