Setting up a passkey is easier than setting up two-factor authentication, and most of the “difficulty” people run into comes from doing it in a scattered way — a passkey on the phone here, one in the browser there, none of them syncing. Get one decision right at the start (where your passkeys live) and the rest is just tapping “approve” with your fingerprint. This guide walks the whole thing, in order, in about half an hour.
Only have five minutes? Do this
If today only gives you a few minutes, add a passkey to the one account that matters most — your email — and save it into wherever you already keep passwords. That single move gives your most important account a phishing-proof sign-in. The rest of this guide is how to do it properly across everything else, but the load-bearing move is that first passkey on your email.
A quick note on what you’re actually doing
A passkey lets you sign in with your fingerprint, face, or PIN instead of a password — and it can’t be phished, because it only works on the real website’s domain. If that’s new, our plain-English passkey guide explains the why. This article is purely the how: the exact steps, in the right order, with the catches flagged.
The single most important thing to understand before you start: passkeys get saved somewhere, and where they’re saved decides whether they follow you across your devices. That’s why the very first step isn’t “add a passkey” — it’s “decide where they live.” Skip that decision and you’ll end up with passkeys stranded on one device and no idea why they don’t appear on another.
Step 1: Decide where your passkeys will live
You have two sensible homes. Pick one and be consistent.
- A password manager (like Bitwarden or 1Password). Passkeys saved here sync across every device and operating system you use — Windows laptop, Mac, iPhone, Android tablet, all the same. This is the brand-neutral choice, and for most people it’s the right one because it isn’t locked to a single company’s ecosystem.
- Your platform’s built-in store. On Apple devices this is iCloud Keychain; on Android and Chrome it’s Google Password Manager; on Windows it’s Microsoft. These are secure and free, and they’re seamless inside their own walls — but a passkey born on an iPhone is awkward the day you pick up an Android phone.
Bitwarden
Free, open-source, and it stores and syncs passkeys across every platform — the tidy, brand-neutral home if you use more than one kind of device.
1Password
The polished paid option: syncs passkeys alongside passwords with the smoothest cross-device experience, and the best setup if you're getting a family onto passkeys together.
How to choose in one line: if you use more than one brand of device, use a password manager; if you live entirely in one ecosystem (all Apple, say), the built-in store is fine too. Either way, decide now so everything lands in the same place.
Step 2: Secure the home account first
Here’s the part that’s easy to forget and important to get right: whatever stores your passkeys is now your master key. If someone gets into that account, they get the passkeys inside it. So before you create a single passkey, lock the store down:
- If it’s a password manager: give it a strong, unique master passphrase (four-plus random words you use nowhere else) and turn on two-factor authentication on the vault itself — an authenticator app, not SMS. This is the same non-negotiable setup we cover in the guide to ending password reuse.
- If it’s your platform account (Apple, Google, Microsoft): make sure it has a strong password and its own two-factor authentication, and that its recovery details are current and yours.
Passkeys are only as safe as the account that syncs them. Two minutes here protects everything that follows.
Step 3: Add your first passkey (start with one important account)
Now the actual passkey. Start with a single major account so you learn the flow before doing it in bulk — email, or your main Google, Apple, or Microsoft account are all good first choices. The steps are nearly identical everywhere:
- Open the account’s security settings. Look for a section named “Passkeys,” “Sign in without a password,” or “Security keys.” If you can’t find it, searching “service name passkey” usually lands you on the provider’s own help page.
- Choose “add a passkey” (or “create a passkey”).
- Approve with your fingerprint, face, or PIN when your device prompts. This is the moment your device creates the key pair.
- Choose where to save it when asked. This is the decision from Step 1 — pick your password manager, or your platform store. If your manager’s browser extension is installed, it’ll usually offer itself here.
That’s it. Under a minute, and you now have a phishing-proof sign-in on that account.
A common snag worth naming: on some setups your device tries to save the passkey to the platform store by default, even if you wanted it in your manager. Watch the “save to” prompt and pick deliberately. If your password manager isn’t offered, make sure its browser extension or app is installed and set as a passkey provider in your device settings (the exact path varies by platform).
Step 4: Test it, and confirm where it saved
Don’t assume — verify. Sign out of the account and sign back in using the new passkey. You should be asked for your fingerprint/face/PIN and let straight in, no password. That confirms two things at once: the passkey works, and it’s reachable where you expect.
Then check it landed in the right home. Open your password manager’s entry for that account (it’ll list the passkey) or your platform’s passkey settings, and confirm the new passkey is there. This thirty-second check is what saves you from the classic “I made a passkey but it’s not on my other phone” confusion — if it’s in a syncing store, it’ll be waiting on your other devices.
Step 5: Add passkeys to your other key accounts
With the flow learned, work through the accounts that would hurt most if compromised — the same priority list from our afternoon security plan:
- Email (if you didn’t start here) — the master key that resets everything else.
- Banking and payment apps.
- Cloud storage (where your documents and photos live).
- Primary social accounts and any shop with a saved card.
For each, it’s the same four taps: security settings → add a passkey → approve → save to your chosen home. After the critical list, add passkeys opportunistically — whenever a site you’re already signing into offers one, take the ten seconds. Don’t turn it into a scavenger hunt across every account you’ve ever made; that’s how people burn out. The important accounts are worth seeking out; the long tail can wait until you happen to log in.
Step 6: Set up recovery, and keep a strong fallback
Two loose ends that prevent a bad day later:
Recovery for your passkey store. Your passkeys live or die with the account that holds them, so make sure that account’s recovery is set up and stored safely:
- A password manager gives you a recovery code, emergency-access contact, or family-plan recovery depending on the product — set one up and store a printed copy somewhere physically safe at home.
- A platform account (Apple/Google/Microsoft) has its own account-recovery flow — confirm your recovery phone and email are current and yours.
A strong fallback password on each account. Most services keep your password active alongside the passkey. That’s convenient, but it means the account is only as strong as its weakest door. Adding a passkey doesn’t rescue a weak old password on the same account — so make sure each fallback is unique and strong (your password manager generates these for you). A handful of services now let you remove the password entirely and go passwordless; only do that once your passkey and recovery are rock-solid.
Platform quick-reference
The wording differs slightly by platform, but the location is consistent — it’s in the account’s security settings. As a rough map (menu labels change, so treat these as approximate):
| Where you’re setting it up | Roughly where to look |
|---|---|
| Google account | Security → “How you sign in to Google” → Passkeys |
| Apple account | Sign-in flows offer to save a passkey to iCloud Keychain; per-site under the site’s security settings |
| Microsoft account | Security → Advanced security options → Add a new sign-in method → Passkey |
| A website (bank, social, shop) | Account/Profile → Security or Login settings → “Passkeys” / “Sign in without a password” |
| Saving into a password manager | The manager’s browser extension/app offers itself at the “save passkey” prompt |
If a service you rely on has no passkey option yet, that’s normal — adoption is still spreading. Keep that account on a strong unique password with app-based 2FA until a passkey shows up.
Common mistakes to avoid
- Skipping the “where do they live” decision. This is the number-one cause of passkey confusion. Decide in Step 1, or you’ll strand passkeys on single devices.
- A weak lock on the store itself. Your password manager or platform account is now the master key — a weak password there undoes the whole point.
- Letting the fallback password rot. A passkey plus a terrible old password on the same account is only as safe as the terrible password. Keep the fallback strong.
- Trying to convert every account in one sitting. Do the critical ones deliberately; add the rest as you naturally encounter the offer. Bulk-converting everything is how people quit halfway.
- Never testing. Always sign out and back in once, so you find any problem now rather than during a lockout.
What passkeys don’t replace
Setting up passkeys is a big upgrade, but it isn’t the whole job. Your accounts still benefit from the rest of the basics — a password manager for the many sites that still need passwords, app-based two-factor where passkeys aren’t offered yet, and current recovery details everywhere. Passkeys slot into that stack; they don’t replace it. If you haven’t done the broader pass, our secure-your-accounts afternoon plan covers the lot in priority order, and the password manager comparison helps you pick the tool that will also hold your passkeys.
Do these six steps once and signing in gets both safer and faster — the rare upgrade that costs you nothing on an ongoing basis. This guide is part of our Privacy & Security Kit, where the passkey explainer and the account-security plan live alongside it.