Passkey
A phishing-resistant credential based on public-key cryptography that lets a user authenticate without transmitting a reusable password secret.
Security Context
A passkey replaces a reusable server-side password secret with a public-key credential. The server stores the public key, while user verification can occur locally at the authenticator through a PIN or biometric mechanism. Origin binding makes the credential resistant to conventional phishing flows.
Authentication Boundary
Using a passkey does not mean that a biometric template is sent to the server. On common authenticators, biometrics are used locally to unlock use of the private credential.
Related Security Concepts
- WebAuthn
- Public Key Infrastructure
- mTLS
- Zero Trust