GlossaryDEFINED TERM / PASSKEY

Passkey

A phishing-resistant sign-in based on asymmetric cryptography and WebAuthn/FIDO principles.

Working definition

With a passkey, the private key remains with the authenticator while the service stores a public key. The signature is bound to the legitimate origin, resisting conventional phishing.

Security also depends on synchronisation, device protection, recovery and fallback. A weak alternative sign-in can completely bypass the passkey's strength.

Three verification questions

  1. 01Is sign-in bound to the correct origin?
  2. 02How do recovery and fallback work?
  3. 03Can individual passkeys be revoked?