The password is finally losing. According to the FIDO Alliance's State of Passkeys 2026 report, there are now an estimated 5 billion passkeys in active use worldwide, and 90% of consumers say they know what a passkey is — up from 75% a year earlier. If you have unlocked an app with your face or fingerprint instead of typing a password, you have probably already used one.
What a passkey actually is
A passkey replaces your password with a pair of digital keys. When you create one, your device generates two linked keys:
- A public key, which the website stores. On its own it is useless to an attacker.
- A private key, which never leaves your device and is protected by your fingerprint, face, or device PIN.
To sign in, the site sends your device a challenge. Your device proves it holds the private key without ever revealing it. Nothing secret travels across the internet, and there is no password sitting in a database waiting to be stolen.
Crucially, your fingerprint or face is never sent anywhere either. It only unlocks the key stored on your own device.
Why this stops phishing
This is the part that matters most. Passkeys are tied to the specific website that created them. If you land on a convincing fake copy of your bank's site, your device simply will not offer the passkey — the web address does not match. You cannot be tricked into handing over a credential you never actually type.
That closes the single most common route into accounts. Phishing, password reuse, and credential-stuffing attacks all depend on a human typing a secret into the wrong place. Passkeys remove the secret from the equation.
Where adoption actually stands
The headline numbers are strong, but the detail is more honest:
- 75% of consumers have enabled a passkey on at least one account.
- 68% of organisations have deployed, are piloting, or are rolling out passkeys for employee sign-in.
- But 57% of organisations that deployed passkeys still rely on phishable methods — such as passwords or SMS codes — for everyday sign-in.
That last figure is the real state of play. Many companies have switched on passkeys without switching off the weaker option behind them, and an attacker will always attack the weakest available route. Support has also lagged in older internal systems that would need significant rebuilding.
How to start using passkeys today
For most people, the practical steps are simple:
- Check your major accounts — email, banking, and social platforms — under security or sign-in settings.
- Create a passkey where offered. It usually takes one tap plus your fingerprint or face.
- Let your device sync it through your platform or password manager so you are not locked out if you lose a device.
- Keep one backup method until you are confident, then remove weak options like SMS codes where possible.
The strongest security habit remains the same one we highlighted in our guide to patching known vulnerabilities: attackers overwhelmingly use the easy door, so closing easy doors matters more than exotic defences.
Why it matters
Passwords have been the weakest link in security for decades. They are reused, guessed, leaked in bulk, and phished daily. A genuinely phishing-resistant standard supported by every major operating system and browser is one of the few security changes that improves safety for ordinary people without asking them to be experts.
Key takeaways
- An estimated 5 billion passkeys are now in active use, with 90% consumer awareness.
- Passkeys use a key pair; the private key never leaves your device and your biometrics are never sent anywhere.
- They resist phishing because they only work on the exact site that created them.
- 57% of organisations that deployed passkeys still allow phishable sign-in methods alongside them.
- Turning on passkeys for your main accounts is a quick, high-value security upgrade.
The bottom line
Passkeys are no longer an experiment. They are widely supported, genuinely more secure, and easier to use than what they replace. The remaining obstacle is not technology — it is finishing the job by switching the old, weaker options off.