To use passkeys and still sign in after losing a device, create the credential on a personal device, identify exactly where it is stored, and test signing in from a second device. Prefer a passkey stored in a synchronizing password manager if you need to use it across multiple devices. Do not assume that every passkey can be recovered automatically: a passkey stored locally in Windows Hello or on a security key may not have a backup (according to support.google.com).
You need a personal device protected by a PIN, password, fingerprint, or face recognition; an account that supports passkeys; and at least one backup sign-in method. If you are new to the concept, read our explanation of passkeys and passwordless sign-in. This article focuses on creating, synchronizing, testing, and handling passkeys when a device is lost.
Distinguishing synchronized passkeys from device-bound passkeys
A passkey is a cryptographic key pair. The service stores the public key, while the private key remains on the device or in a credential manager. When you sign in, you verify your identity with a PIN, fingerprint, face recognition, or a similar unlocking method. Biometric data is not sent to the website. Because a passkey is tied to the service’s correct domain, it reduces the risk of being tricked into entering credentials on a fake website compared with a conventional password (according to FIDO).
The term “passkey” does not, by itself, indicate where the key is stored. Distinguish between these two cases:
- Synchronized passkey: stored in a manager such as Google Password Manager or iCloud Keychain. After you verify your account and the new device, the passkey may appear on another device within the same ecosystem. Recovery still depends on the cloud account, unlock credentials, and the provider’s verification process.
- Device-bound passkey: stored only on a specific computer, phone, or security key. Windows Hello is one example when a passkey is stored locally on a Windows PC; Google says this type of passkey may not be backed up or recoverable if the computer is lost or the operating system is reinstalled (according to support.google.com).
How to choose: for email, social media, and shopping accounts, a synchronized passkey is usually more convenient if the manager account is well protected. For accounts requiring a higher level of assurance, you can add a physical security key, but you should have a spare key or backup method. A passkey stored only on a lost security key generally cannot be recovered remotely (according to FIDO).
Create a passkey and verify that it works on another device

Perform these steps on your personal account and device
Work from the service’s official security page or official app. Do not use a sign-in link in an email or message unless you have verified the address. Menu names may vary by operating-system version, browser, and service.
- Prepare the device: enable a screen lock on your phone or Windows Hello on your computer. Do not create a passkey on a shared computer; anyone who can unlock the device may be able to use the passkey stored on it (according to support.google.com).
- Google Account: open your Google Account security settings, select the passkey section, and create a passkey. When Chrome asks where to save it, select Google Password Manager if you want to use the passkey on devices signed in to the same Google Account. You may need to confirm with the manager’s PIN or the device’s unlocking method (according to support.google.com).
- Apple devices: on an iPhone, iPad, or Mac, turn on iCloud Keychain in your Apple Account’s iCloud settings, and enable two-factor authentication if the account requires it. Passkeys in iCloud Keychain may synchronize to approved Apple devices (according to support.apple.com).
- Windows Hello: on a Windows PC, open Settings > Accounts > Passkeys to view and manage passkeys stored on the computer. When a website asks where to save the passkey, confirm with your PIN, face recognition, or fingerprint. Do not treat Windows Hello as the only backup for an important account, because passkeys stored there may not be backed up (according to support.microsoft.com).
- Other services: in the website or app’s security settings, select Create a passkey or Create passkey. Read the confirmation dialog to determine whether the key will be stored in a manager, on a phone, in Windows Hello, or on a security key. If an option such as Change, Save another way or Save another wayis available, choose a storage location that suits your need to use the passkey across multiple devices (according to support.microsoft.com).
Test it immediately after creation: return to the service’s passkey-management page and check the name of the device or storage provider. Then, on a second device, open that service’s sign-in page and select the passkey. If the passkey does not appear, select Try another way or Use a passkey from another device, then scan the QR code with your phone and complete authentication. When your phone authenticates the nearby computer, Bluetooth may need to be enabled (according to support.google.com).
A successful sign-in on the second device is practical evidence that the service has recognized the passkey and that the storage provider can make the key available to a new device. Do not delete the password or old recovery method until you have tested the new method.
What to do when you lose, replace, or reset a device
First, determine whether you have lost one device but still have access to the passkey manager, or whether you have also lost access to the synced account. These situations require different responses.
- You lost one device but still have another: Use the remaining device to sign in to your account, open the passkey list, and revoke the passkey associated with the lost device. With Google, you can delete the passkey in your account’s security settings. If Android created the passkey automatically, check the relevant device and sign it out of your account if necessary (according to support.google.com).
- You replaced your phone or computer: Install or open the relevant passkey manager, sign in with the same account, enable syncing, and complete the new-device verification step. Apple may require approval from another Apple device or use the iCloud Keychain recovery process. Google may require your Google Password Manager PIN or the corresponding device unlock code (according to Apple Support; Google Chrome Help).
- You lost all your devices: Access the account using your password, trusted phone number, recovery code, recovery device, or the service’s official support channel. Apple describes recovering iCloud Keychain using Apple Account credentials, a trusted phone number, and the device passcode. The process limits the number of attempts, so do not repeatedly guess the code (according to support.apple.com).
- You lost a passkey stored only in Windows Hello or on a security key: Use a backup method to regain access, create a new passkey on the replacement device, and then delete the old passkey from the service’s security page. If that type of passkey has no backup, the original key cannot be recovered simply by reinstalling the application.
For each important account, consider having one synced passkey, one backup method, and, where appropriate, a second device or security key. Store recovery codes in a secure offline location, periodically review the device list, and immediately revoke the passkey belonging to a lost device. Passkeys reduce the risk of being tricked into entering credentials, but they do not protect against someone who has unlocked the device or taken control of the synced account.
If the passkey does not appear during sign-in, check the following in order: Is the device screen lock enabled? Are you signed in to the correct passkey-manager account? Do the browser and operating system meet the service’s requirements? Does the website support passkeys? And does the passkey still exist on the service’s side? Do not erase all passkey-manager data before identifying the cause, because doing so could also delete stored passwords and passkeys.

