Google Services

How to Create and Use Google Passkeys for Passwordless Account Sign-In

Replace vulnerable passwords with FIDO2 WebAuthn biometric passkeys across your phone, computer, and hardware keys for phishing-resistant Google login.

Quick Summary & Key Takeaways

  • Objective: Replace vulnerable passwords with FIDO2 WebAuthn biometric passkeys across your phone, computer, and hardware keys for phishing-resistant Google login.
  • Estimated Time: Approximately 7 minutes following our step-by-step instructions.
  • Safety Recommendation: Ensure your device battery is above 30% and preserve any important files or passwords before modifying system settings.
Biometric fingerprint scanner illustrating cryptographic passkey authentication
Passkeys pair a private cryptographic key on your device with Google's public key, preventing phishing attacks.

Traditional passwords—even complex combinations of symbols, letters, and numbers—remain the single largest vector for account takeovers, credential-stuffing attacks, and phishing compromises. Google passkeys represent the industry-wide evolution toward a passwordless future backed by the FIDO Alliance and World Wide Web Consortium (W3C).

Passkeys allow you to sign into your Google Account using your smartphone's fingerprint scanner, iPhone Face ID, Windows Hello facial recognition, or physical USB security keys. Here is how to create, manage, and use Google Passkeys safely across all your devices.


Why Passkeys Are Immune to Phishing Scams

To understand why passkeys represent a massive security leap forward, consider how phishing works: a scammer tricks you into typing your password into a fake login screen (e.g., g00gle-login.com). Because you enter your actual password, the attacker captures your credentials.

Passkeys rely on asymmetric public-key cryptography:

  • Public Key: Stored securely on Google's authentication servers.
  • Private Key: Stored exclusively inside your phone or computer's hardware security enclave (such as the Apple Secure Enclave or Android Titan M2 chip). It can never be exported or copied.
  • Cryptographic Challenge: During login, Google issues an encrypted mathematical challenge. Your device verifies your physical biometric identity (fingerprint or face) and signs the challenge with the private key.
  • Domain Binding: Your browser strictly refuses to provide the cryptographic signature unless the web address exactly matches accounts.google.com. Even if you accidentally click a malicious phishing clone, the passkey mathematically refuses to respond.

Step 1: Create a Google Passkey on Your Smartphone

Setting up your first passkey takes less than two minutes:

  1. Open your web browser on your phone and navigate to: g.co/passkeys (or open your Google Account dashboard at myaccount.google.com).
  2. Sign in with your existing password and two-factor code if prompted.
  3. Tap Security in the top navigation bar.
  4. Under the "How you sign in to Google" section, tap Passkeys and security keys.
  5. Tap the blue Create a passkey button.
  6. A system dialog appears asking: "Do you want to save a passkey for your Google Account?"
  7. Confirm using your device biometric authentication (Touch ID, Face ID, or Android Fingerprint).
  8. Your passkey is created immediately and synchronized safely to your operating system's encrypted keychain (iCloud Keychain on Apple devices, Google Password Manager on Android).

Step 2: Set Up Passkeys on Windows 11 and Mac Desktops

You can also register your laptop or workstation directly so you can unlock Gmail, Google Drive, and YouTube with a touch of a finger:

  1. Open Google Chrome, Microsoft Edge, or Safari on your desktop.
  2. Go to myaccount.google.com/security/passkeys.
  3. Click Create a passkey.
  4. When prompted by your operating system:
  • On Windows 11: Scan your finger on your laptop's fingerprint sensor or look into the Windows Hello IR camera.
  • On macOS: Touch the Touch ID sensor on your Magic Keyboard or MacBook.
  1. Enter a friendly descriptive label for the device (e.g., "Workstation ThinkPad Windows 11").

Step 3: How to Sign In Using a Passkey on an Unfamiliar Device

If you are using a public computer, library terminal, or a friend's laptop where your personal passkey is not saved, you can still log in without typing a password:

  1. Enter your Google email address at accounts.google.com.
  2. Click Continue. A prompt will state: "Use your passkey to confirm it's really you."
  3. If logging in from an unfamiliar computer, select Use a phone, tablet, or security key.
  4. A secure QR code will appear on the computer monitor.
  5. Open your smartphone's native camera app and scan the QR code.
  6. Your phone establishes an encrypted short-range Bluetooth handshake with the computer to verify you are physically standing in front of the screen.
  7. Scan your fingerprint on your phone. The computer logs you into your Google Account instantly.

Step 4: Managing and Revoking Passkeys

If you sell, trade in, or lose a smartphone or laptop, revoke its passkey immediately:

  1. Visit myaccount.google.com/security/passkeys.
  2. Review the list of active passkeys. Each entry indicates device type, creation date, and last used timestamp.
  3. Locate the decommissioned device and click the X (Remove) icon.
  4. Confirm deletion. The cryptographic key pairing is instantly invalidated across Google's infrastructure.

Account Recovery Best Practices

  • Always register at least two distinct devices (for example, your personal phone and your home laptop) with passkeys.
  • Keep standard account recovery phone numbers and an off-platform recovery email (like Outlook or Proton) verified in your Google Account security tab so you never get locked out if a device breaks.

Frequently Asked Questions

What happens if I lose my phone with my passkey on it?

If you lose your phone, your passkey is still protected by your lock screen biometric or PIN. Furthermore, your passkeys are backed up in end-to-end encrypted cloud keychains (iCloud Keychain or Google Password Manager). Signing into a new phone restores your passkeys seamlessly.

Can someone steal my passkey if Google gets hacked?

No. Google only stores your public cryptographic key. A public key is useless to an attacker without the corresponding private key, which never leaves your physical phone's secure hardware enclave.

Can I still use my traditional password if I need to?

Yes. Google supports hybrid authentication. If you are ever on a device that doesn't support passkeys or modern browsers, you can select 'Try another way' and enter your standard password.

Elena Rostova

About the Author: Elena Rostova

Cloud & Google Workspace Specialist

Elena researches cloud storage architectures, Google Workspace workflows, browser privacy, and account security solutions.