How to Create and Use Passkeys on Android

How to Create and Use Passkeys on Android

Passwords are the weakest part of almost every account. They get reused, guessed, phished, and leaked in breaches you never hear about until it is too late. Passkeys android sign-in replaces the password entirely: instead of typing something you remember, you approve the sign-in with the fingerprint, face unlock, or screen lock you already use on your phone.

A passkey is a pair of cryptographic keys. The website keeps a public key, and your phone keeps the private key locked inside Google Password Manager (or another password manager you choose). When you sign in, your phone proves it holds the private key after you unlock it with biometrics — and it only works for the real website, which is why passkeys cannot be phished. Create the passkey once, and it syncs across your Android devices and Chrome through your Google account.

This guide walks you through it step by step: what you need before you start, how to create a passkey, how to sign in with it on Android and on a computer, how to manage and delete passkeys, and how to fix the problems beginners run into most often.

What Passkeys Are (and Why They Beat Passwords)

You do not need cryptography to use passkeys, but a one-minute picture helps:

  • A password is a shared secret. You type it, the website stores a copy of it, and anyone who learns it — from a phishing page, a leak, or by watching you type — can use it from anywhere.
  • A passkey is not shared. Your phone generates two linked keys: a public key that goes to the website and a private key that never leaves your password manager. Signing in is your phone answering a maths challenge that only the real private key can answer.
  • Your fingerprint never leaves the phone. The website never sees your biometrics. Your fingerprint or face simply unlocks the private key locally, the same way it unlocks your phone.
  • Passkeys are site-locked. A passkey created for your bank only works on your bank’s real domain. A fake look-alike site gets nothing, even if you tap through to it — there is no password to type into the wrong place.
  • Passkeys sync. Passkeys stored in Google Password Manager sync through your Google account with end-to-end encryption, so a passkey created on your phone is available on your tablet and in Chrome on your computer when you are signed in with the same account.
  • There is nothing to remember. Every account gets its own unique passkey automatically. The “one password for everything” problem disappears.

Passkeys do not replace your phone’s screen lock — they depend on it. Whoever can unlock your phone can approve passkey sign-ins, so a strong PIN and registered biometrics matter more, not less, once you switch.

Before You Start: What You Need

Check these five things first and creating a passkey will take under a minute per account:

  1. Android 9 or newer (check in Settings > About phone > Android version). Passkeys work from Android 9, but Android 14 or newer is strongly recommended because it handles third-party password managers properly and makes prompts far more reliable. If an update is waiting in Settings > System > System update, install it first.
  2. A Google account signed in on the phone. Open Settings > Passwords, passkeys and accounts (or search Settings for “passkey”) and confirm your Google account is listed as the autofill / password manager service. This is where synced passkeys live.
  3. A screen lock with biometrics set up. You need a PIN, pattern, or password at minimum, plus a fingerprint or face unlock registered for the one-tap experience. If you have not enrolled a fingerprint yet, do it now: Settings > Security & privacy > Device unlock > Fingerprint Unlock (Pixel), Settings > Security and privacy > Screen lock and biometrics (Samsung), or Settings > Passwords & security > Fingerprint unlock (Xiaomi). Test that it unlocks your phone reliably before you continue.
  4. Updated Google apps. Open the Play Store, search Google Chrome and Google Play services, and install any pending updates. Outdated Play services is the number one reason the “Create a passkey” prompt never appears.
  5. Bluetooth on, for cross-device sign-in. You only need this when you sign in on a computer using a passkey stored on your phone (the devices prove they are near each other over Bluetooth). Leave Bluetooth enabled and you will never have to think about it.

A note on which password manager holds your passkeys

On Android you have a real choice, and it is worth making deliberately:

  • Google Password Manager (recommended for most people): built in, syncs through your Google account, works in Chrome and Android apps, and is the default on Pixel and most phones. This guide uses it as the main path.
  • Samsung Pass: on Galaxy phones Samsung Pass may offer to save passkeys. It works, but it syncs only within the Samsung ecosystem. If you use Chrome or a non-Samsung tablet, prefer Google Password Manager so your passkeys follow you.
  • 1Password, Bitwarden, Dashlane, and other third-party managers: fully supported on Android 14+ through Credential Manager. If you already keep passwords in one of these, storing passkeys there keeps everything in one vault — just set it as your preferred service in Settings > Passwords, passkeys and accounts first.

Whichever manager you pick is where your passkeys will be created, listed, and deleted. Mixed storage (some passkeys in Google, some in Samsung Pass) is the most common cause of “I know I created one but it’s not here” confusion later.

How to Create a Passkey on Android

There are two ways a passkey gets created: the website or app offers it, or you start it yourself from the account’s security settings. Both end at the same Android prompt.

Method 1: Accept the “Create a passkey” offer (easiest)

Many services — Google, Amazon, PayPal, eBay, Microsoft, GitHub, WhatsApp, TikTok, and a fast-growing list of banks and stores — offer a passkey right after you sign in or in a banner on the account page.

  1. Sign in to the app or website the normal way (with your existing password, just this once).
  2. Look for a prompt or banner saying “Create a passkey”, “Add a passkey”, or “Sign in faster next time”. Tap it. If no banner appears, use Method 2 — the option is usually in settings.
  3. An Android system sheet slides up titled “Create a passkey”, showing the account name and which password manager will save it (for example, “Save to Google Password Manager”). Check the manager’s name here — if it says Samsung Pass and you wanted Google (or the other way round), cancel and fix your default first (see the note above).
  4. Tap Continue (wording varies slightly: Create, Continue, or Save).
  5. Unlock with your fingerprint, face, or screen lock PIN when asked. This touch authorises the new private key.
  6. You will see a confirmation such as “Passkey created”. Done — the passkey is already syncing to your other devices.

Method 2: Create it from the account’s security settings

If nothing was offered, create the passkey deliberately. The menu names differ per service, but the shape is always the same:

  1. Open the app or website and go to Account / Profile > Settings > Security (or Sign-in & security).
  2. Find Passkeys, Passkeys and security keys, or Passwordless sign-in. (On a Google account: myaccount.google.com > Security > “How you sign in to Google” > Passkeys and security keys.)
  3. Tap Create a passkey / Add passkey.
  4. Follow steps 3–6 from Method 1: confirm the saving manager, tap Continue, and approve with your fingerprint.

Worked example: add a passkey to your Google account

Your Google account passkey is the most valuable one to create first, because it protects the account that syncs all the others.

  1. On your phone, open Chrome and go to myaccount.google.com, signed in as yourself.
  2. Open the Security tab, scroll to “How you sign in to Google”, and tap Passkeys and security keys.
  3. Tap Create a passkey, then Continue on the explanation screen.
  4. When the Android “Create a passkey” sheet appears, confirm it shows your Google account and Google Password Manager, then tap Continue.
  5. Touch the fingerprint sensor (or enter your PIN). You will get a “Passkey created” confirmation, and the new passkey appears in the list on that page with the date and device.

From now on, signing in to Google on this phone can be a single fingerprint touch — and Chrome on your computer will offer the same passkey because it synced.

Where brands differ: Pixel vs Samsung vs Xiaomi

The passkey sheet itself is Android system UI, so the tap sequence is identical everywhere. What differs is where the surrounding settings live:

  • Google Pixel / stock Android: Settings > Passwords, passkeys and accounts lists your services, and Google Password Manager is the default. Fingerprint setup is under Settings > Security & privacy > Device unlock. Pixel also tends to receive the newest Credential Manager behaviour first.
  • Samsung Galaxy (One UI): the same sheet appears, but Samsung Pass may be preselected if you have used it before. To make Google the default, go to Settings > General management > Passwords, passkeys, and autofill (on older One UI: Settings > Security and privacy > More security settings) and set the preferred service to Google. Fingerprint setup: Settings > Security and privacy > Screen lock and biometrics. Samsung Internet supports passkeys, but Chrome gives more consistent prompts — use Chrome for first-time creation if a prompt misbehaves.
  • Xiaomi / Redmi / POCO (HyperOS / MIUI): look under Settings > Passwords & security for fingerprint enrolment. For the autofill/passkey provider, check Settings > Passwords, passkeys and accounts on newer HyperOS builds (older MIUI: Settings > Additional settings > Languages & input > Autofill service) and confirm Google is selected. In Mi Browser, passkey prompts can be inconsistent; create passkeys in Chrome instead, then use them anywhere.

If your Settings app has a search box at the top, searching “passkey” or “autofill” jumps straight to the right screen on all three brands.

How to Sign In With a Passkey on Android

Signing in is where passkeys feel like magic — one touch, no typing.

In an app or in Chrome on the same phone

  1. Open the app or website and tap Sign in. Many services now show a “Use a passkey” or “Sign in with a passkey” button; others detect passkeys automatically.
  2. If asked for a username, enter it (or pick the account from the autofill suggestion that slides up from the keyboard — Android often offers “Use your passkey” right there with your account name).
  3. The “Sign in with a passkey” sheet appears, naming the account and the site or app asking. Check the site name is the one you expect.
  4. Tap Continue and approve with your fingerprint, face, or PIN.
  5. You are signed in. No password was typed, and nothing reusable was sent anywhere.

If the service still shows a password field and nothing passkey-related, tap the password field once — on Android 14+ the keyboard or autofill bar will frequently surface a passkey suggestion for that account. Selecting it runs the same unlock-and-go flow.

Sign in on a computer using the passkey on your phone

A passkey created on your phone can sign you in on a Windows PC, a Mac, or a shared computer, without the passkey ever leaving your phone.

  1. On the computer, open the website in Chrome (or Edge/Safari) and choose Sign in with a passkey.
  2. The browser shows a QR code on screen.
  3. On your Android phone, open the Camera app and point it at the QR code (on Pixel, the QR scanner tile in Quick Settings also works; on Samsung, the Camera app or the Scan QR code tile).
  4. Tap the link or banner the camera shows, such as “Sign in with a passkey”.
  5. Keep the phone near the computer — the two confirm proximity over Bluetooth — then approve with your fingerprint on the phone.
  6. The computer signs you in a second later.

If you are signed into the same Google account in Chrome on that computer, your synced passkey is usually offered directly and no QR code is needed. On a public or shared computer, always sign out afterwards — the passkey protected the sign-in, but the browsing session afterwards is a normal logged-in session.

Sign in on a second Android phone or tablet

There is nothing special to do. Sign in to the second device with the same Google account, give it a few minutes on Wi-Fi to sync, and your passkeys will simply be offered when a service asks for one. This is also what happens when you buy a new phone: sign in to your Google account during setup, and your passkeys are already there.

How to View, Manage, and Delete Passkeys

All of your Google-saved passkeys are listed in one place:

  1. Open Settings > Passwords, passkeys and accounts > Google Password Manager (or open Chrome > ⋮ > Password Manager), or visit passwords.google.com in any browser.
  2. Tap the service you want. Each entry shows whether it has a passkey, a password, or both, plus the account name.
  3. To see passkey details, open the entry and authenticate with your fingerprint — you will see the created date and last-used information.

From the service’s own security settings (for example, Google’s Passkeys and security keys page, or the equivalent at Amazon, Microsoft, or GitHub), you can also:

  • Rename a passkey where the service allows it (“Pixel 9 – Google” is more useful than a default name when you own several devices).
  • Delete / revoke a passkey. Do this immediately if the phone holding it was lost before you could wipe it, or when you sell a device whose passkeys were not synced (rare — synced passkeys should also be removed from Google Password Manager; see below).
  • Check last-used dates to spot a passkey you do not recognise.

If you are leaving an old Google account behind, deleting the passkey on the service’s page is not enough on its own: delete it from Google Password Manager for that site as well, so no device keeps offering it.

Passkeys With Third-Party Password Managers (Android 14+)

If you keep your digital life in 1Password, Bitwarden, Dashlane, or a similar vault, you do not have to split passwords and passkeys across two homes:

  1. Install the manager’s app and sign in.
  2. Go to Settings > Passwords, passkeys and accounts and set that manager as the preferred / autofill service.
  3. Create passkeys exactly as in the steps above — the Android sheet will now say “Save to 1Password” (or your chosen manager) instead of Google Password Manager.
  4. Signing in works identically: pick the passkey, unlock the vault with biometrics, done.

Passkeys stored in a third-party manager sync through that manager’s account, which also makes them available on iPhone and desktop apps from the same provider — handy in mixed-device households. On Samsung and Xiaomi phones, check after a system update that the brand’s own manager (Samsung Pass / Mi Password Manager) has not reclaimed the default; this silently changes where new passkeys get saved.

Safety and Privacy Notes Worth Knowing

  • Your biometrics never leave the phone. The website receives only a cryptographic “yes, the right private key approved this.” Your fingerprint and face data stay in the phone’s secure hardware.
  • Passkeys resist phishing by design. A passkey is bound to the exact domain that created it. A fake site cannot ask your phone to use the real site’s passkey, and there is no secret to type into a fake page. This is the biggest security upgrade over passwords — and over one-time codes, which can be phished in real time.
  • Syncing is end-to-end encrypted. Google Password Manager syncs passkeys through your Google account in encrypted form. Protect that Google account accordingly: it should itself have a passkey and/or a strong password plus 2-Step Verification.
  • Your screen lock is now your master key. Anyone who can unlock your phone can approve passkey sign-ins. Use a PIN of 6 or more digits (not your birth year), enrol only your own fingers and face, and set a short auto-lock timeout in Settings > Security & privacy.
  • You still need an account-recovery path. Keep your old password (stored in your password manager) and your recovery email and phone number up to date even after creating a passkey. If you lose every device holding a passkey, the service’s normal account recovery is how you get back in.
  • Work and school accounts may behave differently. Managed devices and Workspace accounts can restrict passkey creation or require organisation-approved managers. If “Create a passkey” is missing on a work account, that is policy, not a fault.

Troubleshooting

The website offers no “Create a passkey” option

  • Not every service supports passkeys yet, and some only offer them on the website (not the app), in certain countries, or the other way round. Check the service’s Security settings on its website in Chrome first — that is where support usually lands earliest.
  • Update Chrome and Google Play services in the Play Store, restart the phone, and look again; a surprising number of “missing” passkey options are just stale components.
  • Try while signed in on the service’s website rather than inside an app’s embedded web view, which often cannot trigger the Android passkey sheet.

I created a passkey but sign-in still asks for my password

  • Some services keep the password as the default and hide the passkey behind a “Use a passkey” or “Sign in another way” link on the sign-in screen — tap that instead of typing.
  • The passkey may have been saved to a different manager than the one sign-in is checking (the classic Samsung Pass vs Google split). Look in passwords.google.com and in Samsung Pass or your third-party manager to find where it lives, then set that manager as the default in Settings > Passwords, passkeys and accounts — or delete it and re-create it in the right place.
  • In Chrome, make sure you are signed into Chrome with the same Google account that holds the passkey; a guest profile or second profile will not see it.

The passkey prompt never appears or instantly fails

  • Confirm a screen lock is set and biometrics actually unlock the phone. Android refuses passkey creation on phones with no screen lock.
  • For QR-code sign-ins, toggle Bluetooth off and on and keep the phone within arm’s reach of the computer — cross-device sign-in fails closed if proximity cannot be proven.
  • Clear a one-off glitch: Settings > Apps > See all apps > Google Play services > Storage & cache > Clear cache (cache only, not data), then retry.
  • On Xiaomi/POCO, create and first-use passkeys in Chrome, not Mi Browser; on Samsung, prefer Chrome over Samsung Internet for the first creation. Once created, the passkey normally works in the brand browser too.

Fingerprint is not accepted at the passkey sheet

  • The sheet uses your normal device unlock. If your fingerprint fails there but works on the lock screen, delete and re-enrol the fingerprint, capturing the edges of your finger.
  • Wet or very dry fingers, thick screen protectors, and in-display sensors are the usual culprits. Register the same finger twice for reliability, or fall back to face unlock or PIN at the sheet — all three authorise a passkey equally well.
  • After several failed attempts Android asks for the PIN instead. That is normal security behaviour, not an error.

My passkeys are not syncing to my new phone

  • Check the obvious: the same Google account on both phones, both on Wi-Fi, and Sync enabled under Settings > Passwords, passkeys and accounts (and Settings > Accounts > Google on some brands).
  • Open Chrome on the new phone, confirm you are signed in with sync on, then open passwords.google.com to verify the passkeys exist in the account. If they show on the web but are not offered at sign-in, give sync an hour and restart the phone.
  • Passkeys saved in Samsung Pass or a third-party manager do not sync through Google — you must sign that manager in on the new phone as well.

I lost the phone that held my passkeys

  1. On any computer, sign in to the service (with your password and recovery options, or a synced passkey on another device) and revoke the passkeys listed in its security settings.
  2. For Google-saved passkeys, change your Google account password and review myaccount.google.com > Security > Your devices — sign out the lost phone. A finder cannot use your passkeys without your fingerprint or PIN, but revoking promptly is the clean habit.
  3. Set up your replacement phone, sign in to your Google account, and your remaining synced passkeys restore themselves. Re-create any passkeys you revoked.

Should I delete my password after creating a passkey?

  • Not yet, usually. Many services still require the password for sensitive changes (email change, deleting the account) and for recovery. Keep the password stored in your password manager, make sure it is long and unique, and let the passkey handle daily sign-ins.
  • You may freely delete duplicate passkeys (for example, one in Google and one in Samsung Pass for the same account) to keep sign-in prompts tidy — keep the one in the manager you actually use.

Wrap-Up

Passkeys turn Android sign-in into the thing it always should have been: tap “Use a passkey,” touch the fingerprint sensor, done — no typing, no remembering, and no password for a fake site to steal. Create your first passkey on your Google account and on the services you use daily (email, banking, Amazon, PayPal, WhatsApp), making sure the creation sheet names the password manager you actually want — Google Password Manager for most people — before you touch the sensor. After that, sign-in offers the passkey automatically, synced passkeys follow you to new phones and to Chrome on your computer, and the QR-plus-fingerprint trick covers everything else. Ten minutes of setup today removes your most phishable password from daily use for good.

Frequently Asked Questions

What is a passkey on Android? A passkey is a password replacement stored in Google Password Manager (or another manager you choose). Instead of typing a password, you approve sign-in with your fingerprint, face, or PIN. The site keeps a public key; your phone keeps the private key and only uses it for that exact site, which makes passkeys resistant to phishing.

Are passkeys safe? Yes — they are widely considered safer than passwords. Your private key never leaves your password manager in a usable form, your biometrics never leave the phone, each account gets a unique passkey that cannot be reused or guessed, and a passkey cannot be tricked into working on a fake website. The main thing to protect becomes your phone’s screen lock and your Google account.

Do passkeys sync between my phone and computer? Yes. Passkeys saved in Google Password Manager sync through your Google account, so they appear in Chrome on Windows, Mac, and ChromeOS when you are signed in with the same account. For a computer where you are not signed in, use the QR code shown at sign-in: scan it with your phone and approve with your fingerprint (Bluetooth must be on so the devices can confirm they are near each other).

What happens if I lose my phone? Your passkeys are protected by your fingerprint and PIN, so a finder cannot use them. Sign in on another device (with a synced passkey, your password, or recovery options), revoke the passkeys on important accounts from their security settings, and sign the lost phone out of your Google account. When you set up a replacement phone with the same Google account, your synced passkeys come back automatically.

Can I use passkeys with 1Password or Bitwarden instead of Google? Yes, on Android 14 or newer. Install the manager, set it as the preferred service in Settings > Passwords, passkeys and accounts, and passkeys will be created and stored there instead of Google Password Manager. They then sync through that manager’s account, including to its iPhone and desktop apps.

Why does Samsung keep offering Samsung Pass for passkeys? Galaxy phones ship with Samsung Pass as a default credential service, so the create-passkey sheet may preselect it. You can switch the default to Google Password Manager (or a third-party manager) in Settings > General management > Passwords, passkeys, and autofill. Passkeys already saved in Samsung Pass stay there until you delete and re-create them in the other manager.

Do I still need my password after creating a passkey? Usually yes, as a backup. Most services still use the password for account recovery and for sensitive changes, and you will need it if you ever lose all devices holding the passkey. Keep it long, unique, and stored in your password manager — just stop typing it every day.

Which Android version do I need for passkeys? Passkeys work from Android 9, but Android 14 or newer is recommended: it brings proper support for third-party password managers and much more reliable passkey prompts in apps and browsers. If your phone can update, update before you start.

Passkey or password + 2FA — which is better? A passkey is stronger. A password plus SMS or app codes can still be phished (a fake site can relay your code in real time), while a passkey physically cannot be used on the wrong site. Where a service offers both, prefer the passkey and keep 2FA enabled anyway as a fallback for recovery paths that still involve the password.

Facebook comments