Here’s a strange fact about 2026: over 15 billion accounts worldwide can now log in with a passkey instead of a password, according to the FIDO Alliance, and Google alone processes more than a billion passkey sign-ins a month. And yet, if you’re being honest, you probably typed a password at least once today. One recent industry analysis put it bluntly: 800 million passkeys have been created, but under 10% of workforce logins are actually passwordless day to day. The technology that was supposed to have killed the password by now hasn’t, quite. Here’s what’s actually going on, and what to do about it.
What a Passkey Actually Is
Forget the marketing for a second. A password is a shared secret: you type it, it travels over the internet, and a server stores a version of it to check against next time. Every one of those steps is a place it can leak, get phished, or get stolen in a breach.
A passkey works completely differently. When you set one up, your device generates a matching pair of cryptographic keys: a private key that never leaves your device, and a public key that gets stored on the website’s server. Logging in means your device proves it has the private key, usually by asking you to unlock your phone or laptop with Face ID, a fingerprint, or a PIN, without that key ever being sent anywhere. There’s no shared secret to intercept, no password database entry to steal, and nothing to type that a fake login page could capture. That’s the whole reason security teams are so enthusiastic about them: a passkey genuinely can’t be phished the way a password can, because there’s no secret value for you to be tricked into handing over.
The Adoption Numbers Are Real
This isn’t a niche feature anymore. Every major platform has moved fast: Apple made passkeys the default sign-in method for new iCloud accounts starting last year, Microsoft has gone “passwordless by default” for new Microsoft 365 accounts, and GitHub opened passkeys to its entire user base of over 100 million developers in early 2026. Google reports passkey sign-ins now carry a 99.9% lower account compromise rate than password-based logins, and Amazon says 175 million customers created a passkey within the technology’s first year of rollout on the platform.
Some of the usage numbers are genuinely striking. Password manager Dashlane reports passkey authentications doubling year over year, and roughly 40% of its users now store at least one passkey, up sharply from the year before. Broader consumer surveys put passkey ownership at around 69% of people, up from just 39% two years ago. On the enterprise side, roughly 87% of surveyed US and UK companies report using passkeys in some capacity.
So Why Are You Still Typing a Password?
Here’s the honest gap: creating a passkey and actually retiring your password are two different things, and most organizations have only done the first one. A lot of “passkey support” in practice means a website added the option without removing the old password field, so people default to whatever’s familiar. Surveys back this up: even as passkey creation numbers have exploded, password usage across accounts has only dropped from around 76% to 56%, nowhere near the clean handoff the technology promised.
There’s also a real, practical limitation baked into passkeys: recovery. A passkey lives on your device (or syncs across your devices through your Apple, Google, or Microsoft account). If you lose every device tied to that passkey at once, you’re generally back to an email-based account recovery flow, functionally similar to a password reset. That’s not a flaw exactly, it’s an unavoidable trade-off of tying your identity to physical hardware instead of a memorized secret, but it means passkeys haven’t fully eliminated the “what if I lose access” problem, just moved it.
It doesn’t help that “passkey” quietly covers two different setups, and most people never learn which one they’re using. A synced passkey lives in your Apple, Google, or Microsoft account and copies itself across every device signed into that account, convenient, but it means the security of your passkey is partly tied to the security of that account. A device-bound passkey stays locked to a single physical device and never syncs anywhere, more secure in isolation, but useless the moment that specific device is lost or wiped. Microsoft’s own Windows Hello rollout this year leans on device-bound passkeys for personal machines specifically because of that stronger guarantee. Neither option is wrong, but if you’ve ever wondered why a passkey worked seamlessly on your phone and then wasn’t there when you switched laptops, this is usually why.
How to Actually Start Using Them
If you want to move past the “created one, still using passwords” gap, here’s a practical starting point:
- Start with your most important accounts first — your primary email address and your password manager itself, since those two typically control recovery access to everything else you own.
- Check your device settings. On iPhone or Mac, passkeys are built into iCloud Keychain. On Android, they’re built into Google Password Manager. On Windows, Windows Hello now supports passkeys directly, including on personal, unmanaged devices as of a rollout completed in May 2026.
- Use a password manager that also manages passkeys if you use multiple platforms (say, an iPhone and a Windows laptop). Tools like Bitwarden now support passkey storage across browser extensions and mobile apps, which solves a lot of the cross-device friction that’s slowed adoption.
- Set up a backup method before you need it. Most services still let you register more than one passkey, add one from a second device (a tablet, a partner’s phone in an emergency, a hardware security key) so a single lost device doesn’t lock you out.
- Don’t delete your password everywhere yet. Many services still require keeping a password as a fallback recovery method, even after you’ve switched your day-to-day login to a passkey. Check each service’s account settings rather than assuming the transition is complete.
The Bottom Line
Passkeys aren’t hype, the security case for them is genuinely stronger than passwords, and the industry-wide push behind them is real. But 2026 is turning out to be a messier transition year than the “passwords are dead” headlines suggested a couple of years ago. Passkey creation has become mainstream; passkey-only login hasn’t, not yet. The practical move right now isn’t to wait for that transition to finish on its own, it’s to go set one up on your email and your password manager this week, since those are the two accounts where the security upgrade actually matters the most.
Have you fully switched over to passkeys, or are you still holding onto passwords as a safety net? Let us know in the comments.
Sources & Further Reading
- Passkey vs Password: Are Passkeys Safer? (2026 Guide) – Authgear
- 800 Million Passkeys, and We’re Still Typing Passwords: The 2026 Reality Check – HackerNoon
- World Passkey Day: Advancing passwordless authentication – Microsoft Security Blog

