
If the day you lose your phone is the first time you think about account recovery, you may discover that every backup path depended on that same phone. Passkeys can make everyday sign-in easier and more resistant to phishing, but a passkey is only one part of a sound account plan. You also need a tested way back in after a device is lost, replaced, damaged, or locked.
This guide walks U.S. consumers through setting up passkeys and organizing recovery email addresses, phone numbers, backup codes, authentication apps, and hardware security keys. Menus vary by company and change over time, so the focus is on a repeatable decision process. If you already see unfamiliar sign-ins or recovery changes, skip to the incident-response section before adding anything new.
Passkeys in plain English
A passkey uses a pair of cryptographic keys. A website keeps the public key, while the private key stays under the control of your device, security key, or credential manager. When the site sends a challenge, your device signs it after you approve the action with a screen-lock method such as a face scan, fingerprint, device PIN, or password. In a normal passkey flow, the biometric itself is used locally to unlock the credential; it is not sent to the website as your login secret.
One major advantage is that the credential is bound to the real website domain. A convincing fake page cannot simply collect a reusable password and replay it at the real site. That makes properly implemented passkeys a phishing-resistant option. The important caveat is recovery: if an attacker can reset the account through a weaker email address, an outdated phone number, or a poorly protected help-desk process, the strongest front door does not protect the side door.
Synced and device-bound passkeys
- Synced passkeys can be available on multiple devices signed in to the same credential-manager account. They simplify device replacement, but the security and recovery of that manager account become critical.
- Device-bound passkeys remain on a particular phone, computer, or hardware security key. They can provide useful separation for high-value accounts, but they require a separate backup path.
- Cross-device sign-in may let a nearby phone approve a login on another computer. Read the domain and connection prompt yourself, and do not approve a request initiated by someone else.
Protect accounts in the right order
Do not try to convert every account in one sitting. Start with the primary email account that receives password-reset links for other services. Next review your mobile carrier account, credential manager, financial accounts, cloud storage, and social media. If a phone number is part of recovery, pair this work with the SIM-swap protection checklist.
Create a simple inventory with four fields: service, current sign-in methods, backup methods, and last-tested date. Do not put actual passwords or backup codes in an unprotected spreadsheet. A note such as “printed codes in locked document box” is enough to help you find the material without turning the inventory into a master key.
What to prepare before changing settings
- A secure screen lock: Give each phone and computer a hard-to-guess PIN or password, and install current operating-system security updates.
- A second trusted device: If possible, have a tablet or computer that is already signed in to your credential-manager account.
- Current recovery contacts: Confirm that you can open the backup email and that the recovery phone number still belongs to you.
- A protected storage location: Choose a locked document box or trusted encrypted vault for recovery material.
- An independent authenticator: For a high-value account, consider registering two hardware security keys and storing the spare separately.
Be careful about adding another person’s fingerprint or face to a device for convenience. Anyone who can unlock that device may also be able to approve use of the passkeys stored on it. For a genuinely shared service, use family sharing, delegated access, or separate user profiles when the provider offers them.
An eight-step setup process for one account
- Open the service directly. Use a saved bookmark, type the address yourself, or open the official app. Do not begin from a security-settings link in an unexpected email or text.
- Review active sessions. Before adding a passkey, sign out unfamiliar devices, locations, or browser sessions. Change the password if anything is unexplained.
- Verify recovery contacts. Remove an old work email, canceled phone number, or former household member’s contact information.
- Create the first passkey. Confirm that the service name and domain are correct, then approve creation using your device lock.
- Test from a signed-out state. An existing session can make a setup look successful. Use a private browser window or another browser to perform a real passkey sign-in.
- Add an independent second route. Register another trusted device, a separate hardware key, or an authenticator app if the service supports it.
- Generate fresh backup codes. Some services display them only once. Store them immediately in protected offline or encrypted storage, not in your camera roll or ordinary email drafts.
- Understand the remaining password. Check whether the service removed the password, still permits it alongside passkeys, or keeps it for recovery. If it remains valid, keep it long and unique.
Design recovery around different failure modes
Two backups are not independent if both live only on the same phone. A good recovery plan spreads risk across different places and systems. One practical combination is a synced passkey on your everyday phone, a hardware security key stored at home, and printed one-time backup codes in a locked document box. Losing one item does not automatically remove the other two.
A recovery email is also weakly independent if it can only be opened from the same device. Sign in to that secondary account periodically so it does not become dormant, secure it with strong authentication, and give it its own recovery path. If you must retain SMS recovery, protect the carrier account with an account PIN and any available number-transfer or port-out lock.
Example: a phone is lost during travel
Suppose Maya uses a synced passkey for her primary email but keeps a picture of her backup codes on the same phone. After the phone disappears, opening the cloud photo library may require approval through that primary email, creating a circular dependency. A better plan would leave one registered security key at home and store printed recovery instructions in a sealed envelope. A trusted family member might know where the envelope is without knowing the account password.
Frequent travelers should also avoid keeping every spare in one carry-on bag. The phone and bag can be stolen together. Keep one method on your person and another at home or, where appropriate, in a separate secure location. The purpose is not maximum complexity; it is preventing one ordinary mishap from becoming total lockout.

Device replacement checklist
Before erasing the old phone
- Confirm that credential-manager synchronization has completed on the new phone.
- Perform a real sign-in to your primary email and credential manager from the new device.
- If you use an authenticator app, follow its account-transfer process or re-enroll each service.
- Verify that backup codes are current and physically retrievable.
- Decide when the old device should be removed from each account’s trusted-device list.
After the new phone passes the test
- Enable a strong screen lock and the platform’s find-device and remote-erase features.
- Test passkey sign-in to email, financial, and carrier accounts in that order.
- Erase the old phone, then remove it from online device lists as well.
- If the phone number changed, update recovery records directly at every important service.
- Record the test date and verify that the spare security key still works.
If you are organizing account records alongside household emergency papers, the emergency financial records kit explains how to separate encrypted and offline copies. Keep the actual one-time codes under tighter access control than an ordinary household inventory.
Change the order when compromise is suspected
An alert for a passkey you did not create, a surprise change to recovery email, an unknown login, or repeated approval prompts can indicate an attack. Rejecting a prompt is useful, but it is not a complete response. From a device you reasonably believe is clean, open the official app or type the official address and work through this order:
- Change the primary email password to a new, unique value.
- Review all active sessions and remembered devices, then terminate anything unfamiliar.
- Inspect registered passkeys, hardware keys, authenticator apps, recovery emails, and phone numbers. Remove entries you do not recognize.
- Check email forwarding rules, filters, delegated accounts, and automatic replies for changes an attacker may have created.
- If financial or identity information may be exposed, contact the institution through a number in its official app, statement, or the back of the card, and use IdentityTheft.gov to build a recovery plan.
- If you do not know how the attacker got in, find every other account that reused the old password and replace it.
Do not trust a customer-support number shown in a search ad or unsolicited message. Never give an authentication code to a caller, and do not approve a login or screen-sharing request that you did not initiate. A legitimate employee should not need you to weaken authentication so they can “secure” the account.
Seven common mistakes
- Forgetting the old password as soon as a passkey is added: If password sign-in remains available, that password still needs protection.
- Keeping every recovery method on one phone: One loss, failure, or device lock can remove all access.
- Saving backup codes as screenshots: A compromise of the photo-sync account can expose the codes.
- Leaving an outdated number on the account: A reassigned number may eventually be controlled by someone else.
- Skipping the signed-out test: Setup is not complete until you prove the method works without an existing session.
- Putting two security keys on the same key ring: Both can disappear in the same incident.
- Approving a request for a supposed support agent: Do not approve any sign-in or recovery request you did not start.
A 15-minute quarterly review
- Can you sign in normally to the primary email and credential manager?
- Are all registered devices, passkeys, and security keys recognizable?
- Are the recovery email address and phone number current?
- Can you physically locate the spare key or backup codes?
- Have you removed old sessions and app connections you no longer use?
- Does a trusted person know where emergency instructions are without knowing your everyday password?
Frequently asked questions
Do passkeys eliminate the need for a password manager?
Not necessarily. Passkey support varies, and some services continue to allow passwords. A credential manager can still hold unique passwords for unsupported sites and may also be the system that securely synchronizes your passkeys across devices.
Does the website receive my face or fingerprint?
In a typical passkey transaction, biometrics unlock the credential locally and the site verifies a cryptographic response using the public key it registered. Review your device and service privacy notices for any additional data they collect outside that authentication process.
Should I remove SMS verification immediately?
For important accounts, prefer a phishing-resistant option such as a passkey or hardware security key when available. But if SMS is the only extra factor offered, it can still add protection beyond a password alone. Test stronger replacement and recovery routes before deleting an existing method.
How many hardware keys do I need?
That depends on your risk and budget. One key can become a single point of failure, so the important principle is having an independent spare for high-value accounts. The spare does not always need to be another hardware key; a securely stored recovery code or separately protected device may serve, depending on the provider.
Can a family share one passkey?
For personal accounts, provider-supported family sharing, delegated access, or separate profiles usually makes responsibility clearer than sharing one authenticator. For emergency access, consider sealed instructions, legal authorization where relevant, and the provider’s legacy or inactive-account features instead of routinely sharing the password.
The practical finish line: test recovery, not just sign-in
A “passkey added” confirmation is not the finish line. The goal is to prove that you can safely regain access even after one device disappears. Start with your primary email, create and test the first passkey from a signed-out state, and then add one backup that fails differently from the primary method. Those three actions deliver most of the practical benefit without turning account security into a full-time project.
This article provides general digital-safety information, not individualized legal, financial, or cybersecurity advice. Account menus, supported authenticators, and recovery policies differ by provider; verify the current instructions on each provider’s official site.