Skip to content

Passkeys explained: how they work and why they beat passwords

A passkey replaces the password with a key bound to the real site, unlocked by your face, fingerprint or PIN. How it works, why it is safer, and its limits.

3 min read

Video generated with EducPilot for Kerno, a fictional B2B SaaS, from two public pages (FIDO Alliance, Google). 16:9, 58 s, two review rounds.

Passkeys replace the password with a cryptographic key stored on your devices. For users, signing in feels like unlocking their phone. Here is how it works, what it protects against, and what to know before rolling passkeys out to customers or staff.

The problem they solve

The same password on several sites is exactly what attackers count on: one breach opens the others. And a password can be typed into a fake site as easily as into the real one.

What a passkey is

A passkey is a key pair created when you register with a service:

  • the private key stays on your devices, often synced by your password manager or platform (Apple, Google, Microsoft);
  • the public key is stored by the service.

To sign in, you approve with the same gesture you use to unlock your device: face, fingerprint, PIN or pattern. Your biometric data never leaves the device: it only unlocks the key.

Signing in, in three steps

  1. Enter your email.
  2. Unlock with your face, your fingerprint or your PIN.
  3. You are in.

Why it is safer

RiskPasswordPasskey
Fake site (phishing)Typed into the fake site like the real oneOnly works on the site it was created for
Breach of the service's databaseStolen passwords can be reusedThe service stores no secret worth stealing
ReuseCommonImpossible: one key per service
ForgettingCommonNothing to remember

The browser or the operating system checks the site, so a look-alike address cannot trick the user.

Limits to know

  • Lost device: a synced passkey comes back on a new device through the account that syncs it. Keep a recovery method.
  • Shared or older devices: offer another way to sign in.
  • Not always multi-factor. France's data protection authority, the CNIL, classes a passkey as a possession factor in its 2025 recommendation on multi-factor authentication; it can count as multi-factor when bound to one device and protected by a PIN.

Training customers in one minute

For a software company, passkeys are more a training question than a technical one: customers need to understand why they are offered something other than a password, and where to switch it on. Hence a one-minute video in the help centre that ends on the exact path ("Settings, then Security").

A few rollout habits that help:

  • Offer, do not force, at first. Propose a passkey after a successful sign-in, and keep the existing method while people get used to it.
  • Say where it lives. "Saved in your phone's password manager" answers the question most users have.
  • Plan recovery before launch. Support will be asked what happens when a phone is lost; have the answer written down.
  • Put the video where the question arises: on the sign-in page, in the security settings, in the onboarding email.

How this video was made with EducPilot

  • Sources: two public pages, FIDO Alliance's passkeys page and Google's developer page, pasted as text. Kerno is a fictional company.
  • The plan: a hook (the same password everywhere), an analogy (a key that only opens your door), the three-step sign-in diagram, three benefits, the closing action.
  • Language: the video is in English, for an international customer base. The same film can be generated in French or Chinese.
  • Review: two rounds. A note applied at 0:41: "Move the database icon away from the server."

The script is broken down line by line in How to write a training video script.

Sources

Full transcript

Still typing the same password on every site? That’s exactly what attackers count on.

Passkeys are a safer and easier alternative to passwords.

Think of a house key: it only opens your own door.

Signing in takes three steps. Enter your email. Unlock with your face, your fingerprint or your PIN. And you’re in.

Your face or fingerprint never leaves your device.

A fake site can steal a password. A passkey only works on the real one.

And our servers never store a password for anyone to steal.

Faster, safer, and nothing to remember.

Set up yours today: Settings, then Security.

Try it with your own documents

Upload a PDF or a procedure, approve the plan, correct the video by annotating it.

Read next