Passkeys explained: how they work and why they beat passwords
A passkey replaces the password with a key bound to the real site, unlocked by your face, fingerprint or PIN. How it works, why it is safer, and its limits.
3 min read
Passkeys replace the password with a cryptographic key stored on your devices. For users, signing in feels like unlocking their phone. Here is how it works, what it protects against, and what to know before rolling passkeys out to customers or staff.
The problem they solve
The same password on several sites is exactly what attackers count on: one breach opens the others. And a password can be typed into a fake site as easily as into the real one.
What a passkey is
A passkey is a key pair created when you register with a service:
- the private key stays on your devices, often synced by your password manager or platform (Apple, Google, Microsoft);
- the public key is stored by the service.
To sign in, you approve with the same gesture you use to unlock your device: face, fingerprint, PIN or pattern. Your biometric data never leaves the device: it only unlocks the key.
Signing in, in three steps
- Enter your email.
- Unlock with your face, your fingerprint or your PIN.
- You are in.
Why it is safer
| Risk | Password | Passkey |
|---|---|---|
| Fake site (phishing) | Typed into the fake site like the real one | Only works on the site it was created for |
| Breach of the service's database | Stolen passwords can be reused | The service stores no secret worth stealing |
| Reuse | Common | Impossible: one key per service |
| Forgetting | Common | Nothing to remember |
The browser or the operating system checks the site, so a look-alike address cannot trick the user.
Limits to know
- Lost device: a synced passkey comes back on a new device through the account that syncs it. Keep a recovery method.
- Shared or older devices: offer another way to sign in.
- Not always multi-factor. France's data protection authority, the CNIL, classes a passkey as a possession factor in its 2025 recommendation on multi-factor authentication; it can count as multi-factor when bound to one device and protected by a PIN.
Training customers in one minute
For a software company, passkeys are more a training question than a technical one: customers need to understand why they are offered something other than a password, and where to switch it on. Hence a one-minute video in the help centre that ends on the exact path ("Settings, then Security").
A few rollout habits that help:
- Offer, do not force, at first. Propose a passkey after a successful sign-in, and keep the existing method while people get used to it.
- Say where it lives. "Saved in your phone's password manager" answers the question most users have.
- Plan recovery before launch. Support will be asked what happens when a phone is lost; have the answer written down.
- Put the video where the question arises: on the sign-in page, in the security settings, in the onboarding email.
How this video was made with EducPilot
- Sources: two public pages, FIDO Alliance's passkeys page and Google's developer page, pasted as text. Kerno is a fictional company.
- The plan: a hook (the same password everywhere), an analogy (a key that only opens your door), the three-step sign-in diagram, three benefits, the closing action.
- Language: the video is in English, for an international customer base. The same film can be generated in French or Chinese.
- Review: two rounds. A note applied at 0:41: "Move the database icon away from the server."
The script is broken down line by line in How to write a training video script.
Sources
- FIDO Alliance, Passkeys.
- Google for Developers, Passkeys.
- CNIL, Recommandation relative à l’authentification multifacteur, March 2025 (PDF, in French).
Full transcript
Still typing the same password on every site? That’s exactly what attackers count on.
Passkeys are a safer and easier alternative to passwords.
Think of a house key: it only opens your own door.
Signing in takes three steps. Enter your email. Unlock with your face, your fingerprint or your PIN. And you’re in.
Your face or fingerprint never leaves your device.
A fake site can steal a password. A passkey only works on the real one.
And our servers never store a password for anyone to steal.
Faster, safer, and nothing to remember.
Set up yours today: Settings, then Security.
Try it with your own documents
Upload a PDF or a procedure, approve the plan, correct the video by annotating it.
Read next
- How to turn a PDF into a training video with AI: method, examples and limits
From a 40-page procedure to a 2-minute video people actually watch: a six-step method, what AI does well and badly, and real examples generated from official documents.
- Whiteboard explainer videos for corporate training: when they work, how to make one
Whiteboard video helps people follow reasoning, not copy a physical task. When to use it, when to film instead, what research says, and how to make one.
- How to write a training video script: a situation, one idea per sentence, sources
How to script a one to three minute training video: open on a situation, one idea per sentence, write for the ear, source every fact. With a real annotated script.