In short

You create a passkey on a site that offers one, confirm with Face ID, Touch ID or your Master PIN, and DroidPass files it into your vault. Next time you sign in there is nothing to type and no code to wait for. Passkeys sync to your other devices, encrypted before they leave the phone, and a new device needs your Secret Key as well as your PIN before it can open them. The free plan keeps one passkey; Pro removes the limit.

DroidPass passkeys screen listing Apple, Github, Google, Linkedin and Stripe passkeys, each marked Synced, with a phishing-resistant banner at the top
Your passkeys live in the same vault as your passwords, and sync to your other devices.

Why a passkey cannot be phished

A password is a shared secret. You know it, the site knows it, and anyone who persuades you to type it somewhere else knows it too — which is the entire business model of phishing. A passkey is a key pair instead. The site keeps the public half, your device keeps the private half, and the private half never leaves. A pixel-perfect copy of your bank’s login page gets nothing from you, because there is nothing you could hand over even if you wanted to.

Creating your first passkey

  1. Turn DroidPass on as a provider: open the Settings app, tap General, tap AutoFill & Passwords, and enable DroidPass.
  2. On a site that offers passkeys, choose to create one. It is usually under security or sign-in settings.
  3. Confirm with Face ID, Touch ID or your Master PIN. DroidPass saves the passkey into your vault.

Signing in afterwards is one step: pick your account, confirm, and you are in. No password, no one-time code, no waiting for an SMS that never arrives.

Syncing, and what a new device needs

Your passkeys sync through your DroidPass account like the rest of your vault, encrypted on the device before they are sent. When you set up a new phone it asks for your Secret Key as well as your Master PIN before it will open them.

A single DroidPass passkey for google.com showing it is synced across devices, phishing-resistant, bound to google.com, and unlocks with Face ID or the Master PIN
Every passkey shows what it is bound to and how it unlocks — here, google.com with Face ID or your Master PIN.

That is deliberate, and it is the part worth understanding: it means someone who learns your PIN still cannot unlock your passkeys on their own device. Your Emergency Kit contains the Secret Key — print it before you need it, not after.

Passkeys do not replace every password yet

They only work where a site has implemented them, and most of the web has not. Treat passkeys as something you switch on account by account as it becomes available. DroidPass holds the passwords for everywhere else, along with the 2FA codes for accounts that still use them, so you are not running two apps during the transition.

Bringing passkeys from another app

If you are switching managers, passkeys can come across with your logins — see instant transfer. One caveat worth knowing in advance: a transferred passkey occasionally arrives looking complete and is still refused by the site, because of how the other app exported it. If that happens, delete it and create a fresh passkey on the site. It takes seconds once DroidPass is your provider.

Passkeys FAQ

What is a passkey?

A passkey is a replacement for a password. Instead of a secret you type, your device holds a private key that is unlocked by your face, fingerprint or PIN. The website only ever sees the matching public key, so there is nothing to steal, reuse or leak in a breach.

Can DroidPass store passkeys?

Yes. DroidPass is a passkey provider on iPhone and iPad. Turn it on in the Settings app under General, AutoFill and Passwords, then create passkeys on any site that offers them. They are stored in the same encrypted vault as your passwords.

Do passkeys work on every website?

No. A passkey only works where the site or app has implemented support. Adoption is growing but most of the web still uses passwords, which is why DroidPass keeps both.

What happens if I lose my phone?

Your passkeys sync to your DroidPass account, so a new device can restore them. That device needs your Secret Key in addition to your Master PIN, so keep your Emergency Kit somewhere safe and offline.

How many passkeys does the free plan include?

One. That is enough to try passkeys on your most important account. Pro removes the limit, along with the six-item cap on the rest of your vault.

Is a passkey safer than a password plus 2FA?

For phishing, yes. A passkey cannot be handed to a fake login page, whereas a password and a one-time code both can be. 2FA is still worth having on accounts that have no passkey option, and DroidPass generates those codes too.

DroidPass passkeys screen on the free plan showing one passkey saved and a note that the free plan keeps one passkey
The free plan keeps one passkey — enough to try it on the account that matters most.

Try a passkey on one account

Download DroidPass, turn it on as your provider, and create a passkey on the next site that offers one. The free plan keeps one, which is all you need to see the difference.

Download DroidPass Password Manager on the App Store for iPhone and iPad Get DroidPass Password Manager on Google Play Store for Android devices

Also see: Instant transfer · Autofill · Encrypted password vault · How passkeys work in DroidPass