Passkey login: how signing in with a passkey works
SHORT ANSWER
How does passkey login work?
The site sends a random challenge. Your device asks you to unlock with a fingerprint, face or screen lock, then signs the challenge with the private key and sends the signature back. The site checks it with your public key. No password is typed or sent.
Key takeaways
- Signing in proves you hold the private key; the key itself never leaves your device.
- The signature only works for the real site, so lookalike pages get nothing.
- Your biometric unlocks the key on the device. It is not sent to the site.
- If no passkey appears, you usually have no passkey for that site on this device, or the site is not offering it.
Disclosure: HostSpica makes HostSpica Identity, an Android app that is also a passkey provider. Facts about other services come from their own help pages, checked on 4 October 2026, and can change.
The steps
- You choose to sign in with a passkey, or the site offers it when you tap the username field.
- The site sends a fresh random challenge and its own identity.
- Your device shows the passkeys it holds for that site and asks you to unlock.
- The provider signs the challenge with the private key for that site.
- The site verifies the signature with the public key it stored when you created the passkey.
The full detail, with the cryptography, is in passkeys from first principles. The browser-side standard is Web Authentication.
Why phishing fails
The browser includes the real site's origin in what is signed. A lookalike site has a different origin, so a signature made for it is useless on the real one. There is also no secret for you to type into the wrong page.
Sign in on a computer with your phone
If the passkey is on your phone, the computer shows a QR code. You scan it with the phone, approve, and the phone proves possession over a nearby Bluetooth check handled by Android. The passkey itself does not move. See passkey scanner: how the QR code sign-in works.
When it does not work
| Symptom | Likely cause | Try |
|---|---|---|
| No passkey offered | None created on this device or provider | Sign in another way, then add one |
| Wrong provider shown | A different provider is the default | Change provider in system settings |
| Prompt cancels at once | Provider disabled or screen lock missing | Enable the provider and set a screen lock |
| QR code does nothing | Bluetooth off or no network | Turn Bluetooth on and retry |
With HostSpica Identity, passkeys are stored on this phone only. HostSpica Identity needs Android 14 or newer for passkeys. Its Google Play release is in the final steps as of 4 October 2026, so check the app page for the live link.
Frequently asked questions
Is passkey login safer than a password?
It resists phishing and reuse, and nothing secret is sent. It still depends on the security of the device that holds the key.
Does the site see my fingerprint?
No. The biometric only unlocks the key on your device.
Do passkeys work without internet?
The sign-in needs the site to be reachable. The passkey itself is on your device.
Can I sign in with a passkey on someone else's computer?
Yes, by scanning the QR code with your phone. Nothing is stored on that computer.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED