Passkey
A passwordless sign-in credential built on FIDO2 and WebAuthn: a key pair bound to one site, with the private key kept on the user's device or synced, unlocked locally by biometric or PIN.
A passkey is a sign-in credential that replaces a password with public-key cryptography. Promoted by the FIDO Alliance, passkeys are built on the FIDO2 standards, including W3C Web Authentication. At registration the user’s device creates a key pair for one site; the site keeps only the public key. At sign-in the device signs a challenge with the private key after the user unlocks it with a fingerprint, face or PIN. Because the credential is bound to the site it was created for, the browser and device do not offer it to a lookalike phishing site, which makes passkeys a form of phishing-resistant authentication.
Passkeys are commonly described in two forms. A device-bound passkey stays on one authenticator. A synced passkey is copied through a cloud account to the user’s other devices, which moves part of the trust to that account. NIST SP 800-63B-4 covers syncable authenticators in Appendix B and does not allow them at AAL3, which requires a non-exportable private key. As with other passwordless methods, device loss and account recovery still matter.
Exam relevance: a scenario is likely to ask why a passkey resists phishing when a one-time code does not. Candidates are expected to point to the key’s binding to the genuine site, and to recognise that syncing trades some assurance for recoverability.