Passkeys from first principles: what happens when you sign in without a password
SHORT ANSWER
How does a passkey let you sign in without a password?
A passkey is a key pair. The site stores the public key; the private key stays on your device. To sign in, the site sends a random challenge, your device signs it after a fingerprint or face check, and the site verifies the signature with the public key. No secret is ever sent, and a fake site cannot get a valid signature.
Key takeaways
- Passkeys replace a shared secret (the password) with a key pair, so there is nothing for a site to leak that lets someone sign in as you.
- The signature covers the real website's address, which is why passkeys resist phishing: a lookalike site gets a different address and no matching passkey.
- A passkey can be synced between your devices by a cloud account, or tied to one device. HostSpica's passkeys are tied to the phone.
- A device-bound passkey is not backed up. Keep another way to sign in to each site.
The problem with passwords
A password is a secret that you and the site both know. That makes it leakable from two places: the site's database, and your own typing, which a fake page can capture. Every other fix, such as managers, complexity rules and one-time codes, works around that basic fact. Passkeys remove it.
Registration: making the key pair
- You choose to create a passkey on a site. The site sends your browser a random challenge, its own identity (the relying party ID, usually its domain such as
github.com) and your account details. - Your authenticator, such as HostSpica Passkey, creates a new key pair just for that site. The private key stays on the device. The public key goes to the site.
- It also returns a credential ID so the site can later say which key it wants, and proof about where the key was made (see attestation, below).
- The site stores the public key and credential ID against your account. Nothing in that is secret.
Sign-in: proving you hold the key
- The site sends a fresh random challenge.
- Your device asks for a fingerprint or face check, which unlocks the private key for that one signature.
- The device signs the challenge together with some context: the hash of the site's ID and the exact web origin the browser is on.
- The site checks the signature with the stored public key, checks the challenge is the one it just sent, and checks the origin and site ID are its own. If all match, you are in.
Because every challenge is new, a captured sign-in cannot be replayed. Because the private key never leaves the device, a site breach leaks only public keys, which are useless to an attacker.
Why a fake site cannot use your passkey
The signed data includes the real address the browser is showing. A lookalike such as g1thub.com has a different site ID, so the browser does not offer your passkey for it, and if an attacker relayed a signature it would carry the wrong origin and the real site would reject it. With passwords and one-time codes you decide whether a page is genuine. With a passkey, the software checks.
Synced or device-bound
| Synced passkey | Device-bound passkey | |
|---|---|---|
| Where the key lives | Copied through a cloud account to your other devices | Only in one device's secure hardware |
| Lose the device | Recover through the cloud account | The passkey is gone |
| Exposure | Depends on the cloud account's security | Cannot be copied off the device |
| Example | Google Password Manager, iCloud Keychain | HostSpica Passkey |
HostSpica Passkey is device-bound on purpose: the private keys are generated in Android Keystore and cannot be exported, so there is no cloud copy to attack. The price is that losing the phone loses those passkeys.
Attestation in one paragraph
At registration an authenticator can also prove what kind of key it made. HostSpica Passkey includes Android's key attestation, a certificate chain showing the key was generated inside the phone's secure hardware. Most consumer sites ignore it. It matters to organisations that want to allow only certain devices.
What passkeys do not solve
Try it
The WebAuthn demo site webauthn.io lets you register and sign in with any passkey provider. On an Android 14 or newer phone with HostSpica Identity, turn on the provider in Settings, then choose it when the browser asks where to save the passkey. See how an Android passkey provider works for what happens inside.
Frequently asked questions
Is a passkey the same as a security key?
They use the same standard, WebAuthn. A security key is a separate piece of hardware; a passkey on your phone is the same idea built into the phone.
What happens if I lose my phone?
A device-bound passkey is gone with it. Sign in to each site another way, remove the lost passkey from the site's security settings, and register a new one.
Can a site see my fingerprint?
No. The fingerprint check happens on the device, and only unlocks the key. The site receives a signature and a flag saying the user was verified.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED