Sitemap

Passkeys are just passwords that require a password manager

You reset your passkey the same way you reset your password. But you’ll find that passkeys make it harder to switch between password managers, because you can’t copy and paste a passkey.

6 min readAug 4, 2025

--

Last updated: June 2026

Passkeys are randomly generated passwords that are required to be managed by a password manager. All the major password managers support them, including Apple, Google, Microsoft, Mozilla, and 1Password.

You reset your passkey the same way you reset your password. Some sites make it easy to reset your password, some make it hard. You know the drill; there’s nothing new or different there.

Password managers provide no way for you to copy and paste your passkeys. To present a passkey, you have to use a password manager. This makes it impossible to copy and paste your passkey to the wrong person (someone trying to trick you).

Major password managers don’t even allow you to export your passkeys to a file that you can read/backup yourself. Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.)

You’ll always need a password (or a device) to login to your password manager (or your passkey manager). You can’t use your passkeys without your password manager. To login to your password manager, you need something outside the password manager, most likely a password.

A passkey manager is morally required to do an extra factor of authentication (e.g. fingerprint, Face ID, hardware keys, etc.) when you login, but the site/app has no way of knowing/proving whether that happened.

You reset your passkey the same way you reset your password

Some sites make it easy to reset your password, some make it hard. You know the drill; there’s nothing new or different there.

If your site/app is comfortable with a simple “forgot my password” email to reset their password, then you can also send users a “lost my passkey” email to reset their passkey.

Email providers and banks don’t use simple “forgot my password” emails. The “forgot my password” flow for Google/Gmail can involve a bunch of factors, including backup email addresses, backup recovery codes, recovery contacts, SMS, and push notifications to other apps you’ve logged into. (Google doesn’t document all of the factors they consider, and neither do any of the other major email providers.) Banks with branch offices can ask you to present photo ID, your bank card, your written signature, and your fingerprint on ink.

Whether you make it easy or hard to reset your password/passkey, resetting your passkey works exactly the same as resetting your password.

And if your site/app doesn’t have a “forgot my password” process, you don’t need one for passkeys, either. (But, surely you have something in place…? Even Yubikeys/SSH/PGP private keys can be lost.)

You’ll always need a password (or a device) to login to your password manager (or your passkey manager)

You can only present a passkey with a password manager. To login to a password manager, you need something outside the password manager, most likely a password. (The password-manager company 1Password calls itself that because you do need to memorize/retain one last password, the one you use to login to your password manager.)

Apple and Google both offer password managers, and they both encourage you to login to Apple/Google with a passkey.

That scares a lot of people. “If I login to Google with a passkey managed by Google, how will I login to Google if I lose my passkey/device?”

The answer is: you’ll use your password, at least as a last resort. (Or: you’ll set up backup codes, which are just backup passwords.)

You can login to a password manager with a passkey, if you’re logged into your password manager on another device. Password managers that accept login with passkeys let you scan a QR code with a logged-in device to login to a new device.

But a passkey can’t be your only way to login to a password manager. Password managers will always need to accept a password (or a backup code) as a method of last resort, because you have to use a password manager to present a passkey, and you need something outside the password manager to login.

(Truth be told, you don’t need a password to login to a password manager. The other way is to put your password/passkey on a “hardware security module” [HSM], a USB key like a YubiKey. The answer to “what if I lose my YubiKey?” is “keep backup keys,” just like passwords. “What if I lose my last copy?” Then you’ll just have to reset your password. “What if I lose my last copy and all of my backup authentication factors?” In that case, resetting your password might be impossible, and you’ll lose access to your account.)

Passkeys make it harder to switch password managers, because you can’t copy and paste them

The major password managers are designed not to let you copy and paste a passkey, including from Google’s password manager to Apple’s password manager.

You can import/export your passkeys from one password manager to another, but it’s complicated. Apple and Google have agreed to use a “Credential Exchange Protocol” to support transferring passkeys from one password manager to another. It transfers data directly from one app to another, without allowing you to generate a file that you can read/backup yourself.

Support for this is very new. As of June 2026, it works OK on iOS 26, but it doesn’t work on Android, Windows, macOS, or on Linux.

  • Transfer passkeys from Google: On iOS, open Chrome’s Password Manager and go to Password Manager → Settings → Export Data. It will ask you what app will receive your passwords/passkeys; Apple Passwords is on the list. (This only works on iOS of June 2026. On Android, Windows, macOS, and Linux, Chrome offers an option to “Export Passwords” but no option to export passkeys.)
  • Transfer passkeys from Apple: Open Apple’s Passwords app. On iOS, in the “…” menu, there’s an option to “Export Data to Another App.” Apple will ask you what app will receive your passwords/passkeys (e.g. the Google app, the Chrome app, Edge app, or 1Password). On macOS, you could use the File → Export menu in the Apple Passwords app, but as of June 2026, Google and Microsoft don’t support importing from Apple Passwords on macOS.
  • Microsoft Password Manager doesn’t support exporting passkeys as of June 2026. There’s no way at all to export a passkey from Microsoft Password Manager into any other password manager. You can import into Microsoft Password Manager on iOS, but you can’t export.

This process is just complicated enough that regular people will probably never do it. (I think all the password managers kinda like that lock in.)

Password managers recommend that sites/apps allow each user to have multiple passkeys. Sites/apps may or may not actually allow that, but that’s one way to be sure a given user can login with both Google’s password manager and Apple’s password manager: give each password manager its own passkey for each site.

Passkeys’ restriction on copying and pasting is what provides the anti-phishing protection

Ask yourself: Are you sure you’re never going to copy and paste your password into the wrong hands? Even very “sophisticated” password users have been known to fall prey to social-engineered phishing attacks. Every time you copy and paste a password, you run the risk of sending it to an attacker.

You have to decide for yourself whether protecting yourself from phishing is worth losing your ability to copy and paste. Copy and paste makes it possible to see and understand your passwords, and makes it obvious how to backup and transfer your passwords to other password managers, to paper archives, and to other people. But that’s exactly what makes it possible for you to transfer your passwords to the wrong person.

If you’re using a password manager, and you’re sure you’ll never mistakenly copy and paste your password to the wrong person, there’s no real need for passkeys. But I don’t trust myself that much.

Some password managers do let you export your passkeys to a file

Apple, Google, Microsoft, Mozilla, and 1Password don’t let you export passkeys to a file that you can read and backup, but Bitwarden, Proton Pass, and KeepassXC do.

Allowing passkeys to be exported to a plaintext file undermines the phishing protections, at least somewhat. It’s possible to trick you into exporting your passkeys from Bitwarden and sending the file to an attacker.

The major password managers say that this is the reason they don’t allow exporting passkeys, and it’s not false, but they’re also making it harder to switch password managers, which may be their ulterior motive. (You can’t even import those exported passkey files into any of the major password managers, which they would be incentivized to do, if those smaller players had significant marketshare.)

It’s up to you to decide whether protecting yourself from being tricked into exporting your passkeys is worth sacrificing your ability to read them.

--

--

Dan Fabulich
Dan Fabulich

Written by Dan Fabulich

Dan Fabulich is co-founder of Choice of Games.