Your phone has gone missing, your computer is back at the office and your primary account requires verification on the lost device. That is the real test of passkeys, the access credentials designed to replace our passwords. When everything works, a face or a fingerprint is enough. When life strays from the expected script, that simplicity becomes more fragile. Looking ahead to September 2026, the decisive question is therefore not just adoption: it is whether people can recover, share and move their access credentials without recreating the vulnerabilities of the past.
This analysis draws on deployments and mechanisms documented through June 2024. The developments envisaged for September 2026 are forward-looking assessments, not a review of subsequent features or announcements.
A genuine advance against phishing
A passkey relies on a pair of cryptographic keys. The service stores the public key; the private key remains under the control of your device or credential manager. During sign-in, the device or manager proves that it holds the private key without transmitting it to the website. Unlocking locally, using biometrics or a code, authorizes this operation. Your fingerprint is therefore not sent to the retailer or social network.
The main benefit lies in the binding between the credential and the legitimate service. A fake website resembling your bank cannot simply get you to enter a passkey and then reuse it elsewhere. Under WebAuthn and the FIDO standards, authentication checks the context of the requesting website. This is a fundamental difference from a password, or even a temporary code that a victim might copy onto a fraudulent page.
Apple, Google and Microsoft had begun this transition before June 2024, while services such as Google, PayPal and GitHub were already offering passkeys. But resisting phishing does not mean making an account invulnerable. Malware can target an active session; a fraudster can persuade someone who is signed in to make a bank transfer. A passkey protects one essential step, not all digital activity.
Account recovery: shifting the problem
With a forgotten password, the familiar response is to click a link received by email. With a lost passkey, everything depends on how it is stored. Some keys are bound to a device or a physical security key. Others are synced, in encrypted form, across devices using the same manager. This second approach makes replacing a phone easier, provided you can regain access to the account that handles synchronization.
The center of gravity then shifts. An Apple or Google account, or an account with a password manager, becomes a point of dependency for many other accounts. This is not automatically less secure: these services have sophisticated protection mechanisms. But users must understand a recovery chain they may not have realized they were building.
The emergency exit can become the main entrance
If a service allows a passkey to be bypassed with a simple text message, an attacker may try to hijack the phone number. If support staff can reset access after a few personal questions, social engineering finds itself on familiar ground. Actual security therefore also depends on the weakest recovery path, not just the most modern sign-in button.
Conversely, an excessively rigid recovery process can lock out the legitimate owner. A stolen bag, a broken phone, a change of number: these everyday incidents should not become digital life sentences. A sound compromise combines several independent methods: another device, a second registered key where the service allows it, and backup codes stored offline. But these options need to be presented before something goes wrong.
Sharing access without handing over your entire life
In demonstrations, one person owns one device and accesses their account. In real life, a couple checks bills, several employees manage a store and a relative helps an elderly parent. Sharing a password is poor practice, but it often serves a purpose that the service has never properly accommodated.
Passkeys expose this gap. Some managers already allow credentials to be shared, including passkeys in compatible configurations. Yet this does not replace proper permissions management. Granting access to the same account can also grant the power to change its recovery address, view all its data or lock out other users.
The right answer is often delegation, rather than sharing a secret. Each person should have their own access, with appropriate, revocable permissions. For a business, this also makes it possible to identify who performed an action. For a family, it avoids sharing the central account that also holds photos, backups and payment methods. Passkeys do not create this need; they force us to take it seriously.
Switching ecosystems: the test of freedom
Moving from one phone to another seems simple as long as your credentials follow. Leaving an ecosystem raises a different question: how do you take your passkeys with you? Compatibility of the sign-in protocol does not guarantee compatibility of the vault that stores them. A service can support WebAuthn across several platforms without its users having a direct transfer option between all managers.
A cross-device sign-in, for example by scanning a QR code and then approving the request on your phone, can help when using a different computer. But using a key remotely is not the same as transferring it. To leave a provider permanently, you need either a secure way to export your keys or the ability to register new keys with the relevant services while your old access still works.
Looking ahead to September 2026, portability is therefore a criterion to monitor rather than a benefit to take for granted. Secure, interoperable transfers would reduce dependence on platforms. The challenge is real: making it easier to move private keys out without creating an exfiltration tool. The quality of a solution will also be judged by its controls, its warnings and its ability to support a complete departure.
What to check before making the switch
For users, the right response is not to reject passkeys, but to examine how they work when things go wrong. Three questions are worth more than a promise of “effortless” sign-in:
- Where is my key stored, and will it be available if my primary device goes missing?
- What independent methods can I use to recover my account, and are those methods themselves protected?
- Can I add another way to access the account, delegate permissions and switch managers without starting from scratch?
What next? The next stage may hinge less on facial recognition than on invisible procedures: understandable recovery, precise delegation and verifiable migration. Passkeys offer tangible protection against a broad category of attacks. Their lasting success will depend on a more down-to-earth requirement: allowing people to lose a phone, switch providers or help a relative without losing control of their digital identity.


