Skip to main content
Back to the wiki
Account Security

What Is a Passkey?

Last updated on August 4, 2026

A passkey is a cryptographic login credential that replaces the password entirely. Built on the FIDO2 and WebAuthn standards, it consists of a key pair: the private key stays on the user's device (or synced through their platform account), and the public key sits with the service. Signing in means the device proves possession of the private key, unlocked locally by fingerprint, face, or PIN, and the crucial property is that the credential is bound to the website's real origin. A passkey created for a genuine domain simply does not respond on a look-alike domain, which retires the entire category of attacks that begin with "type your password into this convincing page."

How passkeys change the attack surface

Passwords fail in bulk: they leak in breaches, get reused across services, and feed the credential stuffing economy that turns one site's breach into every site's problem. Passkeys break each link of that chain. There is no shared secret on the server worth stealing: a breached database of public keys authenticates nobody. There is nothing to reuse, since every service gets its own pair. And there is nothing to phish, because origin binding makes the credential unusable on fraudulent domains, the property that defeats the real-time relay proxies cataloged under MFA bypass, which comfortably defeat one-time codes. Security guidance therefore classes passkeys with hardware keys as phishing-resistant authentication, the tier above app-generated codes in the two-factor authentication ladder.

The honest caveats

Synced passkeys concentrate trust in the platform account that syncs them: an attacker who takes over that account inherits its passkeys, which makes the recovery flow of the ecosystem account the new crown jewel. Account recovery in general remains the soft flank: a service that falls back to email links or SMS codes when the passkey is "lost" has rebuilt the phishable path beside the unphishable one, and attackers ask for the fallback by name. Adoption friction is real too: cross-ecosystem sign-ins, shared devices, and enterprise provisioning still produce edge cases, which is why most deployments run passkeys alongside legacy factors for years, leaving the weakest enabled path as the effective security level.

What passkeys leave for bot defense

Passkeys authenticate identity; they do not establish that traffic is human. Authentication endpoints still absorb automated abuse that never intends to log in legitimately: credential-stuffing runs against the password fallback, enumeration probing, recovery-flow abuse, and scripted registration of throwaway accounts that enroll passkeys like anyone else. Keeping that machine traffic away from the ceremony is the role of human verification such as CaptchaFox in front of login, registration, and recovery flows, so the strong credential's remaining weak edges, fallback and recovery, are at least not exposed to attack at machine scale. The pairing is complementary: passkeys make the authenticated path phishing-resistant, and bot defense keeps the paths around it from becoming the new entrance.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Account Takeover (ATO)?

Account takeover is a form of identity fraud in which an attacker gains control of a legitimate user account and exploits it for financial gain.

Read more
What Is an OTP Bot?

An OTP bot is an automated calling or messaging tool that tricks victims into revealing one-time passcodes, letting attackers bypass two-factor authentication.

Read more
What Is Credential Stuffing?

Credential stuffing is an automated attack that tests stolen username-password pairs from data breaches against login forms to take over accounts.

Read more
What Is MFA Bypass?

MFA bypass covers the techniques attackers use to defeat multi-factor authentication: phishing proxies, push fatigue, OTP interception, and token theft.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices