# Passkeys — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/mfa-passkeys

> Explain how passkeys replace passwords and why they resist phishing.

## A key pair, not a shared secret

A **passkey** is a public/private key pair. The site stores the public key; your device keeps the private key and unlocks it with a fingerprint, face or PIN. Nothing reusable is typed, and the credential only works for the real site, which defeats phishing pages.

## A lock and a key you never hand over

With a password you give the guard a secret word each time. With a passkey you prove you hold the key without ever showing it to the guard.

## Sync and back up

Store passkeys in a manager that syncs them, such as 1Password, so a lost phone does not lose your accounts. Keep an alternative sign-in method until you trust the setup.

**Quiz:** What is stored on the website when you use a passkey?

- [ ] Your private key
- [x] Your public key
- [ ] Your master password
- [ ] A copy of your fingerprint

*Answer:* Your public key. Only the public key is stored. The private key stays on your device or in your manager.
