What is a passkey and how is it different from a password?
A passkey replaces the password with a cryptographic key pair. The private key stays on your device, protected by your fingerprint, face or device passcode. The site stores only the public half, which is useless to anyone who steals it.
That difference eliminates several problems at once. There is no shared secret to be leaked in a breach, because the site never holds anything that can authenticate you. There is nothing to reuse across sites, since each one gets its own key pair. And crucially, a passkey is bound to the specific domain it was created for, so it simply will not work on a lookalike site. That is what makes it genuinely phishing-resistant rather than merely stronger.
Using one feels like unlocking your device rather than typing anything, which is why adoption has been faster than most security improvements.
The practical questions people have are mostly about portability and recovery. Passkeys sync through your platform account or password manager, so a new phone inherits them rather than locking you out. Signing in on a device that does not have them typically works by scanning a code with your phone, which uses proximity to confirm the devices are together.
The honest caveats are that support is still incomplete, so most people will run both approaches for a while, and that recovery now depends on your platform account or manager, making that account the critical thing to protect.
Where a site offers passkeys, they are meaningfully safer than any password plus code combination, because they remove the class of attack that most commonly succeeds against ordinary users.