Under FIDO standards, passkeys are phishing-resistant authentication credentials that allow users to sign in to apps and websites with the same process they use to unlock their device, such as biometrics or a PIN. Technologically, passkeys are Discoverable Credentials (known in previous versions of WebAuthn as resident credentials or resident keys). In a Discoverable Credential, all parts of the credential—including the private key, credential ID, user handle, and metadata—are stored entirely in the authenticator. This allows a user to sign in to a relying party without initially providing a user ID.
Synced Passkeys and Device-Bound Passkeys
Passkeys are categorized into two types based on their operational properties:
- Synced Passkeys: A synced passkey is a WebAuthn Discoverable Credential that can reliably be used for account bootstrapping sign-ins without requiring other login challenges such as passwords and OTPs. Passkey providers can achieve this availability by syncing passkeys in real time across a user’s devices, restoring passkeys from a backup when a user sets up a new device, offering passkeys across contexts (such as using an app passkey on the app’s website in a browser), or enabling cross-device use. Passkeys can be managed by first-party passkey providers provided by the OS vendor (such as Windows Hello on Windows, Apple Passwords on macOS and iOS, or Google Password Manager and Samsung Pass on Android devices) or by third-party passkey providers that plug in via platform APIs or browser extensions.
- Device-Bound Passkeys: Previously referred to as single-device passkeys, a device-bound passkey is a WebAuthn Discoverable Credential bound strictly to a single authenticator. For example, hardware FIDO2 security keys typically hold device-bound passkeys because the credential cannot leave the device.
Platform Authenticators and Roaming Authenticators
FIDO authenticators interface with devices as either platform authenticators or roaming authenticators:
- Platform Authenticators: A FIDO authenticator that is built in to a user’s device.
- Roaming Authenticators: A FIDO authenticator usable with any device the user is trying to sign in from. Roaming authenticators attach to users’ devices using USB, NFC, or Bluetooth, and are often referred to as security keys. Additionally, a smartphone can act as a roaming authenticator using FIDO Cross-Device Authentication (CDA).
Account Bootstrapping and Reauthentication
Signing in can refer to two distinct operational events:
- Account Bootstrapping: Occurs when a relying party authenticates a user without any prior knowledge of who the user is. The relying party must establish the user’s identity (such as determining the username or user ID) and verify it (such as checking cryptographic signatures). This occurs when a user signs into an existing account for the first time on a newly purchased device, logs into a website for the first time in a specific browser instance, or signs in during private browsing. Synced passkeys allow bootstrapping sign-in without requiring other login challenges like passwords or OTPs.
- Reauthentication: Occurs when a relying party already knows who the user is but wants to reconfirm control. For example, relying parties may remember identity after an account has been bootstrapped on a device using cookies or local storage. Reauthentication is requested before making sensitive account changes (such as adding a recovery email address or changing authentication methods), after a period of inactivity on a website, or when a mobile app asks the user to sign in on every application start. In non-passkey setups, relying parties typically ask users to re-enter their password or perform another action to reconfirm session control.
Cross-Device Authentication and Credential Exchange
When a passkey is stored on one device and needed on another, FIDO Cross-Device Authentication (CDA) allows a passkey from one device (such as a phone) to sign into a service on another device (such as a laptop). CDA is powered by the FIDO Client-to-Authenticator Protocol (CTAP) using hybrid transport, implemented by authenticators and client platforms rather than relying parties.
To transfer credentials between services, FIDO Credential Exchange specifications define a standardized process to securely transfer passkeys, passwords, and other types of information from one passkey provider to another.
Research Method and Limitations
This answer was prepared strictly from the supplied public source excerpts published by the FIDO Alliance and passkeys.dev. Material limitations include the unavailability of competing coverage, truncation within the secondary excerpt index, and the absence of standardized proprietary cloud recovery or backup specifications within the provided documentation excerpts.

Text version of the diagrams
- Synced vs Device-Bound: Synced — Available across devices; Device-bound — Tied to one authenticator; Key distinction — Portability, not login method
- Two Sign-In Situations: Bootstrapping — Establish and verify identity; Reauthentication — Reconfirm known user control; Context — New context vs remembered identity



