Pick a device you control
A passkey uses a cryptographic credential instead of asking you to type a reusable password into a website. Your device unlock action approves its use. That is useful against fake sign-in pages, but it makes control of the device important. Do not create a personal passkey on a shared reception computer, a borrowed laptop or an unlocked family tablet.
This exercise changes one account on one device. It does not require buying a security key. Check the provider's current device requirements before starting; a managed work account can have different rules from a personal account.
Add one credential deliberately
- Open your account's security settings from a saved bookmark or the provider's genuine app. Confirm the account address, especially if several accounts are signed in.
- Review your existing recovery phone, recovery email and alternative sign-in methods. Keep a working fallback available while you test the new method.
- Open the passkey settings and create a passkey on your personally controlled device. Read the storage prompt: the credential may be stored locally or synchronised by a platform account.
- Name the device clearly if the provider offers labels. Lock your screen, unlock it, then try the account's normal sign-in process in a separate browser session.
Verify what actually happened
Confirm that the sign-in completed on the genuine provider domain and that the account lists the new credential. A successful biometric prompt in an unrelated application is not evidence that your account sign-in worked. Note the date and device name without recording secret recovery material in a public document.
Also confirm that the fallback method remains available. Testing a fallback means completing a normal authorised sign-in, not intentionally exhausting recovery attempts or deleting the only working credential.
Understand the recovery boundary
A synced passkey depends partly on the security of its platform account. A device-bound credential can disappear when the device is lost or reset. Those are different recovery situations. Protect your device unlock code and your sync account, and learn how the provider removes a lost device's credentials.
Avoid a rushed migration
Do not immediately delete every password, authenticator or recovery method after the first successful test. Establish access from another trusted device first. If a screen differs, consult the current provider instructions rather than guessing which removal button is safe.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.