Understand sign-ins

Passkey Compass

Find out whether a passkey makes sense for your next sign-in — without jargon or test data.

Your situation

Recommendation

Check the account settings first

Look for Passkey, security key, or sign-in method in the service. Until then, a unique long password with multi-factor authentication remains the right foundation.

  1. Look for a passkey option in the security settings.
  2. Keep existing recovery codes in a safe place.
  3. Use a unique password from the generator or password manager for this service.

Three essential basics

The private key stays protected

Your device, password manager, or security key holds the private part. A service receives only data it can use to verify a sign-in.

A passkey belongs to a domain

A passkey created for pwgen.de cannot test another website. Every application needs its own relying-party domain.

Account recovery still matters

Plan for device changes, lost security keys, and account recovery. Keep each service's recovery options safe.

What happens technically

Passkeys are built on WebAuthn: the service issues a challenge, your device signs it with the private key, and only the signature and the public key travel back. pwgen.de deliberately offers no test sign-in — no accounts are created here and no credentials are stored.

Read the W3C WebAuthn specification

Frequently asked questions