
Passwords are the part of signing in that everyone hates and nobody has fixed, until now. Passkeys explained in one sentence: they replace a password with a biometric or device-based check, face, fingerprint or PIN, that cannot be phished, reused or leaked in a data breach the way a password can. If you run a busy team where people are signing in from a phone backstage or a laptop they just handed to a colleague, that difference is not academic.
This is the plain-language version of what a passkey actually is, why security teams are pushing them so hard, and how to turn them on.
- A passkey is a device-bound cryptographic key pair. The private half never leaves the device, so a server breach cannot expose it.
- Passkeys are phishing-resistant by design, cryptographically bound to the exact site they were created for.
- Enterprise teams can combine passkeys with single sign-on and team roles for layered identity control.
What a passkey actually is
A passkey is a cryptographic key pair created on your device when you set one up for an account. One half stays locked to your device, protected by whatever unlock method you already use, face, fingerprint or PIN. The other half is registered with the service you are signing into. Signing in proves you hold the private half, without that half, or anything resembling a password, ever being sent anywhere.
That is a fundamentally different model from a password. A password is a shared secret: you know it, and the server also stores something derived from it, which means a breach on the server side can expose it. A passkey never leaves your device, so there is nothing on a server to steal that would let someone sign in as you.
Passkeys are built on WebAuthn, an open standard backed by the FIDO Alliance, and supported natively by every major browser and operating system.
Why passkeys resist phishing where passwords do not
Password phishing works because a password is portable. If someone tricks you into typing it into a fake login page, they now have a copy of the real thing and can use it anywhere. Passkeys break that entire attack.
A passkey is cryptographically bound to the exact website or app it was created for. Even if you were somehow tricked into visiting a convincing fake login page, your device would not offer up a passkey for it, because the fake page's address does not match the one the passkey was registered against. There is no password to type into the wrong place, because there is no password at all.

Passkeys versus the alternatives
| Method | Phishing resistant | Convenient | Notes |
|---|---|---|---|
| Password alone | No | Medium | Reusable, guessable, exposed in breaches |
| Password + SMS code | Partial | Low | SMS can be intercepted or SIM-swapped |
| Password + authenticator app | Better | Low | Still relies on a phishable password underneath |
| Passkey | Yes | High | Device-bound, nothing transferable to steal |
Passkeys are not a replacement for every security control, team roles and network protections still matter, but for the specific job of proving who is signing in, they close a gap that no amount of password policy training fully closes. A team that has spent years reminding people not to reuse passwords will get further in a single afternoon of passkey rollout than another year of reminders.
Setting up a passkey for your Cliqer account
Adding a passkey to your account takes under a minute:
- Go to Dashboard → Settings → Security.
- Click Add biometric sign-in (this appears when your browser supports passkeys, such as Safari, Chrome or Edge).
- Follow your device's prompt, fingerprint, face or PIN, to confirm.
- The passkey now appears in your list, and you can sign in with it going forward instead of typing a password.
On the desktop app, the same flow works through the pairing screen: sign in once with your existing credentials, save a passkey, and future sign-ins on that device use biometrics without a password or licence key. On Windows, identity checks inside the app's settings can use the built-in Windows Hello prompt, face, fingerprint or PIN, the same underlying mechanism.
You can register more than one passkey per account, useful for a work laptop and a personal phone, and remove any of them at any time from the same security settings page.

This is the same authentication layer that sits underneath everything else Cliqer secures over WebRTC: a passkey confirms who you are, encryption protects what travels once you are in. Both matter, and neither substitutes for the other.
Passkeys for teams
For a single user, a passkey is a convenience upgrade. For a team, it is a meaningful reduction in your weakest link. A shared or reused password anywhere in a team is a standing risk; a passkey cannot be shared the same way, because it is bound to a specific device's hardware-backed storage.
Teams on an Enterprise plan can combine passkeys with single sign-on and team roles for layered control: strong individual sign-in, centralised identity management, and scoped permissions once someone is in. If you are building the case for stronger authentication as part of a wider software review, our security checklist for presentation software and getting AV software approved by IT cover the rest of that conversation. For teams handling especially sensitive material, read presenting confidential content alongside this for the full picture of what protects a boardroom deck end to end.
FAQ
Not for everyday sign-in, but most services, including Cliqer, keep a password as a fallback in case you lose access to every device with your passkey. Keep it strong and unique regardless.
Sign in with your password or another registered passkey, then remove the lost device's passkey from your security settings and add a new one on your replacement device.
No. A saved password is still a password, just autofilled, and it can still be phished if entered on a fake site. A passkey uses cryptography that is bound to the real site and cannot be typed into the wrong one.
Generally no, since a passkey is tied to a specific device's secure storage. Use your password on a shared computer, then set up a passkey on your own devices for everyday use.
Get started
Turn on a passkey in under a minute from Dashboard → Settings → Security, or read the full security overview for how passkeys fit alongside SSO and team roles. If you have not tried Cliqer yet, download it free and set up biometric sign-in the first time you pair the desktop app.
Stream Deck for Presentations: Build a One-Button Show Controller
Turn an Elgato Stream Deck into a one-button show controller for slides, timers and callers, over USB or the plugin.
Clicker Latency: Why Milliseconds Matter on Stage
Clicker latency is the gap between your tap and the slide moving. What causes it, what is normal and what cuts it down.
Run your next show with Cliqer
Keep reading
More security & it for your next show


Presenting Confidential Content: Data Protection for Board Meetings

TURN Servers Explained: How Video Gets Through Restrictive Networks
Get the next guide before your next show
Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.
