3.3: Make One Right Now
Make One Right Now
First, find it on the practice computer
Creating the passkey is the easy part — finding the setting is the hunt. Practice the hunt here, then meet the real prompt below.
Reading about key pairs is one thing. Watching your own device create one is another. The demo below is real WebAuthn, the same machinery Google and Apple use, running against this page only. The passkey it creates is a clearly labeled throwaway: it’s never sent anywhere (this page has no server to send it to), and you’ll delete it in step three.
When you click Step 1, expect your device’s own security prompt: Touch ID, Face ID, Windows Hello, or your PIN. That prompt is your device asking permission to use a private key, exactly as Lesson 3.2 described. If your browser is too old for this, the demo will say so, and the annotated cards walk through the same flow either way.
Notice what you didn’t do just now: choose a secret, type a secret, or send a secret anywhere. That’s the whole point of the product.
Now do it for real
The demo passkey opened nothing, so spend the next five minutes making one that matters. Pick one high-value account from your 1.4 list that supports passkeys — Google, Apple, Amazon, GitHub, and most major banks do — and:
- Sign in to the account’s security settings.
- Find Passkeys (sometimes under “Two-step verification” or “Sign-in options”).
- Click Create a passkey and approve the same biometric prompt you just met.
That’s the whole procedure. The next time you sign in on that device: no password, one fingerprint, nothing to phish.
Where should passkeys live — device or manager?
When you create a real passkey, you may be asked where to save it: your platform (iCloud Keychain or Google Password Manager, syncing across that ecosystem’s devices) or your password manager (1Password and Bitwarden store passkeys too, syncing everywhere the manager goes). For most people the platform default is perfect. It’s the smoothest experience, and the sync is encrypted end to end. Choose the manager instead if your life spans ecosystems — an iPhone plus a Windows PC, say — so your passkeys travel with the vault rather than the vendor. The trade-off is that your manager account becomes even more precious than it already was. Both options are excellent. Pick by where you’ll use them, and don’t let the choice stall you: a passkey stored either place beats a password stored anywhere.
All of which raises the right question: if passkeys live on devices, what happens when the phone falls in a lake? That’s the last lesson, and it has a better answer than you’d fear.