What Is a FIDO2 Passkey, and What Needs Backing Up?

A FIDO2 passkey is a cryptographic credential used with the WebAuthn and FIDO2 standards to sign in to websites and applications. Unlike a conventional password, it is normally bound to a particular relying-party account, such as a specific Google, Microsoft, or bank login. The credential may be stored in a platform authenticator such as Windows Hello or a Mac with Touch ID, on a removable FIDO2 security key, or in a synchronized passkey provider such as an Apple, Google, or Microsoft account. A separate FIDO2 key, once registered, is a common alternative to a synced passkey rather than a second copy of that same passkey.

Also worth reading: How Can You Make Speech-to-Text Privacy Safer Without Losing Accuracy? · How Can You Restore Grindr Access in Germany Without Breaking Privacy Rules? · How Do You Merge Multiple Transcript Files Without Losing Timestamps or Speaker Labels?

Backing up a passkey means preserving the ability to create or use another authenticator for the same account. It does not mean exporting a private key into an ordinary file, writing its secret number on paper, or sending it to a transcription service. For most consumers, the account provider already offers a recovery path through a second registered device, a device-management account, or a synchronized credential. Some organizations use password managers, while others intentionally use hardware-only credentials and keep offline recovery codes instead. As of 30 September 2026, passkey adoption is broad, but deployment practices still differ materially between personal accounts and regulated workplaces.

A useful backup plan has at least two independent ways to authenticate, plus a tested account-recovery route. One method can be a platform passkey, such as Windows Hello; another can be a removable FIDO2 key registered directly with the important account. Account recovery should not depend on the second method residing in the same synchronized ecosystem as the first. Microsoft’s move to recognize Windows Hello and macOS platform passkeys as multifactor authentication in Entra ID also illustrates an important distinction: a device-bound credential can serve as strong MFA, but it is not automatically a portable backup.

Platform Passkeys, Security Keys, and Synced Credentials Compared

There is no single best type of FIDO2 backup. Platform passkeys are convenient because they are built into devices people already use, while hardware security keys are more portable and work across accounts that support FIDO2. Synchronized passkeys are convenient across ecosystems, but they trade some local control for cloud-backed availability. A password manager may provide another copy, yet users should confirm that its particular product actually supports creating, storing, and restoring FIDO2 passkeys rather than merely offering a passkey login feature to its own service.

FeaturePlatform or synced passkeyRemovable FIDO2 security key
StorageBuilt into a device or synchronized through a providerCredential stays on dedicated hardware
PortabilityHigh for synced passkeys; low for device-bound credentialsHigh when the site supports USB or NFC keys
Best recovery designMaintain a second device and provider accountRegister at least two physical keys in separate locations
Main concernLost device, provider-account loss, or ecosystem dependenceCost, compatibility, and loss of both keys
Typical costOften included with a device or accountRoughly US$30–$100 per key, depending on features
Best fitEveryday consumer accounts and supported workplace sign-inHigh-value accounts, shared administration, or hardware-only policy
A good design normally combines both categories. For example, retain a device passkey for daily use and register a USB-C or NFC security key as a backup. Do not assume that adding the same physical key to a password manager gives you a separate FIDO2 credential; it may simply be stored as a removable authenticator. The service must explicitly support WebAuthn credential creation and export or restoration for the exact credential to be recoverable there. The Rublon configuration described in the research is a useful example of a product that can use a FIDO U2F or FIDO2/WebAuthn hardware key as well as a FIDO2 passkey stored in a password manager.

A Practical FIDO2 Passkey Backup Procedure

Begin by identifying the accounts that matter most: email, financial accounts, domain or cloud administration, password manager, code-hosting service, and identity provider. Email deserves special attention because password resets for other services often route through it. Inventory the current passkeys and methods in each account’s security settings, recording where each authenticator physically resides. This should take about 20–40 minutes for a typical personal account set, while a small business may need several hours to document credentials, administrators, and recovery procedures.

Next, create a second credential using a different category of authenticator. If the existing passkey is synchronized through a consumer account, create or register a removable FIDO2 key. If the existing method is hardware-only, add a supported platform passkey or a second physical key. When the site offers “backup,” “recovery,” or “another device” options, use them, and give the entry a recognizable label such as “USB-C recovery key” rather than “key 2.” Some services limit the number of passkeys, while others permit many, so a clear label makes later replacement easier.

Then protect the second authenticator and its account. Store one security key in a secure office drawer or home location and another in a separate location if the account permits multiple keys. For a synchronized passkey, enable multi-factor authentication on the provider account, store its recovery codes in an offline password manager or printed safe, and verify that the provider can recover access through a trusted device. Avoid placing an unregistered security key and all its recovery information inside the same bag; that arrangement creates two backups of one failure point.

Finally, test without signing yourself out. Many services provide a “test passkey” or credential-addition flow, and some identity platforms can initiate authentication with the new key. Testing confirms that the device, browser, USB or NFC interface, PIN, and account association all work. Do not delete the original credential merely because a new one was added. A practical checkpoint is to complete one end-to-end test within 7 days, repeat it after 6–12 months, and whenever you replace a phone, laptop, password manager, or security-key firmware.

Why a Passkey Cannot Be “Backed Up” Like a Password

FIDO2 credentials contain asymmetric cryptographic material. The private portion remains on the authenticator, and the public portion is registered with the relying party. This design prevents a phished website from receiving a reusable secret, which is the main reason passkeys resist credential phishing. However, it also means that copying an arbitrary passkey to a text document, cloud folder, email attachment, or audio transcription does not create a valid backup. Even if a user could copy the encoded public credential, that public value would not be enough to authenticate.

A recoverable backup therefore requires a mechanism defined by the credential provider. Synchronized platform passkeys can often be reconstructed through the provider’s account and device ecosystem. Some passkey managers support credential export or account recovery, but they should be assessed by their backup format, encryption, provider recovery rules, and support boundaries. A hardware security key may use a backup scheme supported by its manufacturer, but this is not universal; many models are designed to hold non-exportable credentials. Buyers should ask whether the product supports encrypted backup and restore before assuming that “hardware key” means “replaceable if lost.”

The private key also should never be given to an AI transcription workflow, support agent, or stranger who requests it. Transcribing spoken notes can be useful for records, and audio-to-text tools can process a discussion about recovery planning, but the service should not receive raw authentication secrets, one-time codes, recovery phrases, or private-key material. If a recording is used to plan changes, record only public facts such as “register a second key by 1 October” and redact account identifiers. This distinction matters because spoken confirmation is weaker evidence than cryptographic possession, and an inaccurate transcript could cause the wrong credential to be removed.

Costs, Compatibility, and Real-World Limitations

Platform passkeys are frequently free because Windows, macOS, Android, iOS, and participating account providers already include the necessary hardware and software. Creating a second platform credential may therefore cost nothing beyond a compatible device. Some managed identity products or enterprise plans add fees, while consumer services commonly offer basic passkey registration without charge. A removable FIDO2 key generally costs about US$30–$100 as of 2026, although premium models may cost more because of biometrics, portability, tamper resistance, or management features.

Compatibility is more important than the lowest price. The account must support FIDO2 or WebAuthn, the browser must be current, and the key must match the device port or NFC standard. USB-A keys remain useful with adapters, but USB-C is a better default for newer laptops. NFC works with many phones but depends on browser and operating-system support. A hardware key may authenticate to one service while failing to enroll in another if that service uses a restricted authenticator policy or outdated implementation.

Users should also account for the recovery threshold. A common personal target is two working authenticators, one of which is not tied to the same physical device. A higher-value administrator might keep three: a daily platform credential, an offline hardware key, and another hardware key held by a trusted recovery custodian. Organizations can set thresholds based on risk, but no universal percentage makes three methods automatically sufficient. The decisive test is whether the account can be recovered after the loss of one device, one provider account, and potentially one physical location without relying on a phishable password alone.

Common Backup Mistakes That Can Lock People Out

The most damaging mistake is treating a synchronized passkey and a device backup as independent when they share one account. A phone can contain a platform passkey, but if the associated cloud account is compromised, both may be exposed. Another mistake is adding a recovery key but failing to complete its initial authentication. Registration may succeed while PIN setup, browser permissions, or an unsupported extension remains broken, so the apparent backup is untested.

People also confuse security keys with one-time recovery codes. A code may be used once and then expire, whereas a passkey is intended for repeated authentication. Recovery codes should be stored offline and protected from moisture, loss, and unauthorized access. Similarly, do not create a second passkey on the same phone, assume the phone is backed up, and conclude that a new independent path exists. Replacing a lost phone is sometimes the easiest recovery option, but device replacement depends on vendor account access, inventory activation, proof of ownership, and time.

Avoid removing the old passkey until the new one has completed a full login and a logout. Do not send a key, PIN, recovery code, or QR enrollment secret to “support,” even if the request appears to come from a familiar brand; verify the request through the provider’s official application or published support page. A sensible precaution is to require two successful tests at least 48 hours apart, followed by review every 6 months. A simple spreadsheet can record credential type, label, creation date, and physical location without recording secrets, although a managed password vault may be more appropriate for a business.

When to Act and How to Maintain the Backup

Act before a device fails, an account changes ownership, or a phone is lost. The best time for a personal setup is during a quiet 30–45 minute maintenance window, and the best time for a small organization is during its next access-review cycle. Start with the email account and identity provider because they can reset credentials for other services. Complete the primary and secondary authenticators before migrating to less important sites, and schedule the process backward from 30 September 2026 or another explicit review date so it does not become indefinite.

A maintenance interval of 6–12 months is reasonable for ordinary users, while privileged administrators may review quarterly or whenever membership changes. At each review, confirm that both methods still exist, that recovery codes have not expired, and that the second key opens a current browser. Replace a security key when the manufacturer ends support, when firmware cannot be updated, or when the account begins requiring features the model lacks. Keep a record of model, serial number, purchase date, and firmware version, but do not place the device or a usable copy of its credential beside that record.

Passkey backup is a security decision, not a transcription task. Transcribe a recovery plan if desired, then manually review the generated text against the service’s official settings before deleting any existing credential. The passkey itself must be recreated through the service’s supported enrollment process or restored through a legitimate provider. That final distinction protects the account while allowing audio-to-text tools to help organize instructions, meeting notes, or hardware inventory for people who maintain FIDO2 access.