Recover a passkey after losing your device

A passkey may be synchronized by a password manager or stored only on one device or hardware key. Losing a phone therefore does not always mean losing the passkey, but buying another phone does not automatically recover it either. First identify where the credential was saved.

This page covers passkeys for accounts you own. For a lost authenticator code, use two-factor recovery. If the password manager or Apple or Google identity holding the passkey is locked, recover that provider through its official route; account recovery covers Apple and Google.

1. Check another device with the same synchronized provider

Microsoft's passkey-management guide distinguishes device-bound passkeys from those stored in a synchronized credential manager. If your passkey was synchronized, another approved device signed in to that provider may already have it. Check the provider rather than assuming the website stores a downloadable private key for you.

Apple's iCloud Keychain instructions describe making passwords and passkeys available on approved devices. Use the account and verification requirements Apple presents for your setup. An Apple Account login alone should not be assumed to satisfy every check needed to recover the encrypted keychain.

For a Google Account passkey, Google's official guidance explains its supported sign-in options. Select the intended account and credential provider. Several managers can appear on one device, and the first one offered may not hold the passkey you originally created.

2. Use a second registered passkey or another account method

If another phone, computer, or security key was separately registered with the service, try that supported method. Google's passkey article notes that adding a passkey to a Google Account does not remove its existing authentication and recovery factors. The same assumption should not be applied to every other service without checking its settings.

Choose another sign-in option from the service's own page when offered. That may involve a password, security key, backup code, or account recovery. The available route depends on what was configured and the service's policy, not simply on whether the account uses passkeys in general.

For a work or school account, contact its administrator if the approved credential is unavailable. The organization may restrict which providers or recovery methods can be used. Do not install an unapproved manager or weaken security settings just to imitate a consumer tutorial.

3. Recover the credential provider when necessary

Apple's keychain-recovery guidance describes recovery contacts and its protected recovery process when devices are lost. Follow the requirements for your account, including the trusted verification and device information it requests. Preserve any remaining trusted device until the replacement is confirmed.

For another password manager, use that manager's own recovery process. Our Bitwarden and 1Password guides explain their particular limits. Recovering a website account and recovering the vault holding its passkey can be separate tasks.

A passkey stored only on a missing hardware key or device generally cannot be synchronized after it is lost. Use another registered method or the service's recovery process. A device PIN is local protection for a credential; knowing that PIN does not recreate the missing device's private key on a new computer.

4. Replace access before removing the lost credential

Microsoft's management instructions recommend adding a new method before removing old passkeys. Once you regain the account, register and test the replacement through the service's security settings. Confirm which entry belongs to the lost device before revoking it.

Deleting a passkey from a manager and removing its registration at the service are related but different actions. Follow both providers' instructions where needed. If a device was stolen, also use its platform's lost-device controls and review active account sessions from a trusted device.

A passkey is not immune to a missing recovery plan.

If the only credential was device-bound and every alternate method is unavailable, the service may be unable to restore access. A synchronized passkey still depends on recovering and unlocking its credential provider. No outside helper can promise to recreate a lost private key.

After you regain access

Keep more than one supported path into important accounts and label passkeys so their devices or providers are recognizable. Test the backup route before retiring the old device. Store provider-recovery information somewhere that does not depend entirely on the same missing phone.

Login.com's passkey explanation helps you understand these storage and sign-in differences. Review the account's registered methods after a migration and remove obsolete access only once replacements work. A deliberate backup arrangement makes passkeys easier to recover without turning a future device loss into an unexplained account dead end.

Instructions checked against vendor guidance on 24 September 2026.