Two keys, two jobs.
One key makes the proof. The other checks it. Only the public one goes to the website.
Watch a passkey get created, used, and tested against a fake site,
or step through at your own pace.
Your side of the connection
mysticcoders.com
Imagine you’re creating a passkey for mysticcoders.com. The website asks your device to make a credential just for this site.
This is an interactive model. It won’t create a real passkey or ask for your fingerprint.
Focus the walkthrough and use ← / → to move between steps.
A passkey provider keeps your private keys protected. These are a few examples.
Hardware security keys, such as a YubiKey, can hold device-bound passkeys that stay on the key.
One key makes the proof. The other checks it. Only the public one goes to the website.
Your face, fingerprint, or PIN approves use of the passkey on your device.
A lookalike domain can’t request the passkey belonging to the real site.
It depends on the website. Some let you use only a passkey; others keep a password as a fallback. Check the site’s sign-in and recovery options before removing a password.
If your passkey is synced, you may be able to use it on another device through the same provider. A device-bound passkey needs another registered authenticator or the website’s account-recovery process. Set up recovery before you need it.
Many providers sync passkeys across supported devices. Some sign-in flows also let you use a nearby phone with a QR code and Bluetooth. Availability depends on the website, device, and provider.
A stolen public key cannot produce the private-key signature needed to sign in. But a website breach may still expose other account data, and passkeys do not protect a session that an attacker has already stolen.
No. This is a simplified educational simulation using Mystic Coders as the example website and a fictional lookalike domain. It does not collect biometric data, create credentials, or sign you into any account.