For Windows users, the transition is especially easy to misread. A passkey can make a sign-in feel almost effortless on a familiar PC and phone, yet the next device, a different browser, a work machine, a shared household computer or an account-recovery event can expose the parts of the ecosystem that are still uneven. Passwords remain widespread not because they are frictionless, but because compatibility and operational habits change more slowly than authentication technology.
The headline number is an estimate, not a census
FIDO said in May 2026 that five billion passkeys were in use worldwide. That is useful evidence of considerable scale, particularly compared with the early days of passkey deployment. But the methodology combines public information with FIDO's internal deployment data. Readers should therefore treat it as FIDO's estimate rather than a verified count of all passkeys held by every person, company and service.
There is also a meaningful difference between a passkey being created and a passkey changing a user's everyday behaviour. In FIDO consumer research published in May 2026, 75% of respondents said they had enabled a passkey on at least one account. Only 49% said they used passkeys regularly when the option was available. Those numbers point to real adoption, but they are survey results, not measurements of every account or login around the world.
The gap is even clearer in FIDO's 2025 Passkey Index. Across nine named FIDO member companies that had deployed passkeys for one to three years, the index reported that 93% of accounts were eligible for passkeys, 36% had enrolled one, and 26% of sign-ins used one. This is important directional evidence: making a passkey option available does not automatically make it the default user habit.
It is not a web-wide baseline. The companies were early adopters and FIDO members, while the results are averages from a limited group of deployments. An eligible account may have a user who does not notice the option, decides not to set it up, uses several devices, or prefers an existing process. A low usage share does not establish that passkeys are ineffective; it establishes that deployment, enrolment and regular use are separate problems.
Passwords are still frustrating—just broadly compatible
The argument that passwords persist because they work “everywhere, every time” does not withstand the available evidence. FIDO's 2026 consumer research found that 47% of consumers said they would be likely to abandon a purchase or sign-in if they could not remember a password. Forgotten-password flows, reset messages and account lockouts are familiar forms of login friction, not rare exceptions.
Yet broad familiarity still has value. Many users know how a password field works, have established password-management routines, and encounter it on services that may not offer a workable passkey path for their current device or setup. This does not prove that passwords are the single most common login method globally; the supplied research does not establish a comprehensive ranking of all login methods. It does show a large period of overlap, where password and passkey options coexist.
A related statistic is often used too aggressively. In May 2025, FIDO said that 48% of the world's top 100 websites supported passkeys. That calculation also combined public and FIDO deployment information, and it is a dated 2025 snapshot rather than a verified current count. More importantly, support at a major website does not answer whether passkeys are offered for every account type, in every sign-in flow, on every supported browser, or through every credential manager a customer might use.
Faster sign-ins are promising, but the comparison has limits
The Passkey Index contains encouraging usability results. In its nine-company group, passkey sign-ins were reported as 73% faster and achieved a 93% success rate, compared with 63% for other sign-in methods. Those figures suggest that a well-integrated passkey flow can reduce avoidable login failure.
But they should not be presented as proof that passkeys are 73% faster than passwords everywhere. The comparison category included email verification, SMS codes and social logins, rather than passwords alone. The participating companies were also not a random sample of internet services. The more defensible conclusion is narrower: among these established deployments, passkeys performed well against a mixed set of alternative authentication flows.
That is still consequential for Windows users. Repeated authentication is a routine part of shopping, banking, subscription services and work-adjacent accounts. A login method that succeeds quickly can save time and reduce the temptation to reuse weak or memorable credentials. But real-world reliability includes more than a successful sign-in on the device used at enrolment. It includes access from a replacement laptop, a borrowed PC, a new phone and a browser that is not part of the user's usual setup.
Device loss is not the same as account loss
A common concern is that losing a phone or PC means being forced back to a password. That is too simple. The UK National Cyber Security Centre says that a synced credential manager can restore access after the user regains access to the credential manager's sync fabric. In other words, a passkey need not be confined permanently to the physical device on which it was first used.
Cross-device sign-in is a separate capability from syncing. Microsoft documents that, for any passkey type, a user can sign in across devices by scanning a QR code. This can help when the service is open on one device while the passkey is available on another, such as a phone. It is useful in the practical Windows scenario of needing to access an account on a new PC without having already moved every credential to it.
Neither feature eliminates all failure cases. The user still needs a viable route to the relevant credential manager or another permitted device. Availability can depend on the account configuration, the service's implementation and the devices involved. A well-prepared user should not assume that one working phone is the only path into essential accounts.
The most useful distinction is between three issues that are often bundled together:
- Syncing within one credential-manager ecosystem: this can help restore passkeys after a device is lost, provided access to that ecosystem is regained.
- Cross-device authentication: a nearby device can help complete a sign-in on another device, including through a QR-code flow documented by Microsoft.
- Moving between credential managers: this is portability, and it has historically been a more difficult problem than either syncing or using a phone to authorise another device.
Treating these as the same feature makes both passkeys and their limitations harder to understand.
Portability is improving, not universal
The difficulty of moving passkeys between credential managers is a genuine adoption obstacle. The National Cyber Security Centre identifies inconsistent support, confusing differences between platforms, migration challenges, shared-device constraints and recovery planning as practical barriers to broader use. These are not merely cosmetic problems. They determine whether a user can switch phones, replace a Windows PC, separate personal and work credentials, or choose a different manager without accidentally creating an access problem.
There is evidence of progress. FIDO Credential Exchange is intended to enable secure transfer of credentials, including passkeys, between credential managers. Apple says participating credential-manager apps can import and export passkeys on its 26-platform releases. That means interoperability is not only a future promise.
The qualifying word is “participating.” The supplied material does not provide a complete authoritative inventory of supported credential managers and platforms, particularly for Windows and Linux. Users should therefore verify the source and destination applications and platforms before treating migration as a guaranteed feature. A transfer path demonstrated between participating apps on one platform is not evidence that every manager can exchange passkeys everywhere.
For people who switch devices frequently, use several operating systems, or keep personal and work sign-ins apart, that limitation is practical. It may be sensible to confirm recovery options and planned migration support before changing a primary credential-manager arrangement. This is not an argument against passkeys. It is an argument against assuming that an open-sounding standard automatically produces universal compatibility today.
Recovery remains the security pressure point
The most serious counterargument to a smooth passkey future is not that passkeys can never be restored. It is that any recovery route can become the route attackers target. The National Cyber Security Centre warns that attackers target recovery for both traditional multi-factor authentication and FIDO2-protected accounts because the recovery process can be weaker than the primary authentication method.
This is a residual risk shared with other account-security approaches, rather than a flaw unique to passkeys. The same assessment says recovery is generally similar for passkeys and traditional multi-factor authentication. It also said it had found no reports at the time of attackers phishing a user's sync fabric to obtain passkeys. That observation should not be inflated into a guarantee: security conditions can change, and a provider's recovery policy remains important.
The practical lesson is to prepare for recovery before a device disappears. For important accounts, users should understand what proves account ownership, what devices or credential-manager access remain available, and whether the service provides a documented way to regain access. They should avoid treating password fallback as the only contingency plan, but they should also avoid assuming that a passkey setup makes recovery design irrelevant.
What Windows users should do now
Passkeys are already useful where they fit a person's devices and credential-manager choices. The evidence supports that they can improve sign-in outcomes in mature deployments and that they can be restored or used across devices in some scenarios. It does not support declaring passwords obsolete, portability solved or every recovery journey equally robust.
A measured approach is more valuable than either extreme. Enable passkeys on accounts where the option is available and the sign-in experience works across the devices you actually use. Test a cross-device sign-in before an emergency makes it necessary. If considering a move between credential managers, check whether both sides participate in supported passkey transfer rather than assuming they do. And give account recovery the same attention normally given to the main sign-in method.
Five billion passkeys, if FIDO's estimate is directionally right, marks an authentication shift of substantial scale. But scale is not replacement. The near-term reality is a mixed environment: passkeys gaining ground, passwords remaining widespread, and the quality of the transition determined by interoperability and recovery as much as by the sign-in prompt itself.