A passkey replaces passwords with a public-private key pair stored on the user’s device, offering phishing-resistant authentication via biometric or PIN verification instead of typed secrets. Because no shared secret lives on the server, breaches only expose useless public keys, neutralizing credential stuffing and offline cracking attacks.