Passwords are slowly being replaced by a phishing-resistant alternative called passkeys, and Bitwarden is one of the most popular tools for managing them. This guide explains, in plain English, how Bitwarden handles passkeys, how to set them up in your browser and on your phone, and what to expect if you use the service in New Zealand. If you are new to the wider concept, it also helps to read a short primer on what a passkey is before you begin.
The Bitwarden password manager is open-source software built on the FIDO2 and WebAuthn standards. It can store the passkeys you use to sign in to other websites, and it can also let you unlock your own Bitwarden account with a passkey instead of a master password. These are two separate features, and keeping them apart makes the setup much easier to follow.
Key Points
- Phishing-resistant by design: a passkey is tied to one website’s domain, so it cannot be used on a look-alike phishing site.
- Two separate features: Bitwarden can store passkeys for other websites, and it can let you log in to Bitwarden itself with a passkey.
- Included on the free plan: saving and syncing passkeys costs nothing and works across unlimited devices.
- PRF vault unlock: a PRF-capable browser plus a compatible security key can unlock your vault without the master password.
- Cross-platform: supported in Chrome, Edge, Brave and Firefox extensions, plus iOS 17+ and Android 14+.
- Keep your master password: it is still needed for recovery and new devices, so store an offline copy safely.
What passkeys are and why they matter
A passkey is a login credential based on public-key cryptography rather than a secret word you type. When you create a passkey for a website, your device generates a matched pair of keys: a public key and a private key. Cryptography here simply means using linked mathematical keys to prove identity without ever sending a shared secret.
The website keeps only the public key, which is useless to an attacker on its own. The private key stays locked inside your device or password manager and never leaves it. To sign in, the site sends a one-time challenge that only your private key can answer. Because nothing reusable travels across the internet, passkeys are resistant to phishing, credential stuffing (attackers reusing leaked passwords) and database breaches. They were developed by the FIDO Alliance together with the World Wide Web Consortium (W3C), the group that maintains core web standards.
In practice, the whole exchange is invisible: you tap “sign in”, your phone or laptop asks for a fingerprint, face scan or PIN to prove you are present, and you are logged in. There is no password to remember, reset or leak, and there is no code to copy from a text message. That local verification step is also why a passkey counts as strong two-factor authentication on its own — it combines something you have (the device holding the private key) with something you are or know (the biometric or PIN).
Passwords compared with passkeys
The table below summarises the practical differences between typing a password and using a passkey.
| Factor | Traditional password | Passkey |
|---|---|---|
| How it works | A shared secret sent to the server | A private key that never leaves your device |
| Phishing risk | High — can be typed into a fake site | Very low — bound to the real domain |
| If the server is breached | Password hashes can be cracked offline | Only a useless public key is exposed |
| Effort to sign in | Type or paste a long string | A fingerprint, face or PIN check |
| Second factor | Usually a separate app or SMS code | Built in — the device check counts as verification |
The two ways Bitwarden handles passkeys
Before changing any settings, it helps to know which of Bitwarden’s two passkey features you are using. Both live in the same apps, but they solve different problems. A general overview of how these tools fit together is covered in our password manager guide for New Zealand.
Quick Facts
| Developer | Bitwarden, Inc. |
| Official download | bitwarden.com/download |
| Licence | Open source (client apps under GPLv3; source-available server components) |
| Standards | FIDO2 / WebAuthn, including the PRF extension |
| Platforms | Windows, macOS, Linux; Chrome, Edge, Brave, Firefox and Safari extensions; iOS 17+; Android 14+ |
| File size | Varies by platform |
| Price | Free plan includes passkeys; Premium US$19.80/year; Families US$47.88/year |
1. Storing passkeys for other websites
Here Bitwarden acts as a vault that holds the passkeys for your everyday accounts, such as Google, Microsoft, Amazon or a local retailer. When a site asks you to create or use a passkey, Bitwarden offers to save it and, on your next visit, completes the sign-in after a biometric or PIN check. Passkeys stored this way sync across your devices with the rest of your vault, so a passkey created on your laptop is available on your phone. Note that Bitwarden allows only one passkey per login item, so a second passkey for the same site is saved as a separate entry.
2. Logging in to Bitwarden with a passkey
This is the passwordless login for your Bitwarden account itself. Once enabled, you open your vault with a passkey — for example a hardware security key such as a YubiKey, or your computer’s built-in biometrics — instead of typing your master password. As of late 2025 this option works in the Bitwarden web app and in Chromium-based browser extensions (Chrome, Edge and Brave). For extra protection alongside passkeys, many users also set up two-step login, which we cover in our Bitwarden authenticator guide.
Setting up passkeys in your browser
The browser extension is where most people first meet passkeys. It generates and fills them across Google Chrome, Mozilla Firefox, Microsoft Edge and Brave. By default the extension asks to save and use passkeys automatically, so there is little to configure.
To avoid clashes with your operating system’s own handler — such as Windows Hello or iCloud Keychain on macOS — open the extension, go to Settings and confirm that “Ask to save and use passkeys” is switched on. If there is a site where you never want to be asked, you can add it to the extension’s excluded domains list.
Creating and using a stored passkey then follows a simple pattern:
- On a website’s security or login page, choose the option to create a passkey.
- When the browser asks where to save it, pick Bitwarden rather than the system handler.
- Confirm the save prompt in the extension; the passkey is added to a login item in your vault.
- Next time you sign in, select the account and approve the Bitwarden prompt to complete the login.
Because the passkey lives in your encrypted vault, it syncs to your other signed-in devices automatically. Bitwarden can also include passkeys in an encrypted JSON export, which is handy if you ever migrate accounts, though for day-to-day use the built-in sync is enough.
Enabling passkeys on iOS
Apple devices default to iCloud Keychain, so you must tell the system to let Bitwarden fill passwords and passkeys. You need iOS or iPadOS 17.0 or later.
- Update your iPhone or iPad to iOS 17 or later.
- Open the Settings app and tap Passwords (authenticate with Face ID or Touch ID).
- Tap Password Options (labelled “AutoFill Passwords and Passkeys” on some versions).
- Turn on AutoFill Passwords and Passkeys.
- Under “Use passwords and passkeys from”, switch Bitwarden on. Turn off iCloud Passwords if you want Bitwarden to be the only handler.
- Open the Bitwarden app, go to Settings > Autofill, enable autofill and turn on biometric unlock.
Enabling passkeys on Android
Android uses its Credential Manager framework to pass passkeys between apps and your vault. You need Android 14 or later with Google Play services installed, and passkey autofill is supported in Chromium-based browsers.
- Update your device to Android 14 or later and confirm Google Play services is present.
- Open the Bitwarden app and go to Settings > Autofill.
- Tap Passkey management, then Continue — this opens your device’s system settings.
- Set Bitwarden as a preferred or additional passkey (credential) provider.
- Return to Bitwarden and enable biometric unlock so a fingerprint confirms each sign-in.
One limitation to note: on Android, Bitwarden passkeys can only be used as a primary sign-in credential. Android does not currently allow third-party managers to provide passkey-based two-step verification.
Passwordless login and PRF vault encryption
Switching your Bitwarden account itself to passwordless login removes the need to type your master password during daily use, which reduces the risk from shoulder-surfing and keyloggers. This relies on a technical feature called the FIDO2 PRF (Pseudo-Random Function) extension.
PRF does more than confirm who you are. When both your browser and your security key are PRF-capable — for example Chrome paired with a YubiKey 5 — the passkey can also derive the key that decrypts your vault locally, so a single biometric check both signs you in and unlocks your data. Two caveats apply: Windows 10 is known to have problems with PRF passkeys, and the feature is not available for accounts governed by SSO, trusted devices or Key Connector.
| Step | What to do | Why it matters |
|---|---|---|
| 1. Open security settings | Sign in to the web app and open your account Settings > Security | This is where account login options live |
| 2. Find the passkey option | Locate the “Log in with passkey” section | Shows the passwordless choices available |
| 3. Create the passkey | Select “New passkey” and re-enter your master password | Confirms you own the account |
| 4. Register your device | Follow the prompts to link Touch ID or a YubiKey | Generates the key pair on your hardware |
| 5. Enable vault encryption | Tick “Use for vault encryption” if offered | Lets the passkey unlock your vault too |
| 6. Name and save | Give the passkey a label and save | Adds it as a login method |
You can register up to five passkeys for logging in to your Bitwarden account, which is useful for keeping a backup key in a safe place.
Log in with device on shared computers
If you sometimes sign in on a public or borrowed computer, typing your master password is risky. Bitwarden’s “Log in with device” feature lets you approve a session from a phone or computer you already trust, without typing anything secret on the untrusted machine.
When you enter your email and choose “Log in with device”, Bitwarden sends a push notification to your logged-in apps. To defend against approval-spam (“push fatigue”) attacks, the request is protected by a matching check that you should always verify:
- The new screen shows a random four-word fingerprint phrase, for example juniper-sandbar-footnote-improve.
- The approval notification on your trusted device shows the same phrase, along with the IP address, time and browser of the request.
- Compare the two phrases and approve only if they match exactly.
- Your device must have its vault unlocked to approve, and each request expires after 15 minutes.
Using passkeys in New Zealand
Passkey checks are fast because they involve a small cryptographic exchange rather than a large download. On New Zealand’s fibre network, delivered largely over Chorus infrastructure, and on mobile connections from Spark, One NZ and 2degrees, that exchange completes in a fraction of a second. Strong, unique credentials are also a practical defence for your finances and identity, a theme we return to in our cyber security guide.
Passkey support depends on each individual website, not on your location, but many services New Zealanders use every day already offer it or accept Bitwarden autofill:
- Banking: the major banks — ANZ, ASB, BNZ, Westpac NZ and Kiwibank — increasingly support device-based sign-in and secure autofill.
- Government services: portals such as RealMe, IRD’s myIR and ACC can be reached with strong, stored credentials.
- Investing: local platforms including Sharesies, Hatch and Kernel benefit from unique keys per account.
- Shopping and media: Trade Me, retail sites and news services autofill cleanly from your vault.
Always confirm passkey availability on each provider’s own login or security page, as rollout dates vary between organisations.
Is it free, and what does it cost?
Saving, syncing and using passkeys is included on Bitwarden’s free personal plan, across unlimited devices, at no charge. The paid Premium plan (US$19.80 per year following the January 2026 update) and the Families plan (US$47.88 per year for up to six people) add extras such as built-in two-step login keys and encrypted file storage, but they are not required for passkeys. Current figures and inclusions are set out in our Bitwarden pricing plans overview.
Limits, quirks and good habits
Passkeys are maturing quickly, but a few rough edges remain. Some older or highly localised websites still require a typed password, and certain platforms in the Meta family (such as Facebook and WhatsApp) use multi-origin rules that can occasionally block passkey creation with a third-party manager. Keeping the app updated resolves many of these cases as compatibility improves.
- Keep a strong password as a fallback: where passkey support is patchy, store a long, unique password in the same vault item.
- Remember the one-passkey-per-item rule: adding another passkey for a site creates a separate entry rather than replacing the first.
- Protect your master password and recovery code: even with passwordless logins, these are still needed to add devices or recover access, so keep an offline copy somewhere safe.
- Register a backup: add a second passkey or hardware key so losing one device never locks you out.
Who Bitwarden passkeys suit
Passkeys in Bitwarden are a good fit for anyone who wants one place to hold both passwords and passkeys and to sync them across a mix of devices and operating systems. They are especially useful if you switch between Windows, macOS, Android and iOS, because a single vault follows you rather than being locked to one ecosystem such as Apple’s iCloud Keychain or Google Password Manager. Households sharing a plan and people who already rely on a hardware key like a YubiKey will also get the most from the account-level passkey login and PRF vault unlock.
If you are just starting out, the simplest path is to install the browser extension and the mobile app, sign in to your free account, and begin saving passkeys the next time a site offers one. You can layer on account passkey login and “Log in with device” later once you are comfortable with the basics.
Sources
- Bitwarden Help — Log in with passkeys
- Bitwarden Help — Store and autofill passkeys
- Bitwarden Help — Log in with device
- Bitwarden Help — Password Manager plans
- Bitwarden Blog — Passkeys go mobile
- Help Net Security — Bitwarden extends passkey login to browser extensions
- FIDO Alliance — Passkeys overview
- W3C — Web Authentication (WebAuthn) specification
Frequently asked questions (FAQ)
Are passkeys more secure than a strong password with two-factor authentication?
Generally yes. A strong password can still be typed into a convincing fake website or exposed in a server breach, while a passkey uses a key pair tied to the exact domain, which makes it resistant to phishing and to leaked-database attacks. The device check that unlocks a passkey also acts as a second factor.
Does the free Bitwarden plan include passkeys?
Yes. The free personal plan lets you save, sync and use passkeys across unlimited devices at no cost. Paid plans add features such as built-in two-step login keys and encrypted file storage, but they are not needed to use passkeys.
What happens if I lose the device that stores my passkeys?
Passkeys saved in your vault are encrypted and synced, so a lost phone does not lock you out. You can sign in on a new device with your email and master password, then restore access. Keeping a second registered passkey or hardware key as a backup is a sensible precaution.
How many passkeys can I use to log in to my Bitwarden account?
You can register up to five passkeys for logging in to the Bitwarden account itself. This lets you keep a primary device plus one or more backups, such as a hardware security key stored in a safe place.
Why does a website sometimes refuse to create a passkey in Bitwarden?
Some sites, notably a few in the Meta family, use multi-origin rules that do not always accept a third-party passkey provider, and a small number of older sites do not support passkeys at all. Make sure the app and browser extension are up to date, and use a strong saved password until the site adds full support.




