From Clever Idea to Everyday Logins: What Passkeys Actually Are
Passkeys replace traditional passwords with cryptographic keys stored on your devices. Instead of typing a string of characters, your phone or computer creates a private key that never leaves the device and a public key that websites store. When you sign in, you simply confirm it’s you—usually with Face ID, fingerprint, or a device passcode—and your device proves ownership of the private key without revealing it. This design makes phishing far harder: your password manager or system will only offer a passkey to the legitimate site that matches the stored public key, not a look‑alike scam page. The experience is also smoother, since there are no passwords to remember, reset, or leak in data breaches in the same way. Until recently, though, passkeys came with a major catch: once you committed to a particular password manager or platform, your passkeys were effectively stuck there.

Google Password Manager Passkeys Catch Up With Import and Export
Google Password Manager on Android is now preparing to support passkey import export, closing a crucial gap in password manager portability. A hidden interface discovered in the app shows options to both import and export passkeys, tied into Google Play Services. That matters because many Android apps rely on Google Password Manager passkeys behind the scenes to store and sync credentials. Until now, Google backed the Credential Exchange Protocol (CXP) on paper but had not fully implemented it. CXP, developed through the FIDO Alliance, is the standard that lets different apps and platforms securely move passkeys between them. With Google’s implementation, Android devices gain a way to shuffle keys between providers instead of treating Google’s manager as a one‑way silo. Once this rolls out broadly, switching from Google Password Manager to another service—or vice versa—should no longer mean abandoning your existing passkeys and starting from scratch.
How the Apple Passwords App Helped Break Passkey Lock-In
Apple’s Passwords app quietly became one of the first mainstream tools to support full passkey import and export. With recent updates, it now lets you move passkeys from Apple Passwords to another manager and back again, using the same FIDO Alliance specifications that underpin CXP. For users who had hesitated to adopt passkeys, this was a turning point. Previously, moving between password managers meant your old passwords could follow you, but your passkeys could not. That created a genuine lock‑in risk: the more passkeys you created, the harder it became to leave the Apple ecosystem or any specific app. Now, the Apple Passwords app offers an export flow that hands your passkeys directly to another manager installed on the same device. Import tools work in the other direction as well. Combined with CSV import for legacy passwords, Apple’s approach shows how built‑in managers can support both convenience and long‑term flexibility.

Beyond Human Logins: Proton Pass and Passkeys in the Age of AI
While Apple and Google focus on making passkeys portable, other password managers are exploring what comes next. Proton Pass, for example, has been expanding into monitored credential sharing designed for automation and AI agents. The idea is that you can selectively share access to certain accounts under strict oversight, letting software act on your behalf without exposing raw credentials. Passkeys fit naturally into this evolution. Because they are tied to specific devices and cannot be simply copied like passwords, they offer a safer foundation for delegating access—whether to another person, a team, or an AI workflow. When paired with passkey import export standards, these advanced features no longer trap you in a single vendor. If Proton, Apple, Google, or another provider stops meeting your needs, password manager portability ensures you can move your passkeys and keep building secure, automated systems on your own terms.
Why Passkey Portability Is the Final Step to Mainstream Adoption
For passkeys to become the default way people log in, they must work across platforms, devices, and apps as seamlessly as passwords do today. Until recently, a missing piece was the ability to move passkeys between managers. Vendor lock‑in undermined trust: no one wants to commit to a future where changing apps means losing access to dozens of accounts. The growing support for standards like the Credential Exchange Protocol—now visible in Google Password Manager passkeys, the Apple Passwords app, and major third‑party tools—solves this. Users can adopt passkeys knowing they retain control over their data and can switch providers later. That aligns with the core promise of modern authentication: stronger security, less friction, and genuine choice. As more services support passkeys and more platforms enable secure import export, the question will not be whether to use passkeys, but why anyone is still relying on traditional passwords at all.

