Passkeys need a recovery plan, not a shared password

Passkeys replace passwords with cryptographic credentials. Some sync through a credential provider; others stay on one device or hardware key. Unlocking can use a device PIN or biometrics. Death does not itself tell a device to disable a passkey. The FIDO Alliance explains the distinction between synced and device-bound passkeys.

For each important account, record its provider and authorised recovery route. Do not assume that possessing a device, password or backup code gives someone permission to use an account.

Apple Legacy Contact does not include passkeys

Apple explicitly excludes iCloud Keychain passwords, passkeys and payment information from Legacy Contact access. The contact can request eligible data using the access key and required death documentation. Read Apple’s Legacy Contact guidance and keep that access key with your estate planning documents.

Other providers have their own recovery and succession rules. A synced passkey does not guarantee a successor can recover it. Check the current provider instructions instead of assuming that a password, device PIN or inactive-account setting will unlock everything.

Write down where to start

  1. List important accounts and where their passkeys are managed.
  2. Configure provider-supported recovery or legacy tools where available.
  3. Record who is authorised to help and where the relevant documents are kept.
  4. Keep any recovery secrets under an appropriate separate custody arrangement.
  5. Rehearse with a harmless account and retain an independent copy of the instructions.

ZeroLatch can send your chosen person instructions after missed check-ins, reminders and your extra waiting time. It cannot recover another service’s passkeys, establish legal authority or detect death. Start with a simple family checklist.