What happens to passkey-protected accounts when the account holder dies?

Passkeys, tied to device biometrics and hardware security modules, become inaccessible after death because the device owner's biometrics are disabled by inactivity timeouts; heirs must rely on platform recovery mechanisms or pre-configured backup authentication methods stored in a encrypted delivery.

Passkeys are the future of authentication. They replace passwords with cryptographic keys stored on your device, unlocked by biometrics (FaceID, TouchID) or device PIN. Major platforms — Google, Apple, Microsoft, Amazon — now support passkeys, and the FIDO Alliance projects that passkeys will overtake passwords as the primary authentication method by 2027.

Passkeys are excellent for security during your lifetime: they're phishing-resistant, can't be stolen in data breaches, and don't require memorization. But they create a new challenge for digital estate planning: there's no "password" to share with your heirs.

A passkey lives on your device's secure enclave (iPhone) or TPM (Windows). It's unlocked by your biometrics or device PIN. When you die: • Your biometrics stop working after 48 hours of device inactivity (Apple) or on device restart • Your device PIN is the only way to unlock the passkey — and your heir probably doesn't know it • Even with the PIN, the passkey is tied to the specific device — it can't be exported or copied • Platform-synced passkeys (Apple iCloud Keychain, Google Password Manager) can be accessed from other devices — but only with your Apple ID or Google account credentials, which may also be passkey-protected

This creates a circular dependency: to access your accounts, your heir needs your passkey; to access your passkey, they need your device; to unlock your device, they need your PIN; to get your PIN, they need... a plan.

Use our Death Audit Checklist to catalog every passkey-protected account.

Passkey inheritance strategies by platform

Apple Passkeys (iCloud Keychain) Apple-synced passkeys are stored in iCloud Keychain and available across all your Apple devices. Your heir can access them if: • They have your Apple ID password (or can reset it with your device passcode) • They have your device passcode (to unlock the device) • They can access your iCloud Keychain (requires Apple ID login on a trusted device)

Apple's Legacy Contact provides access to iCloud data, but it's unclear whether passkeys are included in the Legacy Contact data download. Assume they are NOT — plan for alternative access methods.

Google Passkeys (Google Password Manager) Google-synced passkeys are stored in your Google Account. Your heir can access them if: • They have your Google account password • They can bypass 2FA (using backup codes — see our article on 2FA inheritance) • Google Inactive Account Manager has been configured to grant them access

Microsoft Passkeys (Windows Hello) Windows Hello passkeys are stored in the Windows TPM and are NOT synced across devices. If your heir doesn't have access to your specific Windows device and your Windows Hello PIN, the passkeys are permanently inaccessible.

Standalone Passkeys (1Password, Dashlane) Password managers that support passkeys store them in their vault. Your heir can access them if they have the password manager master password (see our article on password manager inheritance).

Hardware Security Keys (YubiKey, Titan) Hardware key passkeys are stored on the physical device. Your heir needs the physical key and the device PIN. Store the physical key's location and PIN in your ZeroLatch vault.

The passkey-ready digital estate plan

Step 1: Document every passkey-protected account List every account where you've enabled passkey authentication, including the platform that stores the passkey (Apple, Google, 1Password, hardware key).

Step 2: Ensure backup authentication methods exist Most platforms that support passkeys also support backup authentication methods (password + 2FA, backup codes, security questions). Ensure these backup methods are configured and documented.

Step 3: Store device passcodes in ZeroLatch Your device passcode (iPhone, Android, Windows) is the master key to your passkeys. Store all device passcodes in your ZeroLatch vault.

Step 4: Store platform credentials in ZeroLatch Store your Apple ID password, Google account password, and password manager master password in your ZeroLatch vault. These credentials provide access to platform-synced passkeys.

Step 5: Store 2FA backup codes in ZeroLatch If platform accounts use 2FA (which they likely do), store backup codes in your ZeroLatch vault so your heir can log in.

Step 6: Store hardware key locations and PINs If you use YubiKeys or Titan keys, document their physical locations and PINs in your ZeroLatch vault.

Step 7: Configure the dead man's switch Set a 14-30 day check-in interval. Designate your digital executor as the recipient. Include clear instructions explaining the relationship between device passcodes, platform credentials, 2FA backup codes, and passkey access.

The passkey era doesn't eliminate the need for a digital estate plan — it changes the credentials your heir needs. Instead of a list of passwords, they need device passcodes, platform credentials, 2FA backup codes, and hardware key locations. All of these belong in your ZeroLatch vault.