Passkeys and account security
Updated 16 September 2026
Add a passkey, and see what is protecting the account behind the scenes.
Add a passkey
In Sign-in & security, add a passkey. From then on you can sign in with Face ID, Touch ID, Windows Hello or your device's unlock instead of waiting for an email code. Email codes keep working as a fallback.
What is protecting the account already
A device limit per member. Access is bounded by the number of devices on the plan, not by who knows a password.
A waiting period. Slots do not free up instantly, so devices cannot be cycled to get around the limit.
Browser access is temporary and approved. Signing in from a browser needs approval from one of your devices, and the session is short-lived.
Your logins are encrypted. Provider credentials are encrypted on your device. They are readable by your devices, and not by us.
Recent activity
The same screen lists recent sign-ins and device changes, with a note of how serious each one is. Two entries worth reading if you see them:
- An old sign-in was used again: a stale credential was replayed, so that session was signed out. Usually a stored session on a device that came back online; occasionally worth investigating.
- A purchase was tried on this account that belongs to another: someone attempted to claim a store purchase already bound elsewhere.
If anything there is not you, disconnect the devices you do not recognise and tell us.