Key takeaways

  • WhatsApp passkeys are now used by more than 1 billion people, according to WhatsApp.
  • A passkey lets a phone confirm your identity with a fingerprint, face scan or device PIN.
  • It removes the need to type a one-time code sent by text message.
  • The change could reduce account theft linked to stolen passwords and fake messages.

WhatsApp passkeys means a safer way to sign in without typing a password or SMS code. WhatsApp says more than 1 billion people now use them. The feature links your account to a trusted device. So a thief needs more than your phone number to get in.

WhatsApp shared the milestone in a recent update about account security. The company did not give a country-by-country split. Still, the number shows that passkeys have moved beyond early tech users. They now protect a large part of WhatsApp’s global audience.

What are WhatsApp passkeys?

A passkey is a digital sign-in key stored on your phone or another trusted device. It uses a security standard called cryptography. That means the device creates a matched pair of secret digital codes.

One code stays on your device, while the other helps WhatsApp check your identity. The private code does not leave the device. You confirm access with the same screen lock you already use, such as a fingerprint, face scan or PIN.

That process feels much like unlocking a phone. But WhatsApp never receives your fingerprint or face data. Your phone checks that information and sends back proof that you are the right person.

WhatsApp passkeys replace a code that can be intercepted with proof from a device you already control.

Why are WhatsApp passkeys safer than SMS codes?

SMS codes can be useful, but they have weak points. Criminals may trick a user into sharing a code. They may also persuade a mobile carrier to move a phone number to a new SIM.

This attack is called SIM swapping. It means a criminal takes control of your phone number by moving it to another SIM card. Once that happens, messages meant for you can reach the attacker.

Passkeys do not send the sign-in secret through a text message. They also resist phishing, which is a fake message or website designed to steal personal details. The passkey works only with the real WhatsApp sign-in request.

That does not make every account risk-free. Someone who unlocks your phone could still reach some accounts. Users should keep a strong screen lock and avoid sharing their device PIN.

How WhatsApp passkeys work on a phone

First, a user creates a passkey in WhatsApp’s account settings. The phone then stores the private part of the key. WhatsApp keeps the matching public part for future checks.

Later, the user starts a sign-in on a new phone. WhatsApp asks the trusted device to approve the request. The user confirms with a fingerprint, face scan or PIN, and the app completes the check.

Passkeys can also work across some devices through password managers. A password manager is an app that safely stores sign-in details. The exact options depend on the phone, operating system and account settings.

WhatsApp first began rolling out passkeys in 2023. The rollout gave users another choice beside SMS verification. The new milestone suggests that many people have adopted the option over roughly three years.

WhatsApp passkeys versus other sign-in methods

The main difference is where the proof comes from. SMS relies on a mobile network. A password relies on a secret that users must remember. A passkey relies on a trusted device and its screen lock.

Method What the user does Main weakness
Password Types a secret word or phrase Can be reused or stolen
SMS code Enters a code from a text Can be tricked or redirected
Passkey Uses a device lock or biometrics Needs access to a trusted device

The table shows why WhatsApp is pushing the feature. Passkeys remove two common trouble spots: remembering secrets and reading codes from messages. The trade-off is that users must protect their devices carefully.

WhatsApp passkeys milestone2023 rolloutNowNew feature1 billion+

What does the 1 billion figure mean?

The figure refers to people using passkeys on WhatsApp, based on the company’s statement. It does not mean that 1 billion passkeys were sold or that every WhatsApp account uses one.

A person may also have more than one passkey. For example, someone could use a phone and a tablet. So the user count and the total number of stored keys are not necessarily the same.

Even with that detail, 1 billion is a major scale marker. It is about eight times the population of India’s 2024 estimate, though the two numbers measure very different things. The comparison simply shows how large the security rollout has become.

What should WhatsApp users do now?

Users should open WhatsApp settings and look for the passkey option under account or security tools. The menu name may vary by phone. If the option appears, setup usually takes only a few steps.

Choose a screen lock you can protect well. Do not share your PIN, and keep your phone software updated. Also, review linked devices and remove any device you no longer recognise.

WhatsApp’s move fits a wider shift away from passwords. The FIDO Alliance’s passkey guide explains how the system aims to block phishing. The W3C WebAuthn standard describes the technology used by many passkey systems.

Passkeys are not a magic shield. But they make one of the easiest attacks much harder. For most users, that is a useful upgrade because the safest sign-in is often the one that requires the fewest steps.

FAQs

What are WhatsApp passkeys?

They are digital sign-in keys that let your phone confirm your identity. You approve access with a fingerprint, face scan or PIN.

How many people use WhatsApp passkeys?

WhatsApp says more than 1 billion people now use the feature. The company has not shared a country-by-country breakdown.

Why are passkeys safer than SMS codes?

They keep the secret on your trusted device. That makes code theft, phishing and SIM-swap attacks harder.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.