Passkeys on Linux: Browsers, Password Managers, and Security Keys

Passkeys on Linux: Browsers, Password Managers, and Security Keys

Passkeys replace passwords with a key pair: the private key stays on your device, the website only stores the public key, and signing in means proving you hold the private key. They cannot be phished, reused, or leaked from a server breach. Every major site that matters now supports them.

On Windows and macOS, the operating system stores passkeys for you. Linux has no built-in passkey store, which confuses people the first time a site offers to “create a passkey” and nothing obvious happens. Passkeys work fine on Linux; you just choose where they live.

How passkeys work, briefly

Passkeys are built on the WebAuthn and FIDO2 standards:

  1. When you register, your device generates a key pair for that site only
  2. The site stores the public key
  3. To sign in, the site sends a challenge, your device signs it with the private key after you unlock it (PIN, fingerprint, or touch), and the site verifies the signature

The signature is bound to the site’s real domain, so a phishing site on a lookalike domain gets nothing usable. That is the key advantage over TOTP codes, which a fake login page can relay in real time.

Where passkeys can live on Linux

OptionSyncs between devicesPhishing-resistantBest for
Password managerYesYesMost accounts, most people
Hardware security keyNo (device-bound)Yes, strongestEmail, password manager, admin accounts
Your phone (hybrid)Via the phone’s ecosystemYesOccasional use from a Linux machine

Option 1: a password manager

Password managers with passkey support store them alongside your passwords and sync them everywhere:

  • Bitwarden (and self-hosted Vaultwarden), through the browser extension
  • 1Password, through the browser extension
  • KeePassXC, which stores passkeys in your local KeePass database, used through its browser integration; see KeePassXC and the 2.8 beta news

When a site offers to create a passkey, the extension intercepts the request and saves it. This is the most convenient option and solves the backup problem, since your passkeys are in your encrypted vault.

Option 2: a hardware security key

A FIDO2 security key, such as a YubiKey, Nitrokey, or SoloKey, holds passkeys in tamper-resistant hardware. You plug it in (or tap it on NFC) and touch it to sign in.

On Linux, the browser needs permission to talk to the key. Most distributions handle this with udev rules from libfido2:

sudo apt install libfido2-1 fido2-tools   # Debian / Ubuntu
sudo dnf install libfido2 fido2-tools     # Fedora
sudo pacman -S libfido2                   # Arch
fido2-token -L                            # should list your key

If the browser does not see the key, unplug it and reconnect after installing. Our udev rules guide explains what those rules do.

Set a PIN on the key so a stolen key alone is not enough:

fido2-token -S /dev/hidraw0     # path from fido2-token -L

Security keys hold a limited number of passkeys (typically dozens to a hundred or so), and they do not sync. That is a feature for your most important accounts: there is no copy anywhere else to steal.

Option 3: your phone

Chromium-based browsers on Linux support the hybrid flow: the browser shows a QR code, you scan it with your Android phone or iPhone, and the two devices complete the sign-in over Bluetooth. Your passkey stays on the phone, synced through Google Password Manager or iCloud Keychain.

It needs working Bluetooth on the Linux machine; our Bluetooth on Linux guide helps if not. Firefox’s support for the hybrid flow on Linux has lagged behind Chromium’s, so if the QR option does not appear, try a Chromium-based browser.

Avoiding lockouts

Passkeys are only as recoverable as where you keep them:

  • For any account with a single hardware key as its only passkey, register a second key and keep it somewhere safe
  • Keep recovery codes for important accounts, stored offline or in your password manager
  • Protect your password manager itself with a hardware key or a strong master password plus a passkey, since it now holds everything

Passkeys for your own services

Self-hosted apps can use passkeys too. Pocket ID is a passkey-only single sign-on provider for your homelab: log in once with a passkey and reach every app that supports OpenID Connect. For SSH, the same security keys work as hardware-backed SSH keys; see our two-factor SSH guide.

Frequently Asked Questions

Do passkeys work on Linux?

Yes. Firefox and Chromium-based browsers on Linux support WebAuthn, the standard behind passkeys. What Linux lacks is a built-in operating system passkey store, so passkeys are kept in a password manager, on a hardware security key, or on your phone instead.

Where should I store passkeys on Linux?

For most people, a password manager that supports passkeys, such as Bitwarden, 1Password, or KeePassXC, is the most practical choice because the passkeys sync across devices and are backed up. Hardware security keys are the most secure option for important accounts like email and your password manager itself.

Why does my browser not detect my YubiKey on Linux?

Usually because of device permissions. Your user needs access to the key’s hidraw device, which is normally granted by udev rules from the libfido2 package or your distribution. Install libfido2 or the u2f udev rules package, unplug and reconnect the key, and try again.

Can I use my phone as a passkey for a Linux computer?

Yes, through the hybrid flow. The browser shows a QR code, you scan it with your phone, and the phone and computer connect over Bluetooth to complete sign-in. Chromium-based browsers support this on Linux, and the computer needs working Bluetooth.

What happens if I lose the device holding my passkey?

If the passkey was synced through a password manager, nothing is lost. If it was on a single hardware key, you need another way in, which is why you should register at least two security keys or keep recovery codes for every important account.

Are passkeys more secure than passwords with 2FA?

Generally yes. Passkeys cannot be phished because they are bound to the real website’s domain, there is no shared secret on the server to steal, and they cannot be reused across sites. TOTP codes, by contrast, can be phished in real time by a fake login page.