Passwordless Login Explained: Magic Links, Passkeys and Biometrics

More services let you sign in without typing a password. They are not all equally secure.
Magic links
The site emails you a one-time link. It is simple, but your email account becomes the key, so it must be well protected. Links can also be intercepted if your mailbox is compromised.
One-time codes
A code sent by SMS or email proves you control that phone or inbox. Convenient, but codes can be phished or intercepted.
Passkeys
A cryptographic key on your device, unlocked by fingerprint, face or PIN. Passkeys resist phishing and cannot be reused, making them the strongest option in this list.
Biometrics
A fingerprint or face scan is usually a way to unlock a key on your device, not the key itself. The biometric data typically stays on the device.
Which to use
- Passkeys where available.
- Magic links only if your email has strong 2FA.
- Avoid SMS codes for high-value accounts if you have a better choice.


