Using Passkeys and 2FA in Proton Pass: A Practical Walkthrough

A password manager stops you from reusing weak passwords, but the login itself can still be stolen through phishing or a database leak. The next layer of defense is two-factor authentication — and, increasingly, passkeys, which remove the password from the equation entirely. Proton Pass supports both, with a built-in authenticator and native passkey storage, which is why this guide exists: to turn those features from checkboxes into a working security upgrade you can complete in one evening.

Passwords Alone Are No Longer Enough

Even a unique, strong password has two weaknesses. First, it must be typed into a website — which is exactly what phishing pages imitate — so it can be handed to an attacker who is pretending to be that site. Second, it can leak: servers are breached, databases are dumped, and passwords hashed carelessly are cracked offline. Two-factor authentication addresses the first weakness by requiring a second proof that rotates every login, and passkeys address both by never sending a reusable secret to the website at all.

The practical reality for most people is that 2FA was always too much friction: opening a separate authenticator app, finding the right entry, retyping a six-digit code before it expires. That friction is the reason billions of accounts remain protected by nothing but a password. Removing the friction is the whole point of how Proton Pass approaches this problem.

What a Passkey Is, in Plain Language

A passkey is a pair of cryptographic keys created for one website. The private key stays on your devices and never leaves them; the website only ever stores the matching public key. When you sign in, the site sends a challenge that only your private key can answer, and your device unlocks the key with biometrics or a PIN. Nothing phishable is ever typed into a form, and there is no shared password that a breach of the website could expose.

The catch has always been synchronization: a passkey saved only on one phone is a single point of failure. This is why storing passkeys inside a synced vault matters. Proton Pass syncs your passkeys across every device where you sign in, end to end encrypted, so a passkey created on your laptop works on your phone and survives the loss of either device.

Storing and Using Passkeys in Proton Pass

Using passkeys with Proton Pass follows the same rhythm as any other login. When a website offers to create a passkey, your browser or system dialog lets you choose where to save it; select the Proton Pass extension or app. The passkey is stored as part of the item for that website, encrypted alongside everything else, and it syncs to your devices automatically.

  • Create: on the website, choose "Use a passkey" and save it into the Proton Pass item.
  • Sign in: when the site asks for the passkey, confirm with biometrics or your PIN.
  • Sync: the passkey is available on every device where you use the same vault.
  • Share: shared vaults can include passkeys, re-encrypted for each member.

A sensible strategy is to convert your most important accounts first — email, banking, cloud storage, social media — because those are the targets of account-takeover attacks. Sites that do not support passkeys yet should get traditional passwords plus one-time codes, which brings us to the second half of the upgrade.

The Built-In Two-Factor Authenticator

For every account that still uses a password, Proton Pass can generate TOTP one-time codes right inside the login item. During setup, scan the QR code the website shows you; from then on, a fresh six-digit code appears next to the saved login and refreshes every thirty seconds. Autofill can even copy the code together with the password, so enabling 2FA on a new account takes one extra tap instead of an app switch.

Because the seeds that generate those codes live in the same encrypted vault, they sync to all of your devices just like passwords. If your phone is lost, the codes are not lost with it — they are waiting in the vault on every other device, protected by your account credentials. This removes the classic fear that a lost authenticator app means being locked out of everything.

Securing Your Own Account First

The vault that holds all of this is protected by your Proton Account, so the account itself deserves the strongest settings you can apply. Enable two-factor authentication for the account, choose a recovery method such as a recovery phrase, and consider advanced protection features like Proton Sentinel, which flags suspicious sign-in behavior. It makes little sense to arm every website with passkeys and leave the front door of the vault on a single factor.

One habit completes the picture: keep the recovery phrase offline, written down like the emergency key it is, rather than stored inside the vault it is supposed to rescue. Recovery exists for the day something goes badly wrong, and that day is the wrong day to discover the recovery method was never set up at all.

A Sensible Order of Upgrades

You do not need to do everything at once. A realistic path looks like this: first, enable the built-in authenticator for your ten most important password logins; second, switch your email accounts to passkeys; third, work through the remaining accounts as you visit them naturally. Within a few weeks the majority of your digital life will resist both phishing and leaks — without any day feeling like a security project.

If you are just starting out, sign in once and let the ProtonPass vault guide the way: every feature described here is available from the same encrypted space, and the order in which you secure your accounts matters far less than the fact that you start today.

Passkey storage and one-time codes generated inside Proton Pass
Passkeys, one-time codes and account protection work together in Proton Pass to make strong security feel effortless.