Meta rolled out passkey support enhancements for WhatsApp that allow users to register multiple passkeys to a single account across iOS and Android devices. The messaging platform now lets users authenticate using biometric or device-level credentials instead of passwords, reducing exposure to phishing attacks.
The update addresses a practical friction point for multi-device users. Previously, WhatsApp passkey support existed only on Android since October 2023. The new capability enables iOS users to link their accounts to passkeys for the first time, while Android users gain the ability to add multiple passkeys to one account. This matters because many people own both iPhone and Android devices or switch between them.
Passkeys replace traditional passwords with cryptographic credentials bound to a user's device. Instead of typing a password vulnerable to interception or credential stuffing, users authenticate with a fingerprint, face recognition, or PIN. The system uses public-key cryptography rather than shared secrets sent across networks. Phishing becomes nearly impossible since attackers cannot redirect passkeys to fake login pages.
Meta stated that over 1 billion WhatsApp users already rely on passkeys for authentication. This scale indicates substantial adoption of the phishing-resistant method across WhatsApp's 2 billion user base. The company positions this as a security foundation rather than an optional feature.
The multi-passkey feature solves a common scenario for users managing multiple devices. Previously, a user with an iPhone and Android phone would need to choose which device to authenticate with. Now they can register a passkey from each device, allowing seamless switching without re-authentication friction. This approach maintains security while improving usability.
Meta's passkey implementation aligns with broader industry momentum away from passwords. Apple, Google, and Microsoft collectively promoted passkeys through the FIDO Alliance. Major platforms including Dashlane, 1Password, and bitwarden now sync passkeys across devices, enabling authentication from any registered device without compromising security.
The announcement arrives as phishing remains the leading attack vector for account compromise. Threat actors use credential theft from phishing emails, fake login pages, and malware to access accounts at scale. Passkeys eliminate this entire attack class by design. A stolen passkey remains useless without physical access to the device that created it.
WhatsApp's position as a communication platform makes account security particularly urgent. Compromised accounts expose direct message histories, contacts, and could be used to impersonate users in conversations. Business users relying on WhatsApp for customer communication face additional risk from account takeover.
The passkey rollout extends to both iOS and Android gradually, typical of Meta's staged deployment approach. Users gain access to manage multiple passkeys through account settings. The implementation leverages native biometric APIs on each platform, using Face ID and Touch ID on iOS and fingerprint or face unlock on Android.
This move represents incremental progress toward passwordless authentication at consumer scale. While passkeys remain less common than passwords, adoption accelerates as major platforms implement support. WhatsApp's integration with over 1 billion existing users signals that phishing-resistant authentication has reached mainstream viability. Organizations considering passkey deployment now have evidence of consumer familiarity and expectations around the technology.
