All posts
Password managers3 min read

Passkeys help you unlock. They rarely help your family.

Passkeys are excellent while you are alive. Here is what they do not solve for inheritance, how they differ from TOTP and password managers, and what to set up so someone you trust is not stuck at a biometric wall.

Soft illustration of a phone with a biometric mark beside a small vault, sealed envelope, and security key

Passkeys are having a good run, and for good reason. Phishing resistance, no shared password to type, unlock with Face ID or a hardware key. For your own daily life they are often better than what they replace.

They are also easy to misunderstand as an inheritance plan. They are not one.

What a passkey is tied to

A passkey is a credential bound to a device, a password manager, or a platform account (iCloud Keychain, Google Password Manager, Windows Hello, a YubiKey). You prove possession, often with biometrics on that device. The site never gets a password it can leak in the old way.

That design is the point. It is also why "just leave them the passkey" usually fails. Your face and fingerprint do not transfer. A key that lives only in your phone's secure enclave does not open for your spouse because they loved you. A hardware key in a drawer helps only if someone knows it exists, has the PIN if there is one, and the accounts still accept that key.

Where inheritance breaks

Platform passkeys stay in the platform. Apple Legacy Contact and Google Inactive Account Manager can help with some iCloud or Google data. They are not a universal "hand every passkey to my kids" switch. Coverage is uneven and slow compared with week-one account work.

Password-manager passkeys follow the manager's recovery path. If 1Password or Bitwarden holds the passkey, family recovery or emergency access may help. If the passkey never left the phone OS, that path does not exist.

Biometrics are for you, not for them. Useful while you can unlock the device. Useless as the only factor once the device is a brick to everyone else.

HeirVault passkeys unlock your vault for you. On HeirVault, a PRF-capable passkey can unlock the live vault on a trusted device. That is convenience and phishing resistance for the owner. It is not how beneficiaries claim. They use the claim path you set up, not your Face ID.

What to do instead

Keep using passkeys. Just do not let them be the only story.

  1. Know where each important passkey lives. Phone only, password manager, or hardware key. Write that down in plain language.
  2. Prefer recoverable homes for the accounts that matter. A password manager with a real emergency or family recovery path beats a lone phone keychain for anything your people might need.
  3. Keep a non-biometric backup for critical accounts. Recovery codes, a second hardware key, or a password-plus-TOTP path you have tested. See what happens to 2FA codes.
  4. Turn on the platform legacy tools you already pay for with your attention. Apple Legacy Contact and Google Inactive Account Manager are free and still underused.
  5. Separate "how I unlock today" from "what they receive later." Passkeys are the first. Instructions, documents, and credentials for claim are the second.

Where HeirVault fits

HeirVault is for the second job. You leave docs, logins, bank details, and files for people you name. They claim after missed check-ins and the waiting period. Your live vault is protected by end-to-end encryption and encrypts in your browser before upload. That means HeirVault stores ciphertext and cannot decrypt your live vault.

Your own passkey can make unlocking HeirVault nicer day to day. Beneficiaries do not inherit that passkey. They get what you assigned, through claim, which is the point.

Start free, or read how it works if you want the release path without the sales pitch.

The short version

Passkeys make you harder to phish. They do not automatically make your family able to get in. Put the important credentials somewhere recoverable, keep a backup that does not require your face, and write down where the keys actually live.

This is general information, not legal advice. Rules differ by country and state. Talk to a qualified professional about your own situation.

Ready when you are

Not for scare. For dignity. HeirVault keeps your documents, logins, and files encrypted in your browser. When you cannot hand things over, only the contacts you name can claim them.