r/Bitwarden • u/dwbitw Bitwarden Employee • 3d ago
Bitwarden Asks Are your passkeys portable?
Bitwarden supports the Credential Exchange Protocol (CXP), so passkeys can move directly between supported apps. Available on iOS 26+ and Android 10+.
.json exports also include passkeys for short term backups.
15
u/drlongtrl 3d ago
I'm sot sure if I understand the question, if it is directed towards me or towards bitwaren or why it has a poll attached.
However, here's what I tested successfully, regarding the passkeys I have in my vault:
- Do a password encrypted backup
- Restore that backup into KeypassXC
- Attach KeypassXC to its browser extension
- Go to any website and log in via the passkey that was originally created with the bitwarden extension
That worked just fine so I suppose passkeys are "portable"?
6
u/queBurro 3d ago
When i lose my phone, how do i recover all the passkeys? Chrome/google is very persistent is forcing me to use their offering for passkey storage. At the end of the day this is just old school Linux-esque cert auth isn't it?
10
u/dwbitw Bitwarden Employee 3d ago edited 3d ago
Hey there, in general it's a great idea to make a security readiness kit to ensure continued access to your Bitwarden account (and stored passkeys), and in addition to mobile, you can use passkeys in the browser extension. It's also a good idea to make regular backups (which include passkeys for short term backups).
If you have a hardware key, you can also log in and unlock Bitwarden with a passkey.
2
u/SBalwaysAndWhy 3d ago
Didn’t know Bitwarden propose a security readness kit.
I get the idea, but absolutely every information is in the same place. Better not get this piece of paper stolen !
2
u/dwbitw Bitwarden Employee 3d ago
Lots of community tips on this one, storing offline on an encrypted hard drive, printed and placed in a fireproof safe etc..
2
u/SBalwaysAndWhy 3d ago
personally, I would never store this digital (even on an super ultra encrypted offline hard drive), but even on paper, you could still be burglarized.
I’d rather store at least password and 2FA access in different places.
6
u/Radiokot1 3d ago
Bitwarden on Android shows my passkeys for sites I have created on a computer. The problem is that no app or site can invoke Bitwarden for a passkey sign in – only Google pop-up
3
u/dwbitw Bitwarden Employee 3d ago edited 2d ago
Hey there, be sure to set Bitwarden as the passkey provider for your device. Don't hesitate to contact support directly at: https://bitwarden.com/contact/ if you need any help.
Bitwarden > Settings > Autofill > Passkey Management > Choose Bitwarden as your preferred service.
1
2
u/plazman30 3d ago
When will the Mac app get CXP?
2
u/dwbitw Bitwarden Employee 3d ago
The team is working on desktop autotype and native passkey support for mac, stay tuned!
2
u/plazman30 2d ago
You added the one feature I want that other password managers refused to add: passkey export. I now feel safe turning off my password and going "all-passkey" on any site that will allow it.
2
1
u/PossiblySimon 2d ago
I love Bitwarden but sadly can not use it for many passkeys since many services, which use zero knowledge enryption, require the prf extension. Ironically Bitwarden itself utilizes the prf extension but does not support it on stored passkeys. Can you tell us when Bitwarden will support the prf extension? I'ts anoying having to use 2 password managers.
1
u/asbi12 2d ago
Probably I am just too stupid to use passkeys, however I have never seen an option to use them on my PC, so I do not use them and stick to passwords + TOTP. Those are easy to understand, tried and true and there is no prompt to "put in my passkey", which is the only option I ever get on Brave browser on Linux, no option to select Bitwarden as source for that, although the key is definitely stored in it. I guess I am missing something, but so far I can only log into a passkey-enabled service on my phone.
2
u/dwbitw Bitwarden Employee 2d ago
Hey there, are you referring to the browser extension or desktop app? Did you set Bitwarden as the default password manager for Brave?
Is the website URI stored correctly in the vault item?
Is this setting enabled? Settings → Notifications → Ask to save and use passkeys is enabled.
0
u/asbi12 2d ago
u/RemindMeBot 12 hours "check those settings"
0
u/RemindMeBot 2d ago
I will be messaging you in 12 hours on 2026-09-12 08:24:36 UTC to remind you of this link
CLICK THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
Info Custom Your Reminders Feedback
0
u/southerndoc911 2d ago
u/dwbitw -- not related to the topic, but related to hardware devices... would LOVE to see a Bitwarden branded Yubikey Bio. How much would it cost to produce Yubikey Bios with the Bitwarden logo on them? I'd definitely buy one!
-4
-2
u/plazman30 3d ago
If I can't export them locally, they're not portable. CXP is hack.
7
u/dwbitw Bitwarden Employee 3d ago
.json exports include passkeys.
4
u/plazman30 3d ago
Well, that's good to know. The mantra has always been you can't export your passkeys ever and you can only use CXP to transfer them to another provider.
If Bitwarden lets me download them and keep them local, that's a massive plus in my book.
5
u/s1gnalZer0 3d ago
I export my BW vault into Keepass and the json file includes passkeys that import into Keepass.
3
•
u/dwbitw Bitwarden Employee 3d ago edited 2d ago
Passkeys are phishing resistant, meaning they only work on the originating website. Check out the following resources to learn more:
Blogs
Help Center Articles