WhatsApp Embraces Multi-Passkey Authentication
Meta has announced a significant upgrade to WhatsApp's account security model: users can now register multiple passkeys to a single account, enabling seamless phishing-resistant sign-in across both iOS and Android devices. The move expands on WhatsApp's earlier passkey rollout and positions the platform among the most security-forward consumer messaging apps available.
What's New
The updated feature set introduces several key capabilities:
- Multiple passkeys per account: Users with both an iPhone and an Android phone can now register a passkey on each device, eliminating the need to choose a primary device or fall back to SMS verification when switching platforms
- Cross-platform coverage: Support spans iOS (using Face ID / Touch ID with iCloud Keychain) and Android (using biometrics with Google Password Manager or third-party passkey managers)
- Phishing-resistant by design: Passkeys use the FIDO2/WebAuthn standard, meaning credentials are cryptographically bound to the legitimate WhatsApp domain — a phishing site cannot intercept or replay them
- No shared secrets: Unlike passwords or SMS OTPs, passkeys never leave the user's device in a form that could be stolen from a server
Why This Matters
More than 1 billion people use passkeys globally, according to Meta, and WhatsApp sits at the center of some of the most sensitive conversations in users' lives — from personal communications to business dealings and financial coordination.
The previous single-passkey limitation created friction for users who regularly switch between iOS and Android devices (common in markets where users carry dual SIMs or upgrade between ecosystems). Multi-passkey support removes that barrier and makes passkeys practical for the full WhatsApp user base.
Passkeys vs. Traditional Authentication
| Method | Phishing Resistant | Server Breach Risk | User Friction |
|---|---|---|---|
| Password | No | High | Medium |
| SMS OTP | No | Medium (SIM swap) | Medium |
| TOTP (authenticator app) | Partial | Low | Medium |
| Passkey | Yes | None | Low |
Passkeys represent the strongest widely-deployable authentication mechanism for consumer apps, combining strong cryptographic security with a familiar biometric UX.
The Broader Passkey Wave
WhatsApp's expansion joins a growing roster of major platforms that have adopted passkeys as a primary authentication method:
- Apple — passkeys integrated across iCloud Keychain and supported in Safari
- Google — passkeys available for Google accounts on Android and Chrome
- Microsoft — passkey support across Microsoft 365 and consumer accounts
- GitHub, Shopify, PayPal, Amazon — all have deployed passkey sign-in for users
The FIDO Alliance estimates that passkey-capable accounts have surpassed 13 billion globally, marking a genuine inflection point in the shift away from passwords.
How to Enable Passkeys on WhatsApp
- Open WhatsApp and go to Settings
- Tap Account → Passkeys
- Select Create Passkey and authenticate with your device biometrics
- Repeat on any additional device to register multiple passkeys
For users who have already registered a passkey on one platform, the new multi-passkey flow allows adding a second without removing the first.
Security Recommendations
- Enable passkeys on WhatsApp as soon as the update is available in your region
- Register a passkey on each device you regularly use to avoid SMS OTP fallbacks
- Use a reputable passkey manager (iCloud Keychain, Google Password Manager, or a third-party like 1Password / Bitwarden) for backup and cross-device sync
- Disable SMS OTP fallback where possible to close the weakest link in your authentication chain