What it means
A PayPal passkey is a credential used during sign-in, generally unlocked through the device's face check, fingerprint or PIN. An active session is an account connection that may already be open in a browser or app. Deleting a passkey changes future sign-in with that key, but an open session or unlocked device needs its own security review. PayPal says a lost-device owner may still use a password or one-time passcode, depending on available account routes.
A real-world example
A stolen phone has a protected passkey, but its PayPal app was left open and notifications appear on the lock screen. Removing the passkey from PayPal helps with future login but does not alone prove that past session exposure was harmless.
What to do
From a trusted device, regain access, add a tested replacement method, remove the lost passkey from PayPal and its credential manager, and review sessions, transactions, linked email and the device's remote-lock status.
The distinction that matters
A passkey is phishing-resistant for the sign-in it performs, not a guarantee that every device holding it is safe. PayPal does not receive your biometric template when you use the device unlock. A credential synced by a manager may have copies or account-level recovery routes, so secure the manager as well as PayPal. If an unauthorized transaction exists, report it promptly through the matching Resolution Center path instead of waiting to finish credential cleanup.
PayPal passkey support