A passkey can be stored on a device, security key or synchronized provider. Losing a phone does not always mean losing the account, but the recovery route depends on where the passkey lived and what other methods are available. Anyone who can unlock a lost device may also be able to use a passkey on it, so act promptly.
Recover and reduce exposure
- From a trusted device, open the normal Google sign-in page. If the missing passkey is offered, choose Try another way and use an existing password, another passkey or a recovery method. Do not enter account details into a link from a stranger offering “passkey recovery.”
- Once signed in, review the account's passkey list and remove the passkey associated with the lost or stolen device. Also inspect signed-in devices and end sessions that should no longer be trusted.
- If the device was lost, use the platform's find or lock feature where available and secure your mobile number and recovery email. A removed passkey is only one part of securing the device and account.
- Create or verify a replacement sign-in method on a device you control, then perform a normal sign-in test. Keep recovery codes or another factor accessible without the original device.