X-Autopilot

X passkey: how to log in without a password

X passkeys let you sign in with Face ID or a fingerprint instead of a password. The exact setup path, the 2FA confusion, and the lockout nobody warns you about.

X-Autopilot Team··9 min read
On this page · 9 sections

The short version

  • ▸A passkey on X replaces the password at the login screen, not on the account. You still have a password, you still need it to add or remove the passkey, and X files the feature under Additional password protection rather than under two-factor authentication.
  • ▸Setup lives in the X app: Settings and privacy, then Security and account access, then Security, then Passkey under Additional password protection. X documents the flow for the iOS and Android apps only.
  • ▸Passkeys are WebAuthn credentials, so the private key never leaves your device and X only ever stores the public half. That is why a passkey cannot be phished the way a password can.
  • ▸Passkeys are bound to the domain they were created on, which is why the move to x.com broke them. X made every account using a security key or passkey for 2FA re-enroll by November 10, 2025, and missing that date is still a common hard lockout.
  • ▸A passkey is not a second factor. X's two-factor settings list three methods - text message, authentication app and security key - and a passkey is none of them, so keep real 2FA switched on alongside it.

The short answer

An X passkey lets you sign in with Face ID, Touch ID or your Android screen lock instead of typing a password. You create it in the X app: Settings and privacy, then Security and account access, then Security, then Passkey under Additional password protection. X will ask for your password once, then hand the rest to your device (X Help, accessed 2026-10-01).

Two things that page does not spell out, and that nearly every guide ranking for this gets wrong:

  • A passkey is not two-factor authentication on X. The 2FA screen offers text message, authentication app and security key. Passkey is a separate item in a separate section, and X never calls it a second factor.
  • It does not delete your password. The password stays on the account, you need it to add or remove a passkey, and it remains the fallback when the passkey is not offered.

The passkey is a better front door. It is not the whole lock.

What a passkey on X actually is

A passkey is a WebAuthn credential. When you enrol, your device generates a key pair: the public key goes to X, the private key stays on your hardware and is never sent anywhere. Logging in means your device signing a challenge from X to prove it holds the private half, which it only does after you unlock it with your face, fingerprint or device PIN. X's own wording is that "your passkey is never shared with X."

That design is the point. A password is a secret you can be tricked into typing into a convincing fake login page. A passkey cannot be handed over that way, because there is nothing to type and the credential is bound to the real domain. For an account that someone would like to steal - a creator account, a brand account, anything with a payout attached - that difference matters more than any password-strength advice.

What a passkey does not protect you from is a session you already handed away. Anything holding a live X session cookie is inside the account regardless of how you logged in, which is why reviewing which third-party apps still have access belongs in the same sitting as turning this on.

How to turn on a passkey on X

X documents this flow for the iOS and Android apps. The page is explicit that passkey "is now available on both iOS and Android."

  1. Log in to the X app with the account you want the passkey on.
  2. Tap Your account in the navigation bar.
  3. Open Settings and privacy, then Security and account access, then Security.
  4. Under Additional password protection, tap Passkey.
  5. Enter your password when prompted.
  6. Select Add a passkey and follow your device's prompts.

Step 6 is where your platform takes over. iOS offers to save the credential to iCloud Keychain, Android to Google Password Manager, and most third-party password managers can claim the prompt instead if you have them set as your credential provider. That choice decides whether the passkey syncs to your other devices or stays on this one, so make it deliberately rather than tapping through.

Removing one is the same path, ending in Delete a passkey. Do that before you sell or wipe the phone, not after.

The rollout history explains why your memory of this feature might be out of date: X shipped passkeys to US iOS users in January 2024, went global on iOS that April (TechCrunch, 9 April 2024), and added Android that August (Engadget, 14 August 2024). Guides written in between describe an iPhone-only feature, and some still do.

Passkey or security key: X has two of these, and they do different jobs

This is the single biggest source of confusion on this topic, and it is X's own settings layout that causes it. The word "passkey" shows up in two unrelated places.

Passkey (Additional password protection)Security key (Two-factor authentication)
Where it livesSecurity, under Additional password protectionSecurity, under Two-factor authentication
What it replacesYour password at the login screenThe code step after your password
Underlying techWebAuthn credential on your deviceWebAuthn credential on a key or device
Counts as 2FA on X?X does not describe it as a second factorYes, one of three documented methods
Can be your only method?No, the password stays on the accountYes, X allows a security key as the sole 2FA method

X's two-factor authentication page lists three methods and no more: text message, authentication app, security key. It also notes that a security key can stand alone, "without any other methods turned on." Passkey is absent from that page entirely.

So the honest reading is this: a passkey changes how you get past the password prompt, and a security key changes what happens after it. They can both be on at once, and on X they are configured in different screens. If you only want one thing, an authenticator app plus a strong stored password protects more than a passkey with 2FA switched off. Our walkthrough of X two-factor authentication covers the enrolment and the backup-code habit that actually saves accounts.

The lockout nobody warns you about

In late 2025 X finished moving the platform off its original domain onto x.com. Passwords and authenticator codes carried over fine. Passkeys and hardware keys did not, because a WebAuthn credential is cryptographically bound to the domain it was created on, so keys enrolled under the old domain simply stopped being valid.

X gave every account using a security key or passkey for 2FA a deadline of November 10, 2025 to re-enroll (Engadget, October 2025; the notice came from @Safety on X). Accounts that missed it were locked until the owner re-enrolled a key under x.com, switched to another 2FA method, or turned 2FA off.

If you are reading this because a YubiKey or a passkey that worked last year is being refused now, that is the likeliest cause, and it is not a forgotten password. Recover with a backup method first, then re-enrol. The settings deep links and the rest of the sign-in failure modes are in X login: sign in at x.com and fix what blocks you.

There is a second-order lesson in this for anyone who hoards credentials: a passkey is only as durable as the domain and the device it was minted against. Keep a path back that does not depend on either.

When a passkey is the right call, and when it is not

Worth doing if you log in mostly on one or two phones you control, you already use iCloud Keychain, Google Password Manager or a password manager that handles passkeys, and you keep 2FA on anyway. The daily win is small but real: no password typed into a login screen, and nothing for a phishing page to capture.

Hold off in three cases. If you sign in from shared or managed machines, the passkey will often not be available there and you will be typing the password regardless. If your credential provider is something you might stop paying for, moving passkeys between managers is still rough. And if you have never written down a 2FA backup code, do that first: the failure mode of passwordless login is not someone breaking in, it is you being locked out by a dead phone.

One habit regardless of which you choose. Review the active sessions list and sign out anything you do not recognise, then change the password if anything looks wrong. The order matters, and how to change your X password covers what a change does and does not log out. If you are in this article because something already looks off on the account, start with X account hacked? How to get it back instead.

Troubleshooting, by symptom

SymptomMost likely causeWhat to do
No Passkey option under SecurityOld app build, or you are in a browser rather than the appUpdate the X app and retry there; X documents enrolment in the app
Passkey refused at loginCredential enrolled under the old domainSign in with password plus 2FA, delete the stale passkey, add a new one
Passkey missing on a new phoneCredential was device-bound, not syncedSign in with password plus 2FA, then enrol a passkey on the new device
Prompt appears then cancelsAnother credential provider is claiming itSet your preferred provider in system settings, then retry
Works in Safari or Chrome, not in an app's in-app browserEmbedded browser cannot reach the credential storeOpen the sign-in in your real browser

Nothing in that table needs a third-party "login fixer," and search results for passkey problems are thick with tools offering to manage your X sign-in for you. Anything that stores or proxies your session is holding the account itself. Keep the credential on hardware you own.

If you run more than one account

Each account needs its own passkey, enrolled while logged in to that account. That is a small tax if you keep a personal account and a project account side by side, and it is worth paying: shared recovery paths are how a problem on one account becomes a problem on all of them. The ceiling on how many accounts you can keep signed in, and the switcher itself, are covered in how to switch between X accounts.

Multi-account setups also tend to be where automation creeps in, so the honest note belongs here. Browser-based engagement on X is not a sanctioned API path, and X's automation rules are worth reading yourself rather than trusting a vendor's summary. X-Autopilot runs on your own Mac inside your own logged-in browser session, so the session cookie stays on your machine instead of sitting in a cloud service: a smaller detection surface than a shared cloud IP pool and a delegated login, not an absence of risk. A passkey on the front door and a session you never hand out are the same instinct applied twice.

The one-line version

Turn the passkey on in the X app if you mostly log in from your own phone, keep your password stored and your authenticator app enrolled, and save a backup code somewhere that survives losing the device. Passwordless sign-in is a real upgrade against phishing. It is not a replacement for the second factor, and on X it was never filed as one.

Frequently asked

Answers indexed by Google + AI assistants.

What is a passkey on X?+

It is a login credential stored on your device that stands in for your password. X's help page describes it as a WebAuthn key pair: your device keeps the private key, X stores only the public key, and signing in means your device proving it holds the private half. In practice you tap Face ID, Touch ID or your Android screen lock instead of typing anything.

How do I set up a passkey on X?+

Open the X app and log in, tap Your account in the navigation bar, then Settings and privacy, then Security and account access, then Security. Under Additional password protection, tap Passkey, enter your password when prompted, then select Add a passkey and follow the system prompts. X documents the same path for removing one, via Delete a passkey.

Is a passkey on X the same as two-factor authentication?+

No. X's two-factor authentication page lists exactly three methods: text message, authentication app and security key. Passkey sits in a different place in settings, under Additional password protection, and X does not describe it as a second factor. Treat it as a better front door and keep an authenticator app enrolled behind it.

Does a passkey work for logging in to x.com in a browser?+

X only documents enrolment inside the iOS and Android apps, so the app is where you create the credential. Whether the passkey is then offered at a given browser sign-in depends on your platform's credential manager and whether that browser can reach it. If no passkey prompt appears on the web, fall back to your password and 2FA code rather than deleting anything.

Why did my X passkey suddenly stop working?+

The usual cause is the domain migration. Passkeys and hardware keys are cryptographically tied to the domain where they were enrolled, so credentials created under the old twitter.com domain stopped validating on x.com. X told affected accounts to re-enroll by November 10, 2025. Get back in with another method, then add the passkey again under x.com.

What happens to my X passkey if I lose my phone?+

It depends where the credential lives. Passkeys synced through iCloud Keychain or Google Password Manager come back when you sign in to that account on a new device. A device-bound credential does not, and the account's password plus your 2FA method is the route back in. Keep a 2FA backup code saved somewhere that is not the lost phone.

Related searches
x passkeyhow to use passkey on xx passkey logintwitter passkey setuphow to add a passkey to xlog in to x without a passwordx passkey not workingdelete passkey xis a passkey the same as 2fa on xwebauthnface id loginsecurity keytwo factor authenticationadditional password protectionx account security
DY
Deepak YadavBuilding X-Autopilot

Product designer and indie hacker. Runs the agent on his own X account every day and writes up what the data shows, including when it's inconvenient.

Follow on X →
Try X-Autopilot.
$199 once. No subscription, no monthly bill. Real Chrome on your Mac.
See pricing▶
Free PDF · the X Growth Playbook

The exact playbook we use to grow on X

The bio that converts, the daily reply loop, the posting cadence, and the tool stack, in one no-fluff PDF. Drop your email and it's yours.

No spam. Unsubscribe anytime.

Free tools

Try it yourself.

All free X tools →
Keep reading

Related posts.