Cybersecurity

How Do I Remove a Passkey from a Lost or Old Device?

Published by PHWhy Editorial · 4 min read · Updated August 23, 2026
Prepared under our editorial standards; local service details are checked against official provider guidance.
Natural editorial photo for Cybersecurity technology guides by PHWhy

A passkey is tied to a device or credential manager, so deleting one safely involves two separate checks: the online account that accepts the passkey and the place where the credential is stored. If a phone or laptop is lost, start by securing that device. If it is simply being sold or retired, confirm that another sign-in method works before removing anything.

Short answer: sign in from a trusted device, remove the old passkey in the account’s security settings, review active sessions, and then delete the matching credential from your password manager if it remains there. Create and test a replacement before wiping an old device you still control.

First decide whether the device is lost or just being replaced

For a lost or stolen phone, use the platform’s official lost-device tools to lock or erase it when possible. Also contact your mobile carrier if the SIM may be at risk. Do not wait for the passkey cleanup before protecting email, banking, social and other high-value accounts.

For a phone or computer that you still have, keep it connected until you can sign in on the replacement. A factory reset normally removes local credentials, but it should be the final step, not the first one.

Make sure you have a working way back into the account

Use another trusted phone, computer, hardware security key, recovery code or the provider’s account-recovery flow. Never share an OTP, recovery code, device PIN or QR code with someone offering to help. If a site provides a “try another way” option, use it only on the provider’s real website or app.

If you are new to the terminology, read what a passkey is and when to use one before changing several sign-in methods at once.

Remove the passkey from the online account

Open the account’s security or sign-in settings and look for Passkeys, Security keys, or Sign-in methods. Select the entry that matches the old device and remove it. Device names can be vague, so compare the creation date, last-used date and platform before confirming.

Google’s current instructions place passkeys under Google Account → Security & sign-in → Passkeys and security keys. Google also notes that an automatically created Android passkey may require signing that device out under “Your devices.” Other services use different menus, so follow the provider’s own account page rather than a generic third-party tutorial.

Check the password manager or device credential store

Removing a passkey from the service invalidates it for that account, but an old entry can still appear in a credential manager. On current iPhones, Apple says passkeys are visible in the Passwords app; you can open Passkeys, choose the account, tap Edit and delete the passkey. With iCloud Keychain enabled, that change can sync to your other Apple devices, so confirm that you selected the old entry.

Android, Windows and third-party password managers can store passkeys differently. Open only the credential manager you already use, find the account by its website name, and remove the stale entry if it is still listed. Do not install a “passkey cleaner” or unknown browser extension.

Review sessions and recovery details

Removing a passkey does not automatically end every existing login session. Review the account’s signed-in devices, sign out unfamiliar or lost devices, and check the recovery email and phone number. Change the password if the provider recommends it after a theft or if someone may know it. Also review recent security activity for changes you did not make.

Create and test a replacement passkey

Create the new passkey only on a device you personally control and protect with a strong screen lock. Test it in a private browser window or on another device, while keeping one backup sign-in method available. Two independent recovery options are safer than relying on a single phone.

Do not photograph recovery codes or save them in an unprotected notes app. Store them offline or in a reputable password manager, and never keep the only recovery copy on the same phone that holds the passkey.

What if the old passkey still appears?

Allow a short time for synchronization, then refresh both the account security page and the password manager. Check whether the same account has more than one passkey with similar device names. If sign-in prompts still point to the removed credential, use another sign-in option and consult the provider’s official support page. Avoid repeated account-recovery attempts from many devices, which can make an already stressful situation harder to diagnose.

Official sources

Checked against official provider guidance on August 23, 2026. Menu names can vary by operating-system version and account type.

Share this guide

Help someone else find this answer.

Facebook X WhatsApp Telegram