A new phone should not turn an ordinary sign-in into an account recovery project. Passkeys can make access easier, but it pays to understand the escape route before you need it.
The unlock screen is not the credential
When you approve a sign-in with a fingerprint, face scan or device PIN, you authorise the use of a cryptographic credential. The website does not receive your fingerprint. Unlike a reusable password, a passkey is tied to the service it was created for, which helps resist phishing.
That does not make every account problem disappear. A lost device and a convincing message from a scammer are different problems, with different recovery steps.
Find out where it lives
A synced passkey can be available through its provider on other supported devices. A device-bound passkey stays with a particular device or hardware security key. The word “passkey” on a settings page does not tell you which arrangement you have.
Open the account settings while you are still signed in. Note the provider, any registered security keys and the recovery methods offered by this particular service. Do not assume that two websites behave alike.
Rehearse a second way in
Try a supported sign-in from another device you own. Keep the original session open until the test succeeds. If the service offers recovery codes or another credential, store them somewhere you could reach without the missing phone.
A useful question is: “If this phone were unavailable this afternoon, what would I actually use?” An answer that depends on a code stored only on that phone needs work.
When the phone really is missing
Use the service’s official recovery instructions from a trusted device. Review signed-in devices and remove access that should no longer remain. Changing one password is not a substitute for checking the account’s sessions and recovery settings.