RESOURCE / EN

Passkey and MFA migration checklist

A safe path to passkeys or new MFA: critical accounts, backup sign-in, a second key, recovery codes, and an emergency test.

First read how passkeys, security keys, SMS, and TOTP differ. Then work through this list one account at a time. Do not disable the current sign-in method before testing a fallback.

Critical accounts

  • I list my primary email, password manager, Apple/Google/Microsoft account, bank, mobile carrier, and important social accounts
  • I start with a less critical account so I can learn the process without risking access to my main email
  • For each account, I record the available methods: passkey, security key, TOTP app, SMS, password, and support-assisted recovery
  • I verify the official domain and open security settings there — I do not set up a passkey from a link in a message

A backup route in

  • I add a passkey on the first device but keep the current working method
  • I add an independent recovery route: a second physical key, recovery codes stored away from the phone, or a device that does not depend solely on the same syncing account
  • I store the second key or device separately, not in the same bag as my phone and laptop
  • I identify the provider account that syncs my passkeys and confirm I can recover that account
  • The recovery phone number and backup email belong to me and are current

Recovery codes

  • I generate fresh recovery codes after changing MFA if the service offers them
  • I keep them away from the phone: a printout, sealed envelope, or encrypted store reachable from another device
  • I do not keep the only photo of the codes on the phone those codes are meant to replace
  • I label the account and date without writing the password on the same sheet

Emergency test

  • I open a new private browser session and sign in with the passkey
  • I sign out of the test session and try the second device or second key
  • I locate the controls for revoking a lost passkey, key, and active sessions
  • I read the provider’s recovery procedure; I do not start it merely as a test if it could lock the account
  • Only after a successful test do I remove an old method I no longer want

Keep it working

  • I repeat the test after changing my phone, number, primary email, or password manager
  • Every few months I review devices, passkeys, and active sessions
  • A household member or emergency contact knows where the backup is — they do not need my password

A fallback stored on the lost laptop is not independent. Protect device data with full-disk encryption. For an organisation, dependencies and recovery paths can be reviewed as part of cybersecurity.

Want this implemented or scoped?

The resource stays open. The form is for implementation, not an email gate.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.