Passkeys went mainstream in 2025 and 2026. Google, Apple, Microsoft, banks and many SaaS products now push them as the default sign-in, and password managers sync them across devices. For anyone who shares sensitive documents, such as tax papers, contracts or medical records, this changes the safest way to do it.
What a passkey is
A passkey replaces a password with a cryptographic key pair. The private key stays on your device or in your password manager; the website stores only the public key. You unlock it with your fingerprint, face or device PIN.
Two properties matter for document security:
- Phishing resistance. A passkey only works on the real site it was created for. A lookalike login page cannot capture it.
- Nothing to leak. A breach of the website exposes public keys, which are useless to attackers.
Why this matters for sharing documents
Most document leaks are not clever hacks. They are phished logins to an email account or a cloud drive. If the portal where clients upload or download documents uses passkeys, the most common attack against it stops working.
So the safest pattern for sensitive files in 2026 is often: put the document in a portal or cloud folder protected by passkeys, and share access, not attachments.
When a password-protected PDF still makes sense
Portals are not always practical. You might be sending one document to someone who will never log in to your system. A password-protected PDF is still a good tool when:
- The recipient does not have an account anywhere you control.
- The document must travel by email or messaging.
- You want the file to stay protected after download.
Use AES-256 encryption, a long random password, and send the password through a different channel, such as a text message or a phone call. See how to password protect a PDF and AES-128 vs AES-256.
Comparing the options
| Method | Protects against phishing | Protects the file after download | Recipient effort |
|---|---|---|---|
| Portal with passkeys | Strong | No | Account needed |
| Cloud link with sign-in | Depends on sign-in method | No | Low |
| Password-protected PDF | Weak (password can be phished) | Yes | Password needed |
| Plain email attachment | None | No | None |
The strongest setups combine methods: a passkey-protected portal, and an encrypted PDF inside it for the most sensitive files.
Habits that matter more than technology
- Expire links. A shared link from three years ago is still a shared link.
- Remove hidden data before sharing. See how to strip metadata from a PDF.
- Redact properly rather than drawing black boxes. See PDF redaction failures.
- Turn on passkeys for your own email and cloud storage. If your inbox is safe, most of your documents are too.
Takeaway
Passkeys make the accounts that hold your documents far harder to steal. Share through passkey-protected services where you can, keep encrypted PDFs for the cases where files must travel, and prepare the file itself locally before it goes anywhere. A browser editor like Docento.app can password-protect a PDF without uploading it. See also how to share a PDF securely.