What protects the account before losing a phone that holds Google passkeys
A lost phone can remove one convenient way to authenticate, but passkey and account recovery behavior depends on how your passkeys are synced and what other sign-in methods you kept. Confirm that another trusted device or recovery path may complete sign-in prior to you retire the existing credential. List the password, passkey, authenticator, phone or trusted-device methods that still work and avoid removing the last usable factor.
Immediate sign-in risk during losing a phone that holds Google passkeys
The physical device is no longer under your control, so secure it or remotely erase it where possible. Store recovery material outside the browser. Make the first access risk of losing a phone that holds Google passkeys observable: test sign-in before the change and repeat it after the old factor is altered.
Keep a recovery path through losing a phone that holds Google passkeys
You may still sign in through other passkeys, traditional credentials or account recovery methods if configured. Keep one independent recovery route working. Once the loss of the phone that has your Google passkeys is visible, test a signed-out login afterward. Do not rely on an untested fallback during losing a phone that holds Google passkeys; complete a recovery check now and preserve an independent method afterward.
Protect recovery material before losing a phone that holds Google passkeys
Billing is unaffected by losing the device. Test the fallback from another device. Before losing a phone that holds Google passkeys, verify where recovery codes live and which trusted devices remain usable after the security change.
Sessions and connected apps around losing a phone that holds Google passkeys
Someone who can unlock the lost device may pose an account-security risk. Before finalising the Google-passkey device-loss plan, try a signed-out or second-device recovery check. Review active sessions and connected apps before losing a phone that holds Google passkeys; close obsolete sessions and verify the remaining integrations after the change.
Losing a phone that holds Google passkeys: verify sign-in from a clean session
Keep more than one recovery method. Remove the lost device from trusted-device lists. Save backup codes away from the phone. Once the loss of the phone that has your Google passkeys is visible, remove only credentials you no longer trust. Finish losing a phone that holds Google passkeys with a clean-session login test and a fallback-recovery test so both normal access and recovery are proven.
Related consequence reports for “If you lose the phone that has your Google passkeys: what to do next”
Continue in this topic
Find more distinct decisions and source-backed consequence reports in the Security & 2FA topic hub.
Official sources for “If you lose the phone that has your Google passkeys: what to do next”
- Google — PasskeysOfficial source ↗