WhatsApp is rolling out a major upgrade to its authentication toolkit—allowing users to register and use multiple passkeys on a single account across iOS and Android. This move aims to make sign-ins far more resistant to phishing attacks while simplifying access across devices. Over one billion users already rely on passkeys to access WhatsApp. Support was first launched on Android in October 2023, followed by an iOS release in early 2024. Meta later brought the same feature to Facebook logins in June 2025.
What’s New & How It Works
Those with WhatsApp on their phone can go to Settings ▸ Account ▸ Passkeys to manage multiple passkeys affixed to their account. The system supports several passkeys, allowing different methods or devices for authentication, while protecting against phishing attempts.
WhatsApp is also expanding its two-step verification by replacing the old six-digit PIN system with full passwords. Users will now be able to create longer, alphanumeric passwords with special characters, which are markedly harder to guess. For Android users, there’s an added layer of transparency: when someone outside their contacts places a call, they’ll see more detail, such as whether the caller is in their address book, any shared group memberships, and where the call might be coming from.
Why It Matters
Passkeys are part of a broader push toward passwordless and phishing-resistant authentication. Traditional methods like SMS codes and fixed PINs are known weak points in security. By allowing multiple passkeys per account, WhatsApp enables users to adopt more secure sign-on options while maintaining convenience across devices.
Upgrading two-step verification from a simple PIN to a full password offers stronger protection in case of account takeover attempts. Providing more context in unexpected calls helps users detect potential scams based on urgency or impersonation tactics.
The deployment of these features also reflects how major messaging platforms are evolving to meet growing threats. As phishing and account hijacking remain top vectors for attacks, stronger authentication forms an essential defense layer.
Looking ahead, precise rollout timing might vary by region; users aren’t expected to scramble—that said, the shift emphasizes that even long-trusted platforms must adapt. It’s wise for all users to check their security settings. Enable passkeys, upgrade two-step verification, and stay alert for suspicious calls. These changes may seem incremental, but combined, they mark a tougher stance against phishing and social engineering attacks.