Enterprise Passkey Whitepaper. Practical guidance, rollout patterns and KPIs for passkey programs.
.deviceOwnerAuthentication policy in
clamshell mode.Apple is ushering the passwordless future with passkeys with macOS Ventura. In this article, we want to show how passkeys can be used on the Apple Watch as the latest device from the Apple cosmos, after they were previously available with Face ID and Touch ID on Mac, iPhone and iPad.
Discuss passkeys news and questions in r/passkey.
One of the many new features of macOS Ventura is that passkey logins are now available by using an Apple Watch. After the passwordless login with Touch ID or Face ID was already supported on Mac, iPhone and iPad, users can now create a passkey with yet another Apple device. This is possible for all passkey-supported websites on Safari as well as on Chrome.
Below, you'll find an instruction on how to set up the passkey login for your Apple Watch:
Even though macOS Ventura and newer Apple Watches work together to authenticate you in more places (like unlocking your Mac or the new Passwords app), Apple has a policy decision that prevents the Watch from counting as a “strong” user verification (UV) in certain contexts—specifically, when cryptographic keys are protected by the Secure Enclave. In these cases, Touch ID or a typed password is required, and macOS will not allow the Apple Watch alone to complete the final authentication.
When using passkeys with Safari (which stores them inside the Secure Enclave via iCloud Keychain), Apple’s framework is designed to ignore the Apple Watch for the final “user verification” step if Touch ID is unavailable (such as in clamshell mode). Instead, it forces you to enter your Mac password—even though the Watch can unlock your Mac in other scenarios. This is because Apple does not consider the Watch by itself a high‐enough level of security to release Secure Enclave–protected credentials.
In contrast, if you use passkeys stored by Google Password Manager or inside your Chrome
profile, they are generally kept outside Apple’s
Secure Enclave. That means Chrome can use the broader
.deviceOwnerAuthentication policy in LocalAuthentication, which lets macOS determine
whether to prompt you for Touch ID, Apple Watch, or your password. As a result, Apple
Watch fallback often works in clamshell mode for Chrome‐based passkeys (since the system
allows it) while Safari’s Secure Enclave–based passkeys do
not.
You might wonder why the Watch can unlock your Mac session or the new Passwords app yet not finalize a passkey login in Safari. Apple considers the Mac session unlock and password manager unlock to be convenience features, whereas accessing Secure Enclave–protected keys (the actual cryptographic passkeys) requires stricter user verification. In practical terms, that means if you’re in clamshell mode and go to log in to a passkey‐enabled site in Safari, you’ll see a password prompt instead of being able to confirm on your Watch—even though you’re wearing it.
Below is a summary of how passkeys behave on a MacBook in clamshell mode, with different storage and authentication configurations:
| Scenario | Stored In | Clamshell Apple Watch Fallback? | Why? |
|---|---|---|---|
| 1. Safari & iCloud Keychain (Secure Enclave) | Secure Enclave | No – Password is required | Apple enforces a policy that the Watch alone is not a sufficient factor for unlocking Secure Enclave keys. |
| 2. Chrome & Google Password Manager (non‐Enclave) | Google/Chrome storage | Yes – Apple Watch can confirm | Passkeys not in Secure Enclave, so .deviceOwnerAuthentication can allow Apple Watch as fallback in macOS. |
| 3. OS‐Level Unlock (e.g., unlocking Mac session) | System authentication | Yes – Apple Watch auto‐unlock | Apple sees session unlock as a “convenience” factor, so watch unlock is sufficient (but not for Enclave keys). |
Since passkeys are enabled on all Apple devices, it's time to also make browsing on your website even safer and much more user-friendly by fully replacing passwords.
Try passkeys in a live demo.
With Corbado's solution, we help to you easily integrate the new sign-in method. Check out our demo and discover how the passwordless future looks like.
Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert →
On macOS Ventura, visit a passkey-supported website in Safari or Chrome, initiate sign-up or login, then check your Apple Watch for a notification and double-click the side button to confirm. Your Watch must be worn on your wrist and paired with your Mac for this to work.
Apple enforces a policy that the Watch alone is not a sufficient factor for unlocking Secure Enclave-protected credentials, where Safari and iCloud Keychain store passkeys. In clamshell mode without Touch ID available, macOS forces a password prompt even though the Watch works for other system unlocks.
Safari stores passkeys inside Apple's Secure Enclave via iCloud Keychain, and Apple's
policy disallows Watch-only authentication for those keys. Chrome stores passkeys in
Google Password Manager outside the Secure Enclave, so macOS can apply the broader
.deviceOwnerAuthentication policy and permit Apple Watch as a fallback.
Apple classifies Mac session unlock as a convenience feature where Watch authentication is sufficient, whereas accessing cryptographic passkeys stored in the Secure Enclave requires stricter user verification. This means Touch ID or a typed password is mandatory for the final passkey step in Safari, regardless of Watch availability.
Related Articles
Table of Contents