WhatsApp expands multi-device passkeys and account protections

Meta has added support for multiple passkeys to a single WhatsApp account, allowing people who use both iOS and Android devices to sign in with phishing-resistant authentication. The company said that more than 1 billion people now use a passkey to log in to WhatsApp.
The feature extends WhatsApp’s passkey implementation across a wider set of personal device arrangements. Passkeys first arrived on Android in October 2023 and expanded to iOS in early 2024. Meta later integrated passkeys into Facebook logins in June 2025.
Multiple passkeys for one WhatsApp account
Users can manage their WhatsApp passkeys through Settings > Account > Passkeys. Supporting more than one passkey on an account is intended to help users retain the phishing-resistant sign-in method when they use both major mobile operating systems.
Passkeys are a login mechanism designed to avoid the password-based credentials that phishing pages can solicit from users. In WhatsApp’s update, the practical change is the ability to associate multiple credentials with the same account rather than limiting users with several devices to one passkey setup.
Two-step verification gains a password option
WhatsApp is also changing its two-step verification controls. The extra account-protection layer was previously based on a six-digit PIN. It will now offer a full password option that can be longer, alphanumeric and include special characters.
WhatsApp said two-step verification helps prevent account takeover even when someone obtains a user’s one-time passcode. The new password option gives users a way to move beyond easily guessed numeric PINs, particularly where a simple sequence has been reused.
More context for calls from unknown people
For Android users, WhatsApp is adding more information about calls from people who are not in their contacts. The context can include where a call is originating from, whether the caller is already in the recipient’s contact list and whether the two people share any groups.
The company said the information is intended to give recipients a moment to assess an unexpected call before responding. It does not replace verification of the caller, but it supplies details that may be relevant when an unfamiliar caller creates urgency.
What organisations should do
Businesses that rely on WhatsApp for staff or customer communications can ask employees to register passkeys on each device they legitimately use, then review two-step verification settings and replace weak PINs with strong passwords where available. Teams should also treat the new caller details as a prompt to verify unexpected contact rather than an automatic signal that a call is safe.

