The short answer

A passkey is a FIDO cryptographic credential used to sign in to an app or website. It may be synced across a user’s devices or bound to one device. A biometric card is physical hardware that can verify a fingerprint locally and may hold device-bound FIDO credentials, physical-access credentials or payment functions. The categories overlap, but they are not interchangeable.

What biometrics do in each model

With a phone or computer passkey, the device’s fingerprint or face sensor usually unlocks use of the credential. With a biometric card, the fingerprint sensor is built into the issued card and verification occurs within the card architecture. In both well-designed FIDO cases, the website receives cryptographic proof rather than the fingerprint.

Synced passkeys prioritize convenience

Synced passkeys can become available across devices through a passkey provider. This reduces friction when a user replaces a phone or signs in on another device. The trade-off is that credential availability and recovery depend partly on the provider account and its security controls.

Cards and security keys can keep credentials device-bound

FIDO says security keys can store device-bound passkeys that do not leave the hardware. A biometric card can follow this roaming-authenticator model while adding local fingerprint verification. Organizations may prefer it when they issue and control authenticators or require one physical credential per person.

Physical access changes the comparison

Ordinary synced passkeys are primarily for digital authentication. Some biometric cards can also carry door-access technologies and visual identity, allowing one issued credential to serve buildings, computers and online services. Compatibility is configuration-specific and must be tested against the actual readers and identity platform.

Recovery is the central operational difference

Synced passkeys are designed to remain available when a user changes devices. Device-bound cards require spare credentials, secure replacement and account-recovery procedures. That can add administration, but it also gives an employer stronger control over issuance, revocation and possession.

Which should you choose?

Consumers usually benefit most from synced passkeys already integrated into their devices. Enterprises may choose biometric cards or other device-bound authenticators for managed workforces, shared terminals, physical access or higher-assurance environments. Many organizations will use both: synced passkeys for broad convenience and managed hardware for selected roles or systems.

Evaluation checklist

Compare phishing resistance, authenticator ownership, device portability, physical-access needs, reader requirements, attestation, enrollment, accessibility, lost-device recovery, offboarding and total lifecycle cost. The best option is the one whose recovery and management model matches the actual risk.