A passkey and a security key are not competing technologies. They are the same technology in two different containers, which is the part most coverage skips.
Both are FIDO2 credentials. Both replace a password with a private key that never leaves the device it lives on, and both refuse to authenticate to a domain they were not created for. That last part is what makes either of them phishing-resistant. A fake login page can copy your password and it can relay a six-digit code, but it cannot make a FIDO2 credential sign for the wrong domain. The credential simply does not respond.
The choice is about where you want the private key to live.
Where a synced passkey is genuinely enough
A passkey stored in iCloud Keychain, Google Password Manager or a password manager syncs across your devices through your platform account. For most personal logins, that is the right trade. You get phishing resistance, you get it free, and you get it without carrying anything.
If you are protecting a personal email account, a shopping account or a social login, and you are already inside one platform with a strong account recovery setup, a synced passkey is a sensible place to stop, and buying hardware for it is not money well spent.
Where the hardware key still earns its place
Four situations change the maths.
The first is when the credential must not be recoverable from a cloud account. A synced passkey is exactly as strong as the platform account it syncs through. Compromise that account, or social-engineer its recovery flow, and the passkeys come with it. A credential on a hardware key cannot be extracted or synced. It exists on that key and nowhere else, which is the entire point for administrator and break-glass accounts, and for anything holding money.
The second is shared and machine accounts. A passkey assumes a person with a personal platform account. A duty mailbox, a shared finance login or a service account has no such thing, and the workaround people reach for is usually storing credentials somewhere they should not be. A key in a safe is a cleaner answer, and it is auditable in a way a shared login never is.
The third is staff without a work phone. Warehouse staff, field crews, clinical staff on shared workstations, anyone who cannot or will not install a work app on a personal device. Passkey rollouts stall on these people, and the stall is usually where a security project quietly dies. A key on a lanyard sidesteps the argument entirely.
The fourth is when someone else sets the rules. Insurers and tender documents increasingly ask for phishing-resistant MFA on privileged accounts specifically, and some ask for the credential to be hardware-bound. Whether a synced passkey satisfies a given clause depends on the clause. Read it before you decide.
Where this lands
Passkeys have made hardware keys less necessary for ordinary personal accounts, and that is a good thing. The credential is spreading to people who would never have bought a key.
What passkeys have not done is remove the reason keys exist. The value of a hardware key was never that it was the only phishing-resistant option. It was that the private key is bound to an object you can hold, lock in a drawer and hand to someone on their first day. Nothing about the passkey rollout changed that.
The sensible end state for most organisations is both. Synced passkeys for general staff on their day-to-day accounts, hardware keys for administrators, finance and break-glass accounts, and for anyone the passkey model does not fit. That is not a compromise. It is two tools doing the jobs they are respectively good at.