The UK government has officially started deploying passkeys to over 23 million GOV.UK One Login users, ushering in a password-free era for accessing public services. These range from renewing driving licenses and managing state pensions to claiming childcare support and paying taxes.
What’s Changing
Instead of typing in a password plus receiving a one-time code via text, users can now unlock services using the same biometric or device-based methods they use to unlock their phones or computers—like fingerprints, face scans, PINs, or device patterns. While passkeys are now available, passwords remain as an optional fallback. Users who can’t use—or choose not to enable—passkeys can still log in with traditional credentials and security codes.
This rollout builds on a trial involving over 300,000 participants who successfully switched to passkeys. Already, nearly 10% of daily authentications through One Login are happening this way. The move also cuts costs: SMS verification requirements are expected to drop, saving around £600 per day.
Security & Operational Benefits
Passkeys are built on the FIDO2 standard. Rather than sending credentials to online servers, authentication takes place through cryptographic credentials tied to the official service and managed locally via a trusted device or credential manager. This design reduces the risk of credential-phishing attacks, because there’s no reusable password that can be tricked out of a user via a fake login page.
The National Cyber Security Centre points out that passkeys can’t be intercepted, reused, or stolen the same way passwords are. While biometric data such as fingerprints or facial scans are used to unlock the passkey locally, GOV.UK does not store this biometric data. Users can also authenticate on a second device by having their primary device scan a QR code.
However, the change isn’t total. Passwords still play a role. Recovery routes using passwords will continue to exist, so the overall safety of accounts will still partly depend on how secure those backup methods are. Also, passkeys are not recommended for shared devices—anyone with access to a shared device that’s unlocked could use stored credentials.
Government officials are enthusiastic. They say the new method will allow people to reach essential services in seconds, while also strengthening defences against fraudsters who target passwords. The National Cyber Security Centre describes passkeys as a “highly phishing-resistant alternative” and is urging users to enable them wherever possible.
For the government, passkeys offer dual gains: operational cost savings and reduced friction in user experience. For citizens, it means less password fatigue, fewer SMS codes, and smoother sign-ins—so long as fallback paths remain well-protected as adoption spreads.