The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public services.
The deployment covers everything from childcare support and driving license renewals to State Pension checks and tax management, significantly changing how citizens authenticate to government systems.
Instead of entering a password and a one-time code sent by text message, users can sign in with the same fingerprint, facial recognition scan, device PIN or pattern used to unlock a phone, tablet or computer.
UK Government Passwordless
Officials say passkey authentication is up to eight times faster than the existing username, password and two-step verification process.
The rollout follows an initial trial in which more than 300,000 people successfully adopted passkeys, according to the official announcement published by GOV.UK.
Nearly one in ten daily GOV.UK One Login authentications are already completed this way, reducing SMS verification costs by almost £600 per day.
From a security perspective, passkeys address several weaknesses associated with password-based authentication. Built on the FIDO2 standard, they use cryptographic credentials linked to the legitimate website and managed by a trusted device or credential manager.
This design makes passkeys resistant to conventional credential-phishing attacks because users have no reusable password to disclose through a fraudulent login page.
The National Cyber Security Center says passkeys cannot be intercepted, reused, or stolen in the same manner as passwords and recommends choosing them wherever supported.
A fingerprint, facial template, or PIN is used locally to authorize the credential; GOV.UK One Login does not receive or store that biometric information.
A passkey may be synchronized through a device’s credential manager, while users can also authenticate on another device by scanning a QR code with a nearby device holding the passkey.
The change does not immediately abolish passwords. Passkeys remain optional, and users can continue signing in with a password and security code or use that route as a fallback if a passkey becomes unavailable.
GOV.UK also warns against setting one up on a shared device, since anyone who can unlock it could potentially use the stored credential.
Digital Government Minister Stephanie Peacock said the technology would let people reach essential services in seconds while strengthening protection against fraudsters targeting passwords.
NCSC Director for National Resilience Jonathon Ellison similarly described passkeys as a “highly phishing-resistant alternative,” urging citizens to enable them on GOV.UK One Login and other services supporting the technology.
For the government, the migration combines measurable operational savings with reduced authentication friction. For users, it removes password fatigue and dependence on SMS codes.
However, because password-based recovery remains available, overall account security will continue to depend partly on how securely those fallback mechanisms are implemented and protected as passkey adoption expands.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post UK Government Begins Moving 23 Million Users Away From Passwords appeared first on Cyber Security News.
