UK Government Begins Moving 23 Million Users Away From Passwords With Passkeys
The UK government has begun rolling out passkey authentication to more than 23 million GOV.UK One Login users, marking a major move away from traditional password-based authentication for accessing public services.

The rollout allows users to sign in using the same security mechanism they use to unlock their device, such as a fingerprint, facial recognition or device PIN, instead of entering a password followed by a security code.
The technology is being introduced across GOV.UK One Login, which provides access to a growing range of government services, including childcare services, driving licence services, State Pension information and tax-related services.
From Passwords to Passkeys
Traditional authentication typically requires users to enter a password and then verify their identity using an additional security code.
With a passkey configured, the process becomes:
Enter email address → Authenticate using passkey → Access GOV.UK service
The passkey is stored through the user's device ecosystem or password manager. Depending on the device, authentication can involve:
- Fingerprint recognition
- Facial recognition
- Device PIN
- Device passcode or unlock pattern
GOV.UK says users' biometric information is not shared with GOV.UK One Login or the government service being accessed. The biometric check takes place on the user's device.
Why Passkeys Are More Resistant to Phishing
Passwords remain a major target for phishing, credential stuffing and account-takeover attacks.
Passkeys are based on public-key cryptography and remove the shared password that attackers traditionally attempt to steal.
Instead of transmitting a reusable password to a website, the user's device retains the private cryptographic credential and proves possession during authentication.
This also makes passkeys resistant to many conventional phishing techniques because the credential is associated with the legitimate service rather than something the user manually enters into a fraudulent login page.
The UK's National Cyber Security Centre (NCSC) now recommends passkeys as the preferred authentication method where they are available, saying they are generally more secure than even strong passwords combined with two-step verification.
Trial Involved More Than 300,000 Users
The nationwide rollout follows an initial GOV.UK One Login trial involving more than 300,000 users.
Government figures indicate that passkeys are already being used for almost 10% of daily One Login authentications, while the new authentication process can be significantly faster than the previous password-and-security-code approach.
The broader deployment will now make the option available to more than 23 million One Login users.
Passwords Are Not Disappearing Immediately
Despite the move toward passwordless authentication, GOV.UK is not immediately removing passwords entirely.
Once a user creates a passkey, it becomes their main way of signing in. However, GOV.UK says there may still be circumstances where a password and security code are required as a backup, such as when users lose access to their passkey.
This provides an account-recovery mechanism while the government transitions users toward passkey-based authentication.
Device Requirements
GOV.UK currently supports passkey creation on modern smartphones, tablets and computers.
Examples include:
| Platform | Minimum Requirement |
|---|---|
| iPhone | iPhone 8 or newer with iOS 16+ |
| iPad | iOS/iPadOS 16+ |
| Android | Android 10+ |
| Windows | Windows 10+ |
| macOS | macOS Ventura 13+ |
The device must also have a screen-lock mechanism configured.
Users are advised not to create a passkey on a shared device, because someone capable of unlocking that device could potentially use the stored passkey to access the account.
Passkeys Could Also Reduce SMS Authentication Costs
Moving millions of authentications away from SMS security codes could have financial as well as security benefits.
Reporting on the rollout indicates that GOV.UK One Login has been sending millions of SMS authentication codes each month, generating substantial messaging costs. Expanding passkeys reduces dependence on SMS while also removing a commonly targeted authentication mechanism.
A Significant Shift in Government Identity Security
The rollout is notable because GOV.UK One Login operates at national scale.
Rather than treating passkeys as an experimental authentication option, the UK government is moving toward making them a mainstream way for millions of citizens to access digital public services.
The approach also aligns with guidance from the NCSC, which announced earlier in 2026 that consumers should prefer passkeys where available instead of relying on passwords.
Security Takeaway
Moving more than 23 million government-service users toward passkeys could significantly reduce exposure to traditional credential-stealing attacks.
Passkeys cannot eliminate every form of account compromise. Attackers can still target account-recovery processes, compromised devices, malicious software and social-engineering workflows.
However, removing reusable passwords from the normal authentication process eliminates one of the most commonly targeted pieces of account information.
For organizations considering their own passwordless strategies, the GOV.UK rollout demonstrates how passkeys are moving from consumer technology platforms into large-scale government identity infrastructure.
The transition will not make passwords disappear overnight, but it represents another significant step toward an internet where users increasingly authenticate with cryptographic credentials rather than secrets they must remember, type and protect.
SEO Meta Description:
The UK government is rolling out passkeys to more than 23 million GOV.UK One Login users, replacing passwords and security codes with phishing-resistant authentication.
Related reporting
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have uncovered a sophisticated banking-malware campaign that hijacks Google Chrome and Microsoft Edge using malicious browser extensions capable of stealing credentials, cookies, session tokens and other sensitive browser data.
WhatsApp Tests Restricted Chat Feature to Keep Sensitive Conversations on Your Primary Phone
WhatsApp is developing a new privacy feature called Restricted Chat that could give users greater control over where sensitive conversations are accessible.
Enterprise-Wide AI Adoption Is Reshaping the SOC With a Surge in AI-Driven Alerts
As organizations rapidly integrate generative AI and AI agents into everyday workflows, Security Operations Centers (SOCs) are facing a new challenge: AI itself is becoming a major source of security alerts.


