Skip to main content
The Wire
CyberNews by Zentrya One
Threat Intel

UK Government Begins Moving 23 Million Users Away From Passwords With Passkeys

The UK government has begun rolling out passkey authentication to more than 23 million GOV.UK One Login users, marking a major move away from traditional password-based authentication for accessing public services.

The rollout allows users to sign in using the same security mechanism they use to unlock their device, such as a fingerprint, facial recognition or device PIN, instead of entering a password followed by a security code.

The technology is being introduced across GOV.UK One Login, which provides access to a growing range of government services, including childcare services, driving licence services, State Pension information and tax-related services.

From Passwords to Passkeys

Traditional authentication typically requires users to enter a password and then verify their identity using an additional security code.

With a passkey configured, the process becomes:

Enter email address → Authenticate using passkey → Access GOV.UK service

The passkey is stored through the user's device ecosystem or password manager. Depending on the device, authentication can involve:

  • Fingerprint recognition
  • Facial recognition
  • Device PIN
  • Device passcode or unlock pattern

GOV.UK says users' biometric information is not shared with GOV.UK One Login or the government service being accessed. The biometric check takes place on the user's device.

Why Passkeys Are More Resistant to Phishing

Passwords remain a major target for phishing, credential stuffing and account-takeover attacks.

Passkeys are based on public-key cryptography and remove the shared password that attackers traditionally attempt to steal.

Instead of transmitting a reusable password to a website, the user's device retains the private cryptographic credential and proves possession during authentication.

This also makes passkeys resistant to many conventional phishing techniques because the credential is associated with the legitimate service rather than something the user manually enters into a fraudulent login page.

The UK's National Cyber Security Centre (NCSC) now recommends passkeys as the preferred authentication method where they are available, saying they are generally more secure than even strong passwords combined with two-step verification.

Trial Involved More Than 300,000 Users

The nationwide rollout follows an initial GOV.UK One Login trial involving more than 300,000 users.

Government figures indicate that passkeys are already being used for almost 10% of daily One Login authentications, while the new authentication process can be significantly faster than the previous password-and-security-code approach.

The broader deployment will now make the option available to more than 23 million One Login users.

Passwords Are Not Disappearing Immediately

Despite the move toward passwordless authentication, GOV.UK is not immediately removing passwords entirely.

Once a user creates a passkey, it becomes their main way of signing in. However, GOV.UK says there may still be circumstances where a password and security code are required as a backup, such as when users lose access to their passkey.

This provides an account-recovery mechanism while the government transitions users toward passkey-based authentication.

Device Requirements

GOV.UK currently supports passkey creation on modern smartphones, tablets and computers.

Examples include:

Platform Minimum Requirement
iPhone iPhone 8 or newer with iOS 16+
iPad iOS/iPadOS 16+
Android Android 10+
Windows Windows 10+
macOS macOS Ventura 13+

The device must also have a screen-lock mechanism configured.

Users are advised not to create a passkey on a shared device, because someone capable of unlocking that device could potentially use the stored passkey to access the account.

Passkeys Could Also Reduce SMS Authentication Costs

Moving millions of authentications away from SMS security codes could have financial as well as security benefits.

Reporting on the rollout indicates that GOV.UK One Login has been sending millions of SMS authentication codes each month, generating substantial messaging costs. Expanding passkeys reduces dependence on SMS while also removing a commonly targeted authentication mechanism.

A Significant Shift in Government Identity Security

The rollout is notable because GOV.UK One Login operates at national scale.

Rather than treating passkeys as an experimental authentication option, the UK government is moving toward making them a mainstream way for millions of citizens to access digital public services.

The approach also aligns with guidance from the NCSC, which announced earlier in 2026 that consumers should prefer passkeys where available instead of relying on passwords.

Security Takeaway

Moving more than 23 million government-service users toward passkeys could significantly reduce exposure to traditional credential-stealing attacks.

Passkeys cannot eliminate every form of account compromise. Attackers can still target account-recovery processes, compromised devices, malicious software and social-engineering workflows.

However, removing reusable passwords from the normal authentication process eliminates one of the most commonly targeted pieces of account information.

For organizations considering their own passwordless strategies, the GOV.UK rollout demonstrates how passkeys are moving from consumer technology platforms into large-scale government identity infrastructure.

The transition will not make passwords disappear overnight, but it represents another significant step toward an internet where users increasingly authenticate with cryptographic credentials rather than secrets they must remember, type and protect.

SEO Meta Description:
The UK government is rolling out passkeys to more than 23 million GOV.UK One Login users, replacing passwords and security codes with phishing-resistant authentication.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.