Passkeys promise password‑free logins for millions of UK citizens, trimming wait times and cutting fraud risks.

The digital gateway GOV.UK One Login now supports passkeys a device-based method that replaces traditional passwords with a fingerprint, facial recognition, or a simple PIN. More than 23 million people already use the service to reach over 250 public portals, ranging from childcare support to driver-licence renewal.
By tapping the same biometric or PIN that unlocks a smartphone, users can bypass the mental load of remembering passwords and the delay of entering one-time codes.
How passkeys work and why they matter
A passkey is an encrypted credential stored locally on a user’s device and linked to a specific website.
When a person attempts to sign in, the device proves ownership of the credential by presenting a biometric sample or PIN; the actual secret never leaves the device, and no password string is transmitted. This design makes the authentication process up to eight times faster than the classic combination of username, password and SMS verification.
Because the credential is bound to both the device and the domain, it cannot be reused on another site, guessed by attackers, or harvested through phishing emails. The biometric data used to unlock the passkey remains on the device and is never visible to GOV.UK One Login, preserving user privacy while dramatically raising security.
Rollout results: adoption, speed and savings
During the initial trial, more than 300,000 users – roughly one in ten daily sign-ins – switched to passkeys. That early momentum has accelerated, with the technology now available to millions of additional users. Government calculations show that each SMS verification avoided saves about £0.02; multiplied across the volume of logins, the country saves close to £600 per day, translating into millions of pounds over a year.
Beyond the financial upside, the experience is noticeably quicker. Users report that a passkey login completes in seconds, compared with the minute or more often required for entering a password and waiting for a text message. For people managing taxes, checking pension details, or renewing licences, this reduction in friction means more time for the task itself and less frustration.
Security endorsement and user-centred design
The UK National Cyber Security Centre (NCSC) has officially recommended passkeys as a more resilient alternative to passwords, citing their resistance to interception, reuse and phishing. Jonathon Ellison, NCSC Director for National Resilience, emphasised that the shift removes a common attack vector and forces cyber-criminals to look for harder-to-exploit routes.
Developers and designers at the Government Digital Service (GDS) built the rollout around extensive user research. Over 2,500 people were surveyed, and multiple rounds of testing with participants of varying digital confidence informed the final flow. Workshops with security, fraud, and accessibility specialists ensured that the experience works for users with assistive technology and respects privacy concerns surrounding biometrics.
Digital Government Minister Stephanie Peacock summed up the aim: “Nobody enjoys hunting for a forgotten password or waiting for a text message code. Passkeys mean people can access the services they rely on in seconds, using the same fingerprint or face scan they already use to unlock their phone.” The optional nature of the feature also allows anyone who prefers the traditional password route to continue doing so.
