Summary
- More than 23 million GOV.UK One Login users are becoming eligible for passkeys following an initial trial involving over 300,000 people.
- Passkeys use device security such as a fingerprint, face scan, or PIN and resist phishing because there is no reusable password to steal.
- Nearly one in ten daily One Login sign-ins already uses passkeys, with government estimating SMS savings of almost £600 per day.
The UK government is extending passkey authentication across more than 23 million GOV.UK One Login accounts, turning one of the country’s largest digital identity systems into a substantial real-world deployment of passwordless security following an initial trial involving more than 300,000 users.
Government Digital Service is making passkeys available across GOV.UK One Login, which provides a common account for services including State Pension checks, childcare support, tax services, and other government transactions. Users can authenticate using the same fingerprint, facial recognition, device PIN, or screen-lock mechanism they already use to unlock a compatible phone, tablet, or computer.
Passwords remain available for people who prefer them, making the rollout an adoption programme rather than an immediate mandatory migration. Those setting up a passkey will normally use it as their main sign-in method, with credentials stored through the password-management system associated with their device.
The government says nearly one in ten daily One Login authentications already uses a passkey, while removing text-message security codes from those transactions is saving close to £600 per day in SMS costs. It also says passkey sign-ins can be up to eight times faster than entering a username and password followed by a two-step verification code.
Phishing resistance changes the security model
The more important change is security rather than convenience. Traditional passwords are reusable secrets: if someone can persuade a user to enter one into a fake website, extract it from another compromised service, or intercept it through malware, the attacker may be able to attempt the same credential against the genuine account.
Passkeys use public-key cryptography instead. The authentication credential is bound to the legitimate service and unlocked locally by the user’s device, meaning a phishing site cannot simply collect a password and replay it later. The National Cyber Security Centre consequently recommends passkeys as a more secure alternative to passwords.
Biometric information used to unlock the credential also remains on the device rather than being sent to GOV.UK One Login. The service sees evidence that the correct cryptographic credential has been used, not the fingerprint or facial template employed by the phone or computer to authorise it.
That distinction becomes important when a public identity system is used across many services. Consolidating authentication can make government transactions simpler, but it also increases the value of an account to an attacker because a compromised identity may provide access to several services rather than one isolated website.
Improving authentication is therefore part of the infrastructure problem created by One Login itself. As more government departments move services onto a common sign-in system, security improvements can be deployed centrally instead of asking each department to build and maintain its own authentication stack.
Scale turns marginal costs into infrastructure costs
The SMS figure illustrates the operational economics of national digital services. A security code may cost only a small amount to send, but millions of logins turn marginal transaction costs into recurring expenditure. Moving authentication onto credentials already stored on users’ devices removes some of that communications cost alongside the security benefit.
GDS says more than 300,000 people successfully switched during the initial passkey trial before the broader rollout began. The service supports modern iPhones, Android devices, Windows PCs, Macs, and tablets, although users need compatible operating systems and a configured screen lock before they can create a credential.
People can also use a passkey across devices sharing the same password manager, while signing in on a separate computer can be handled through a QR code and a nearby device containing the credential. Passwords and verification codes remain available as backup options, including where someone loses access to the device containing a passkey.
Keeping that fallback is operationally necessary during a mass migration, but it also means password-related risk does not disappear simply because passkeys are available. Attackers tend to follow the weakest remaining recovery or authentication path, so the long-term security effect depends partly on how many users switch and how securely account-recovery processes are managed.
Digital identity is becoming shared infrastructure
The rollout sits inside a broader effort to replace separate departmental accounts with reusable government identity infrastructure. That can reduce duplicated technology and make services more consistent, although it also puts greater pressure on the central platform’s availability, accessibility, privacy controls, and resilience.
Passkeys help with one part of that problem by reducing reliance on credentials people have to create and remember themselves. They do not resolve questions around identity proofing, account recovery, access for people without modern devices, or the design of individual public services, but they remove one familiar weakness from the authentication layer.
Optional adoption also provides GDS with a way to measure behaviour before making any more aggressive move away from passwords. The early numbers suggest there is demand: hundreds of thousands of users have already enrolled, and passkeys are accounting for a visible proportion of daily sign-ins before the full 23 million-account rollout has matured.
One Login creates a shared layer once and lets multiple services inherit changes to it, so an improvement to sign-in security can propagate across departments without each organisation running its own migration. Rolling phishing-resistant authentication across tens of millions of accounts consequently combines a security improvement with a measurable reduction in the cost and friction of each transaction.












