The UK government is broadening passkey sign-in for GOV.UK One Login, allowing users to authenticate with a device biometric or local passcode instead of entering a password and a separate security code. The option follows a trial and remains an alternative rather than the only sign-in route.
Biometric Update reported that more than 300,000 users adopted passkeys during the trial. GOV.UK guidance explains that the biometric template used to unlock a credential stays with the user’s device or credential manager and is not sent to One Login.
A passkey is distinct from the identity-checking process that may compare a selfie with an identity document. It authenticates possession of a cryptographic credential after an account has been established; it does not independently prove the civil identity behind that account.
Why it matters
Public-sector passkey deployments can reduce phishing exposure, but recovery and fallback paths remain part of the security boundary. A strong credential can be undermined if enrollment, account recovery or help-desk processes allow weaker impersonation routes.
For wider context, see SectechMedia’s related technical coverage.
