The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services.
This initiative aims to reduce reliance on passwords and SMS-based verification codes, which are common targets for fraud and credential theft.
UK Enables Passkey Login
GOV.UK One Login is a single sign-in solution for a variety of government services, such as childcare support, tax management, State Pension checks, and driver’s license renewals.
Users who opt in can authenticate using a device-bound passkey, unlocked through existing local security measures like fingerprints, Face ID, or a device PIN.
Unlike traditional password-based sign-in processes, passkeys eliminate the need for users to remember, type, reuse, or reset passwords.
The government reports that passkey authentication can be up to eight times faster than using a username, password, and two-step verification code. This technology also reduces delays and operational costs associated with sending SMS one-time passcodes.
During the initial trial, over 300,000 users of GOV.UK One Login adopted passkeys. The government indicated that nearly one in ten daily sign-ins already uses passkeys, saving taxpayers nearly £600 per day in SMS costs.
Passkeys offer security benefits because of their cryptographic, device-bound design. Each passkey links to a specific website or application and cannot be copied, guessed, or reused across services. During authentication, the user’s device verifies it is communicating with the legitimate service before allowing the login.
This design directly combats common phishing attacks. In traditional credential-harvesting scenarios, victims may inadvertently enter their password on a fake login page, allowing attackers to reuse it.
Passkeys do not expose reusable passwords to websites, significantly diminishing the effectiveness of cloned login portals and deceptive phishing emails.
The biometric data used to unlock a passkey is stored only on the user’s device. GOV.UK One Login does not receive or store users’ fingerprints or facial-recognition data. Instead, the biometric check or PIN acts as a local authorization method for using the passkey stored on the device.
Digital Government Minister Stephanie Peacock said the rollout would simplify access to essential government services while strengthening protection against password-related fraud. She emphasized that users can log in with the same fingerprint or facial scan they use to unlock their phones.
The National Cyber Security Center (NCSC) has endorsed passkeys as a more secure alternative to passwords. The NCSC emphasizes that passkeys cannot be intercepted, stolen, or reused like traditional credentials.
Jonathon Ellison, NCSC Director for National Resilience, noted that this deployment would give the public a faster, more secure way to access government services, reducing “password headaches.”
For security professionals, this rollout exemplifies a broader trend toward phishing-resistant authentication based on FIDO-style public-key cryptography.
Such advancements can minimize an organization’s vulnerability to credential theft, password spraying, reused passwords, phishing attacks, and SMS interception risks.
Passkeys remain optional for GOV.UK One Login users, allowing individuals to continue using passwords if they prefer. However, the government and NCSC are encouraging users to enable passkeys where available, promoting this technology as a valuable security enhancement for public-sector digital identity services.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.





