RSS Amplifier

Passkeys Substack · Aug 14, 2026

Explain passkeys to one colleauge in one sentence

0
Sign in to vote or save

Vincent Delitz · Passkeys Substack

Here are this week’s topics that you don’t wanna miss out on!

🎤 The session: passkeys explained clearly in 20 minutes

🇮🇳 The room: what India is already shipping with passkeys

Read the full guide

Last Friday I had 20 minutes on stage at the FIDO Alliance India Working Group meetup in Bengaluru in front of 130 people from 80 organizations, roughly four out of five of them developers. The brief was to leave the room able to explain passkeys to a CTO, a security reviewer or the newest developer on the team.

Three questions carried the whole session. What is a passkey, in a model you can repeat. Why can it not be phished, in enough detail to defend in a security review. And how do you actually get it used, because shipping passkeys and getting them used are two different problems. A short summary:

Apple puts the average iPhone at more than 80 unlocks a day, nearly all of them Face ID or Touch ID. Anything you do 80 times a day feels natural and a passkey login is that exact gesture pointed at a service instead of a lock screen.

The question every team with fingerprint unlock asks: we already have biometrics, what is different? Local biometrics unlock something on one device and never talk to a server. A passkey signs you in to a service, works across devices and is bound to the real domain. Same face, different job.

Phishing resistance is a property of the protocol, not of user training. The passkey is locked to the real domain’s Relying Party ID at creation, so on a pixel-perfect look-alike the browser simply reports no passkeys available. There is no warning to click away and no decision for the user to get wrong.

Adoption is creation times usage, so a strong number on one side is worth nothing while the other sits at zero. Created but never used, because login still leads with password and OTP. Or never created, because the prompt only lives in a settings menu.

The one-sentence version I left the room with: a passkey signs you in to a service with the gesture that unlocks your phone and there is no password behind it, so there is nothing to phish, nothing to reuse and nothing to steal from a server.

Read More

The rest of the day was the part you cannot get from a spec. Government, banks, telco, payments and travel in one room at Google Ananta and most of them are past the “should we” stage and into the numbers. Five things worth taking home.

  • MakeMyTrip: a copy change doubled sign-ups: In an A/B test, “skip OTP next time” got exactly twice the passkey sign-ups of the generic create-a-passkey nudge. Their reported results so far: 61% adoption among repeat users, 25% saved on SMS cost and logins 4x faster than sign-up and 7x faster than the mobile OTP flow. They nudge once, never twice and back off the moment a user says no.

  • PhonePe: the blockers are UX, not crypto: They went identifier-first, offer the passkey right after a successful login and refuse to create duplicates. The real friction sits elsewhere: a meaningful share of users, senior citizens especially, have no device lock or biometric set at all and on Samsung devices the default credential manager sends users through a Samsung account setup first. Payments still run through the UPI PIN, the passkey replaces the login OTP.

  • Visa: authentication is going federated: Visa Payment Passkey enrolls the cardholder once, with consent, inside a normal checkout and that one enrollment then works at any other enabled merchant. Reported effect on a payment: roughly 50 seconds down to about 20 and 11 interactions down to 3. The issuer keeps the decision and the liability.

  • Aadhaar meets WebAuthn: SETS presented a proof of concept with UIDAI that binds Aadhaar identity proofing to the device holding the passkey, through an intermediary that issues a device identifier and signs the device certificate. The pitch is a national chain of trust: Aadhaar proves the human, the passkey proves possession and e-governance services get a phishing-resistant login they can accept.

  • Recovery is the new front door: The FIDO Alliance’s own framing echoed by Google on stage: once login cannot be phished, attackers move to account recovery and the state of the art there is still SMS OTP, which is really just proof of possession of a SIM.

See the full agenda

Our mission is to free the world from passwords to make the Internet a safer place - this can only be accomplished together.
Join our passkeys community to connect with other passkey enthusiasts, stay up-to-date, get implementation support and show your passkeys projects!

Join Passkeys Community

No posts

Read the original on passkeys.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.