Full Breakdown
UK Government Rolls Out Passkeys for 23 Million One-Login Users
By Drooid · · How we work
Government Push to Replace Passwords with Passkeys
The UK government is extending the use of passkeys to more than 23 million citizens who access services through GOV.UK One Login. Passkeys allow users to authenticate with a fingerprint, facial recognition, or device PIN instead of a traditional password and a two-factor authentication (2FA) text message. The rollout follows a pilot that involved over 300 000 participants and is part of the broader digital-transformation programme for public services.
How Passkeys Work and Expected Benefits
A passkey stores cryptographic credentials on the user’s device and links them to a specific website or app. When a user unlocks the device with biometric data or a PIN, the credential is presented to the service without exposing the secret to the server. Because the credential is device-bound, it cannot be intercepted by phishing sites or reused on other services. The biometric data or PIN never leaves the device, preserving user privacy.
Adoption Data and Cost Savings
Government figures indicate that nearly one-in-ten daily One Login sign-ins are now completed with a passkey, and that signing in with a passkey can be up to eight times faster than the password + SMS verification flow. The shift away from SMS-based 2FA is reported to save taxpayers roughly £600 per day in messaging costs.
Official Statements & Responses
Digital Government Minister Stephanie Peacock has said the initiative is intended to make public services “simpler and safer for everyone,” emphasizing that the new method reduces the need to remember passwords or wait for text-message codes. The National Cyber Security Centre (NCSC) is promoting the technology, noting that it offers a “highly phishing-resistant alternative to passwords.” Passkeys remain optional; users may continue to log in with passwords if they prefer.
Verbatim Quote
“Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target,” — Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC)
