October 1, 2026
What Are Passkeys? What the GOV.UK Rollout Means for You
23 million people can now sign in to government services without a password. Here’s what that means, and why you should expect the same…

By Brian Jones
3 min read
23 million people can now sign in to government services without a password. Here's what that means, and why you should expect the same from your bank
This month GOV.UK One Login, the account you use for things like tax, your State Pension and renewing your driving licence, started offering passkeys to its 23 million users. Instead of a password and a code sent by text, you sign in the same way you unlock your phone: your face, your fingerprint, or your PIN.
Most of the coverage has been written for people who build these systems. This post is for the people who use them. I work on technology for government, and I've come to think that the biggest driver of better security isn't regulation or clever engineers. It's users who understand enough to ask for better.
So let's get you there.
What's wrong with passwords?
A password is a secret you share. You know it, and the website knows a scrambled version of it. Every time you sign in, you type the secret and send it off.
That creates three problems:
- It can be guessed. People reuse passwords, pick memorable ones, and write them down. Attackers know this.
- It can be stolen. If a website is breached, its store of passwords can leak. If you reused that password elsewhere, those accounts are at risk too.
- It can be tricked out of you. This is the big one. A convincing fake website asks for your password, you type it in, and now someone else has it. That's phishing, and it works on clever people every day.
The text-message code was added to patch these holes. It helps, but it can also be tricked out of you by the same fake website, and criminals can sometimes take over a phone number altogether. It also costs money to send: GOV.UK says passkeys are saving taxpayers nearly £600 a day in text-message costs.
How a passkey is different
A passkey works like a lock and key rather than a password.
When you create a passkey, your phone or computer makes a matched pair. One half, the lock, goes to the website. The other half, the key, stays on your device and never leaves it. When you sign in, the website sends a challenge, and your device proves it has the key without ever sending the key itself.
That fixes all three problems:
- There's nothing to guess. You didn't choose it, and you can't reuse it.
- A breach doesn't give much away. The website only holds locks. A stolen lock doesn't open anything.
- A fake website gets nothing. This is the clever bit. Each passkey is tied to the real website's address. If you land on a fake site, your device simply won't offer the key. You don't have to spot the fake. Your device does it for you.
"Does the government get my fingerprint?"
No, and this is worth being clear about because it's usually the first thing people worry about. Your face or fingerprint is only used to unlock the key on your own device, exactly as it does when you unlock your phone. It never gets sent to GOV.UK or anyone else. If you'd rather not use biometrics at all, your device PIN does the same job.
What if I lose my phone?
Most passkeys are now stored in the password manager built into your phone or computer, such as 1Password, Apple's iCloud Keychain or Google Password Manager. This means they're backed up and synced to your other devices. A new phone signed in to the same account gets your passkeys back.
And on GOV.UK One Login, passkeys are optional. If you don't have a compatible device, or would rather not, you can carry on signing in with your password and code. That matters. A government service has to work for everyone, including people with older phones, shared devices, or no smartphone at all. Offering the better option without taking away the old one is the right call.
Is it actually better, or just different?
On the numbers GOV.UK has published, better. Passkey sign-ins are up to eight times faster than a username, password and code. Over 300,000 people tried passkeys before the full rollout, and nearly one in ten daily sign-ins already use them. The National Cyber Security Centre recommends them as a more secure alternative to passwords.
Speed matters more than it sounds. Security that's annoying gets worked around. Security that's quicker than the insecure option gets used.
Setting one up
The details vary by device, so follow GOV.UK's own guidance, but the shape is always the same:
- Sign in to your GOV.UK One Login account the usual way.
- Look in your account's security settings for the option to add a passkey.
- Your device will ask you to confirm with your face, fingerprint or PIN.
- Next time, choose to sign in with a passkey.
It takes about a minute.
Now ask for it everywhere else
Here's the part that matters most. The UK government has just shown that passkeys work at the scale of tens of millions of ordinary people. There's no longer a good excuse for services that hold your money or your data not to offer them.
So next time you sign in to your bank, your energy supplier, your email or your GP surgery's app, ask:
- Do you support passkeys? If not, when will you?
- Can I stop you texting me codes? Once you've got a passkey, the text message is the weak point.
- What happens if I lose my device? A good answer involves a sensible recovery process, not a phone call where someone reads out your mother's maiden name.
Companies change what they build when enough customers ask the same question.
You now know enough to be demanding better.
Sources:
- GOV.UK, "Millions of people to benefit from simpler, more secure way to sign in to government services",14 September 2026
- Government Digital Service blog, "How we made it easier for millions of users to sign into government services", 16 September 2026