UK Government Phases Out Passwords for 23 Million Users in Passkey Push

Whitehall rolls out FIDO2 passkeys across GOV.UK One Login, cutting SMS verification costs and securing millions of citizen accounts.

Smartphone displaying a secure biometric login prompt for government digital services.
Smartphone displaying a secure biometric login prompt for government digital services.

The UK government is rolling out passkeys across GOV.UK One Login for 23 million citizens, replacing vulnerable passwords and slashing costly SMS authentication fees.

Key takeaways
  • The UK government is expanding passkey support across GOV.UK One Login for over 23 million citizens.
  • Passkey sign-ins are up to eight times faster than traditional password and SMS 2FA workflows.
  • The transition is already saving taxpayers nearly £600 daily in SMS telecommunications costs.
  • Passkeys are cryptographically bound to specific domains, effectively neutralizing traditional phishing attacks.
In short

The UK government is rolling out passkeys across GOV.UK One Login for more than 23 million citizens, replacing traditional passwords and SMS two-factor authentication with cryptographic device credentials to improve security and lower operational costs.

The United Kingdom is systematically dismantling traditional password authentication for millions of citizens through a national identity platform rollout. According to The Register, the UK government is extending passkey support across GOV.UK One Login to more than 23 million users, shifting authentication away from vulnerable text message codes and static passwords toward cryptographic device credentials. This massive identity modernization effort follows a successful pilot involving over 300,000 individuals, proving that biometric sign-ins like Apple Touch ID, Windows Hello, and Android device locks can scale to national infrastructure without sacrificing usability.

Passkeys are proving to be up to eight times faster than traditional password-plus-2FA workflows, altering how citizens interact with public sector digital services. Nearly ten percent of daily logins to GOV.UK One Login now utilize passkeys rather than legacy credentials. Whitehall stands to secure a direct fiscal benefit alongside security gains, as replacing transactional SMS text messages with public-key cryptography is already saving taxpayers hundreds of pounds daily in telecommunications expenses. Because cryptographic pairs are bound to specific web domains, phishing attacks targeting government portals become structurally impossible, since a malicious replica site cannot trick a device into releasing credentials it does not locally expose.

How does the UK passkey migration impact national digital identity infrastructure?

The transition from passwords to passkeys across GOV.UK One Login represents a foundational shift in how national digital identity systems authenticate users at population scale. By leveraging W3C and FIDO Alliance standards, the government avoids maintaining proprietary credential stores while offloading biometric processing entirely to the end user's hardware. When a citizen registers a passkey, their device generates a private and public key pair. The private key never leaves the smartphone, tablet, or hardware security key, while the public key rests on government servers. Authentication relies on a local challenge-response mechanism unlocked by a biometric scan or device PIN. This architecture removes credential stuffing, brute-force attacks, and server-side credential database breaches from the threat model entirely, forcing attackers to find alternative entry vectors.

To evaluate how organizations should approach credential modernization, security teams can apply the Identity Migration Matrix. This practical decision framework categorizes users into three distinct operational tiers to optimize rollout velocity and risk mitigation:

  • Tier 1 - Digital Natives: Users comfortable with biometric authenticators who can be transitioned immediately via automated UI prompts during routine login flows.
  • Tier 2 - Legacy Holdouts: Citizens relying on older hardware or password managers who require clear fallback paths, educational onboarding, and progressive encouragement.
  • Tier 3 - High-Risk Administrators: Internal government personnel and high-privilege accounts requiring hardware-bound security keys as an absolute policy mandate.

“Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target.” — Jonathon Ellison, Government Security Authority

What happens next for enterprise authentication and public sector tech budgets?

As national identity platforms like GOV.UK One Login eliminate passwords for millions of citizens, enterprise security budgets and public sector procurement cycles will face immediate cascading pressures. The elimination of high-volume SMS two-factor authentication demonstrates that modern identity architectures reduce both operational overhead and telecom supplier costs. Procurement officers across regional and municipal governments will likely demand FIDO2-native compliance from software vendors, shifting IT budgets away from legacy SMS gateway contracts toward device-native authentication tooling. Organizations lagging behind this standard will find themselves auditing expensive, legacy multi-factor infrastructure that fails to meet evolving cyber insurance requirements.

Operational teams executing similar migrations must anticipate specific failure modes during rollout. The primary friction point in national-scale passkey deployments is account recovery when a user loses or replaces their primary hardware device. Without a well-designed multi-device syncing strategy utilizing cloud password managers or secure enterprise recovery workflows, support desks will experience a surge in identity lockout tickets. Furthermore, legacy enterprise applications relying on older protocols like LDAP or SAML 1.1 will require modern identity proxy layers to broker FIDO2 credentials, complicating backend infrastructure upgrades for IT departments.

What to watch next

Tracking the long-term success of national passkey adoption requires monitoring specific operational milestones and metrics over the coming quarters:

  • Account Recovery Volume: Monitor helpdesk ticket ratios regarding lost device lockouts as the 23 million user threshold is crossed.
  • SMS Cost Reductions: Track official Treasury reporting on telecommunications savings to quantify the exact return on investment for infrastructure modernization.
  • Vendor Compliance Mandates: Observe whether Whitehall extends passkey mandates to third-party suppliers and government contractor portals.

Frequently asked

What is GOV.UK One Login?

GOV.UK One Login is the UK government's unified digital identity platform designed to give citizens a single secure account to access various public sector services online without needing multiple different credentials.

How do passkeys protect against phishing?

Passkeys use cryptographic key pairs tied strictly to specific web domains. Because the private key never leaves the user's device and cannot be shared, phishing sites cannot trick users into handing over their credentials.

Why is the UK government moving away from SMS codes?

SMS text message verification codes are vulnerable to interception and SIM-swapping attacks. Additionally, sending millions of text messages incurs significant recurring telecommunications costs for taxpayers.

How many users are affected by the UK passkey rollout?

More than 23 million citizens are being given the opportunity to ditch traditional passwords in favor of passkeys as the GOV.UK One Login platform expands its authentication capabilities.

This article answers
  • uk government passkeys gov uk one login
  • passkeys replacing passwords uk
  • gov uk one login passkey rollout 23 million
  • how do passkeys protect against phishing
  • why are text message 2fa codes expensive for government
  • what is gov uk one login passkey authentication
  • uk cybersecurity passwordless initiative 2026
  • fido2 passkeys public sector adoption
Topics
P
Patrick
Senior Technology Correspondent

Patrick covers AI infrastructure, model releases and enterprise automation. He has spent more than a decade reporting on how engineering decisions inside large platforms end up reshaping the software everyone else has to build on.

AI model launchesEnterprise automationCloud infrastructureDeveloper tooling