According to the GOV.UK news release, passkeys are being rolled out across GOV.UK One Login, extending the option to more than 23 million users. The sign-in system is already used for a growing range of public services, including childcare support, tax functions, State Pension checks and driving licence renewal. The change does not alter eligibility or service rules. It changes how people prove they are the account holder, with the stated aim of making routine access to government services quicker and less exposed to password-based fraud.
A passkey lets a user sign in with a fingerprint, a facial recognition tool such as Face ID, or a device PIN rather than a password. GOV.UK says that can make sign-ins up to eight times faster than the standard combination of username, password and a two-step verification code. For a common sign-in route used across multiple services, speed matters. Reducing the time spent retrieving passwords or waiting for text codes can remove a frequent point of friction in digital service delivery, particularly for high-volume transactions carried out on mobile phones.
The initial trial offers the clearest indication of user response so far. The government says more than 300,000 users successfully switched to passkeys during early testing, with the feature now being opened to millions more account holders. The same release says nearly one in 10 daily GOV.UK One Login sign-ins are already completed with passkeys. It adds that the shift is saving the taxpayer nearly £600 a day in SMS costs, as fewer users rely on text-message codes to complete the sign-in process.
The security case is central to the rollout. The National Cyber Security Centre recommends passkeys as a stronger alternative to passwords because they are tied to a particular device and website, which makes them much harder to steal through phishing, guess, or reuse across different accounts. The government has also emphasised that the biometric or PIN data used to unlock the passkey remains on the user's device. According to the GOV.UK announcement, that information is not viewed or stored by GOV.UK One Login itself.
Digital Government Minister Stephanie Peacock presented the change as a practical upgrade for common interactions with government. In the official release, she said the purpose is to remove the delays associated with forgotten passwords and one-time text codes, while giving users stronger protection against fraudsters who target password-based accounts. Jonathon Ellison, the National Cyber Security Centre's Director for National Resilience, placed the measure within a wider cyber-security context. His comments reflect an official view that reducing dependence on passwords can close off one of the most common attack routes used against consumer-facing digital services.
Passkeys remain optional. Users who prefer to continue signing in with a password can do so, rather than being required to adopt a device-based method immediately. That optional model matters for service delivery. It allows departments to raise security standards and reduce authentication costs without removing existing access routes for people who are more comfortable with traditional sign-in methods. For GOV.UK One Login, the rollout marks a further step towards faster, more phishing-resistant access across mainstream government services.