Passkeys: Secure and passwordless authentication

The missing link in payment authentication

What are passkeys?

FIDO2-certified authentication technology that eliminates passwords, reduces fraud, and delivers frictionless user experiences across and payment services.

Passkeys represent the next generation of authentication, replacing vulnerable passwords with cryptographic key pairs that never leave your users' devices. Built on FIDO2 and WebAuthn standards, passkeys leverage biometric authentication or device PINs to deliver phishing-resistant security that's faster and more convenient than traditional methods.

Passkey_tech-image

How does the technology behind passkey security work?

When a user registers, their device generates a unique cryptographic key pair. The private key stays securely on their device—never transmitted or stored on servers—while the public key is registered with your service. Authentication happens through biometric verification (fingerprint, Face ID) or device unlock, proving possession without exposing credentials.

Leading platforms including Apple, Google, and Microsoft have embraced passkeys, making them available across billions of devices. For financial institutions, this means robust authentication that meets regulatory requirements while dramatically improving customer experience.

Benefits of payment authentication

For Issuers

Replace SMS OTPs in 3DS challenges with passkey authentication

For PSPs

Secure merchant portal access and enable merchant passkey support

For Payment networks

Support emerging standards (SPC, Click to Pay integration)

Future-proof

Aligns with strategic direction and PSD3 requirements

Passkey_02

Why passkeys transform digital financial services

  • Eliminate card-not-present fraud
  • Reduce cart abandonment
  • Accelerate customer onboarding
  • Enable frictionless access
  • Secure high-value transactions
  • Meet regulatory requirements

Built on global standards

  • FIDO2 & WebAuthn Compliance: Passkey authentication is built on FIDO2 (Fast Identity Online) and WebAuthn (Web Authentication) standards developed by the W3C and FIDO Alliance.
  • Phishing-Resistant by Design: Passkeys cannot be tricked into being entered on fake websites.  Each passkey is cryptographically bound to your service's domain.
  • Device Synchronization & Recovery: Modern passkey implementations support synchronization across a user's ecosystem (Apple iCloud Keychain, Google Password Manager) while maintaining security through end-to-end encryption.

Passkey_01

Passkeys in payment transactions

Passkey authentication is revolutionizing payment security by integrating directly into transaction flows. Major card networks including Visa and Mastercard are actively deploying passkey-based authentication services, replacing vulnerable SMS OTPs with phishing-resistant biometric authentication.

For payment service providers, issuers, and merchants, passkeys offer multiple integration points across the payment ecosystem—from 3-D Secure authentication to Click to Pay checkout experiences.

Integration with 3-D Secure authentication

Challenge Flow Authentication

90% faster than SMS OTP

Passkeys replace SMS one-time passwords in EMV 3-D Secure challenge flows. When an issuer's Access Control Server (ACS) requires step-up authentication, customers authenticate with biometrics instead of waiting for SMS codes—reducing authentication time from 20-45 seconds to 3-8 seconds.

Secure Payment Confirmation (SPC)

PSD3-ready architecture

SPC is a W3C standard specifically designed for payment authentication using FIDO/WebAuthn. Transaction details (amount, merchant, payee) are displayed in a browser-native dialog with passkey authentication—meeting dynamic linking requirements for PSD2/PSD3 compliance.

 

Frictionless Risk Signals

15-25% conversion lift

When merchants use passkeys for account login, this FIDO authentication data can be passed to issuers via 3DS as a strong trust signal. Issuers leverage this to approve transactions frictionlessly without additional challenges—improving conversion while maintaining security.

 

Passkey authentication across financial services

  • E-commerce Platforms: Reduce checkout abandonment with one-touch payment authentication. Enable stored payment methods that customers can authorize instantly without memorizing passwords or waiting for OTPs. Increase conversion rates while exceeding PSD2 Strong Customer Authentication requirements.

  • Payment Service Providers: Deliver seamless authentication for merchants accessing dashboards, processing refunds, and managing settlements. Support multi-user account structures with role-based authentication that's both secure and convenient. Accelerate PSP onboarding with streamlined KYC and authentication enrollment.

  • Wealth Management & Investment Platforms: Provide secure access to sensitive financial information and high-value transaction capabilities. Enable quick authentication for time-sensitive trading while maintaining audit trails. Balance the need for robust security with the speed required in financial markets.

  • Digital Wallets: Create frictionless wallet access for frequent micro-transactions while maintaining security for wallet funding and peer-to-peer transfers. Support multiple device types and operating systems with consistent authentication experiences.

passkeyswebinarnew copy2

Webinar: The next generation of authentication

Join our authentication experts to explore how leading financial institutions are implementing passkey technology, navigating regulatory requirements, and achieving measurable improvements in security and user experience.

  • Real-world passkey implementation case studies
  • Technical deep-dive on FIDO2/WebAuthn integration
  • Migration strategies from legacy authentication
  • PSD3 compliance considerations

FAQ

  • In contrast to passwords, passkeys use device-bound cryptographic keys and biometrics instead of shared secrets, so there’s nothing to phish or reuse. Also, the sign-in gets faster and safer, especially for financial services.  Learn more about the differences in our comparison of passkeys vs passwords.

  • Yes, passkeys provide significantly stronger security than traditional password-based authentication.

    Security advantages for financial services:

    • Phishing immunity: Passkeys cannot be tricked into working on fraudulent sites, even if customers are socially engineered
    • Breach resistance: Server-side database breaches yield only public keys, which are cryptographically useless to attackers
    • Device-bound security: Private keys are protected by device secure enclaves (TPM, Secure Element) and cannot be extracted even by malware
    • Biometric privacy: Biometric data never leaves the device—services receive only cryptographic signatures, never fingerprints or facial scans
  • Passkeys are specifically designed to meet stringent financial services regulatory requirements.

    Regulatory compliance:

    Passkeys inherently satisfy multi-factor authentication requirements:

    • Possession factor: The device holding the passkey
    • Inherence factor: Biometric authentication (fingerprint, Face ID)
    • Knowledge factor: Device PIN (alternative to biometric)

    For PSD2 Strong Customer Authentication (SCA), passkeys meet all requirements including dynamic linking when implemented via Secure Payment Confirmation (SPC). For the upcoming PSD3 regulations, passkeys satisfy the phishing-resistant authentication mandate that will be required for high-risk transactions by October 2027.

    Major card schemes (Visa, Mastercard) have certified passkey authentication for payment transactions, and regulatory bodies including the European Banking Authority recognize FIDO2-based authentication as meeting enhanced security standards.

  • Passkeys integrate with EMV 3-D Secure in multiple ways, offering financial institutions flexibility based on their role in the payment ecosystem:

    For Card Issuers (via Access Control Server):

    When your Access Control Server (ACS) requires step-up authentication during a 3DS transaction, passkeys replace SMS one-time passwords in the challenge flow. Instead of customers waiting 20-45 seconds for an SMS code, they authenticate with biometrics in 3-8 seconds. This can be implemented through:

    • Standard WebAuthn integration: Passkey authentication within your ACS challenge page
    • Secure Payment Confirmation (SPC): Browser-native authentication dialog displaying transaction details (amount, merchant, payee) with passkey authentication—meeting dynamic linking requirements without redirecting customers


    For Merchants (Delegated Authentication):

    Large merchants using passkeys for account login can pass FIDO authentication data to issuers via the 3DS request. Issuers recognize this strong authentication as a trust signal

    and can approve transactions frictionlessly without additional challenges—improving conversion by 15-25% while maintaining security.


    For Payment Service Providers:

    PSPs implementing G+D Netcetera's 3DS Server can support both models—processing FIDO data from merchant passkeys for frictionless flows, and integrating with issuers' passkey-enabled ACS for challenge flows.


    For Payment Networks:

    Visa Payment Passkey and Mastercard Payment Passkey services provide network-level passkey authentication that works across all participating merchants, integrated with their 3DS infrastructure and Click to Pay services.

    G+D Netcetera's 3-D Secure solutions (ACS for issuers, 3DS Server for PSPs/acquirers) support passkey integration across all these scenarios, with SPC readiness built into our roadmap.

  • Modern passkey implementations solve the device loss challenge through secure synchronization and multiple recovery options—making passkeys actually more recoverable than passwords while maintaining security.

    Multi-Device Synchronization:

    Passkeys created on one device automatically sync to all of a user's devices within the same ecosystem using end-to-end encrypted cloud storage:

    • Apple ecosystem: iCloud Keychain syncs passkeys across iPhone, iPad, and Mac
    • Google ecosystem: Google Password Manager syncs across Android devices and Chrome browsers
    • Microsoft ecosystem: Microsoft Account syncs across Windows devices

    Importantly, this synchronization maintains security—passkey material is encrypted on the device before cloud storage, and the cloud provider (Apple, Google, Microsoft) cannot access the private keys even though they host the encrypted data.


    What this means for device loss:

    If a customer loses their phone, their passkeys remain accessible on their other devices (tablet, computer, etc.). When they get a new phone and sign in to their Apple ID, Google Account, or Microsoft Account, their passkeys sync to the new device automatically.


    Recovery Options for Financial Institutions:

    For customers who lose all their devices or are setting up a new ecosystem, Netcetera's passkey authentication supports multiple recovery strategies:

    1. Secondary passkey enrollment: Customers can register multiple passkeys (e.g., phone + laptop) during initial setup

    2. Backup authentication methods: Time-limited fallback to alternative authentication during recovery period

    3. Supported account recovery: Enhanced identity verification process (multiple knowledge-based questions, document verification, video identity confirmation) followed by new passkey enrollment

    4. Device-based recovery: For mobile banking apps, users can re-register passkeys after reinstalling the app and completing strong identity verification


    Better than password recovery:

    Traditional password recovery often relies on email or SMS—both vulnerable to interception. Passkey recovery leverages the security of device ecosystems and multi-factor identity verification, providing more secure recovery than password reset flows.

    Financial institutions can configure recovery policies based on their risk tolerance, with Netcetera providing flexible implementation options from highly automated (for low-value accounts) to heavily supported (for high-net-worth or corporate accounts).

Ready to Implement Passkey Authentication? Schedule a Consultation

By checking this box, I explicitly confirm that I would like to receive regular newsletters, offers, and marketing-related materials from G+D Netcetera. I understand that for this purpose, G+D Netcetera will process the personal data I have provided (including my name, email address, and other information, such as language preference or information regarding G+D Netcetera products and updates that are of my interest). I acknowledge that my data will be used to send back to me tailored content based on my interactions and preferences with G+D Netcetera. I understand that I can withdraw my consent at any time by clicking the unsubscribe link at the bottom of each email or by contacting G+D Netcetera at marcom@netcetera.com or privacy@netcetera.com. I am aware that further information about how G+D Netcetera processes my data, my rights regarding my data, and how to exercise them can be found in the G+D Netcetera Privacy Policy at https://www.netcetera.com/privacy-policies/global-privacy-policy.html

More stories

On this topic