Passkeys

SMS OTPs are slow, phishable, and out of step with how customers expect to authenticate. Passkeys replace them with biometric verification: faster, safer, built into your customers' devices. 
Contact us

What are passkeys and why does authentication need to change?

SMS OTPs were a reasonable solution fifteen years ago. Today they cost you conversions, create phishing exposure, and fall short of where regulation is heading. Passkeys are the upgrade, FIDO2-certified, built into your customers' devices, and designed for payments.
Speed

SMS OTP authentication takes 20 to 45 seconds — the wait for the message, the context switch, the manual entry. Passkey authentication takes 3 to 8 seconds. A different category of experience, and a different conversion outcome. 

Security

Passwords and SMS codes can be phished. A passkey is cryptographically bound to your service's domain, it cannot be entered on a fake website because it does not work anywhere except the legitimate service it was created for. Phishing-resistant by design. 

Regulation

PSD2's dynamic linking requirements are satisfied by Secure Payment Confirmation (SPC). PSD3 is pushing further in the same direction. Getting ahead of that now means not reworking it when the next mandate arrives. 

Benefits of our Passkeys solution

Passkeys solve different but equally important problems for issuers, PSPs, payment networks, and merchants.
Issuers: replace SMS OTP in 3DS

Replace SMS one-time passwords in EMV 3DS challenge flows with passkey authentication. Customers authenticate with biometrics instead of waiting for SMS codes — reducing authentication time from 20-45 seconds to 3-8 seconds. Fewer abandoned transactions. Lower SMS delivery costs. 

PSPs: secure portals, trust signals

Secure merchant portal access with phishing-resistant passkey authentication. When merchants authenticate their customers with FIDO, that data can be passed as a trust signal in 3DS requests, driving frictionless approvals downstream. 

Networks: ahead of the mandates

Support Secure Payment Confirmation (SPC) and Click to Pay passkey integration. Align with the strategic direction of the major card networks that actively deploy passkey-based authentication services — ahead of new regulatory requirements rather than reacting to them. 

Regulatory alignment

Passkeys are the authentication method the regulatory and technical ecosystem is converging on. Deploying now means building on a foundation that regulators are mandating and card networks are embracing, not one that will need replacing in a couple of years. 

Solution overview

Passkeys integrate at several points in the payment flow. Each one solves a specific problem for a specific audience.

90% faster than SMS OTP  Passkeys replace SMS one-time passwords in EMV 3-D Secure challenge flows. When an issuer's Access Control Server requires step-up authentication, customers authenticate with biometrics instead of waiting for an SMS code. The challenge step does not disappear; it just stops being the reason customers abandon.  

Best for: issuers and their ACS challenge flow. Available via G+D Netcetera’s 3DS Passkey Server. 

Secure Payment Confirmation (SPC)  SPC is a W3C standard designed for payment authentication using FIDO and WebAuthn. Transaction details — amount, merchant, payee — are displayed in a browser-native dialog with passkey authentication, meeting dynamic linking requirements. The customer sees exactly what they are authorizing and authenticates with a biometric.  

Best for: PSPs and payment networks preparing for PSD3, without the UX cost of legacy challenge flows. 

Conversion lift through trust signals  When merchants use passkeys for account login, that data can be passed to issuers as a strong trust signal. Issuers who receive it can approve transactions frictionlessly, without an additional challenge step, because the customer has already authenticated at a higher standard than an SMS OTP.  

Best for: PSPs improving frictionless approval rates for their merchant customers.

Transaction authentication within Click to Pay  Skip 3DS entirely and authenticate with a biometric passkey instead — Face ID, fingerprint, done. The challenge step disappears, the customer stays in the checkout flow, and the transaction moves straight to authorization. A Click to Pay experience that delivers on the 'one click' promise without compromising on security.  

Best for: PSPs and merchants running G+D Netcetera's Click to Pay SRCI. 

Admin, consumer portals, and mobile apps  Passkeys work wherever password-based authentication is currently used. Secure administration access for internal and partner-facing portals. Consumer portal login for self-service banking. Mobile app authentication that replaces PIN entry with a biometric gesture. Each integration point removes a password-based attack surface. 

Best for: institutions eliminating passwords beyond the payment transaction itself. 


Benefits of our Passkeys solution for your customers

No passwords to remember. No codes to wait for. Authentication that takes seconds and cannot be phished. 
No more waiting for a code



Biometric authentication completes in 3 to 8 seconds. No SMS to wait for, no code to type, no app to switch to. The payment completes in the same gesture that unlocks the phone — the experience customers expect, now the one they can have. 

Secure on every device they already own

Passkeys work on the devices customers already carry — iPhone, Android, any modern device. No new app to download, no new account to create. One biometric gesture and they are authenticated. Their private key never leaves their device. 

Protected even if they lose their device

Passkeys synchronize securely across a customer's devices through Apple iCloud Keychain or Google Password Manager — using end-to-end encryption. Losing a phone does not mean losing access. Recovery goes through the device account, not a vulnerable password reset. 

How passkey security actually works

The security comes from the cryptography, not from a policy. What happens at registration and authentication. 
Registration

When a user registers, their device generates a unique cryptographic key pair. The private key stays securely on the device — it is never transmitted and never stored on a server anywhere. 

The public key is registered with your service. This key pair is unique to the combination of user, device, and service, which is exactly what makes it useless to an attacker anywhere else. 

Authentication

When the user authenticates, their device uses the private key to sign a challenge from the server. The user proves they have physical possession of the device — confirmed by biometric verification (fingerprint, Face ID) or device PIN. 

No password is transmitted. No code is sent. Nothing is shared that could be intercepted, replayed, or phished. 

Synchronization and recovery

Modern passkey implementations support synchronization across a user's ecosystem — Apple iCloud Keychain, Google Password Manager — through end-to-end encryption. 

If a user loses their device, recovery happens through their device account, not through a vulnerable password reset flow. Security is maintained throughout because the keys themselves are never exposed during sync.

FAQs

The questions financial institutions ask before deploying passkey authentication — answered by the team that builds it. 
How do passkeys work in payment transactions?

Passkey authentication integrates directly into transaction flows. Major card networks including Visa and Mastercard are actively deploying passkey-based authentication services, replacing vulnerable SMS OTPs with phishing-resistant biometric authentication.  For payment service providers, issuers, and merchants, passkeys offer multiple integration points across the payment ecosystem — from 3-D Secure authentication to Click to Pay checkout experiences. 

How does passkey authentication differ from passwords?

Passwords are shared secrets — the server stores a version of your password, and the user transmits it during login. That creates two attack surfaces: the server database and the transmission channel. Passkeys eliminate both. Nothing is stored on the server except a public key, which is useless without the corresponding private key on the user's device. Nothing is transmitted during authentication except a signed cryptographic challenge — which cannot be replayed or used elsewhere. A passkey cannot be guessed, stolen from a database, phished, or reused. Passwords can be all four

Are passkeys secure enough for banking and payments?

 

Yes — and they are more secure than the SMS OTP methods they replace. The private key never leaves the user's device. The passkey is cryptographically bound to the specific service domain, making phishing attacks structurally impossible. Biometric verification adds a possession factor that an SMS code does not provide. Major card networks are deploying passkey-based authentication specifically because the security profile is stronger than existing methods. Financial regulators increasingly treat FIDO2-based authentication as meeting SCA requirements under PSD2 — with PSD3 reinforcing this direction. 

Do passkeys meet regulatory requirements?

Yes. Passkeys built on FIDO2 and WebAuthn are designed to meet SCA requirements under PSD2, including the dynamic linking requirement when implemented via Secure Payment Confirmation (SPC). SPC displays transaction details (amount, merchant, payee) within the biometric prompt, satisfying the requirement that the authentication be bound to the specific transaction. PSD3 is expected to strengthen SCA requirements further in the same direction that passkeys already satisfy. Deploying passkeys now means building on a regulatory-aligned foundation rather than retrofitting for future mandates. 

How do passkeys work with 3-D Secure?

Passkeys integrate with 3DS at three points. First, as a challenge flow replacement: when the ACS requires step-up authentication, it triggers a passkey challenge instead of sending an SMS OTP — reducing authentication time from 20-45 to 3-8 seconds. Second, via Secure Payment Confirmation (SPC): transaction details are shown in a browser-native passkey dialog, meeting dynamic linking requirements. Third, as a frictionless risk signal: when merchants use passkeys for customer login, that data can be passed in the 3DS request, enabling issuers to approve transactions without a challenge step. G+D Netcetera's 3DS Passkey Server handles the first and third; SPC is handled at the browser layer. 

What happens if a customer loses their device?

Passkeys support account recovery through the user's device ecosystem account — Apple ID, Google Account, Microsoft Account. Passkeys can be synchronized across a user's devices through platform keychains (iCloud Keychain, Google Password Manager) using end-to-end encryption, so losing one device does not mean losing all passkeys. For financial institutions, recovery flows can be designed to match existing identity verification processes — the passkey enrollment is re-established after identity is confirmed, without requiring a vulnerable password reset flow. The private keys themselves are never exposed during synchronization or recovery. 


Related resources

Find out more about our Passkeys solution
Webinar: The next generation of authentication

Find out how leading financial institutions implement passkeys, navigate regulation, and measure the results.

 

Watch the webinar  

Podcast: Passkeys? Pass what?


Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.

 

Listen now


Related solutions 

Passkeys work best as part of a connected payment authentication and checkout stack. 
Click to Pay SRCI

Passkey authentication within Click to Pay eliminates the 3DS challenge step entirely — the customer authenticates biometrically and the transaction moves straight to authorization.

Discover the solution​

eCOM Tokenizer

Passkeys secure the identity verification, tokenization secures the payment credential. Together they cover authentication and data protection across the e-commerce transaction. 

Discover the solution​

3-D Secure Issuer Service 

Modern fraud prevention for issuers, combining the latest EMV 3-D Secure standards, broad multi-scheme certification, and intelligent risk-based authentication. 

Discover the solution​

The G+D Netcetera Email Newsletter

Latest updates and news in your inbox

Subscribe now

Talk to our experts

Read the full G+D Netcetera Privacy Policy More information about G+D Netcetera's Privacy Policy

Related Insights

The Friendly Fraud Problem

The Friendly Fraud Problem

First-party misuse is now the world’s leading type of fraud, yet it is almost impossible to spot at checkout. Discover why friendly fraud is rising, what it costs the payments industry, and how better data sharing could help distinguish genuine disputes from deliberate abuse.

E-commerce Fraud in the UK: Is 3DS Enough?

E-commerce Fraud in the UK: Is 3DS Enough?

This free on-demand webinar with G+D Netcetera and The Payments Association UK explores why 3DS alone is no longer enough, and how banks can use earlier intervention, cross-channel intelligence and secure data sharing to make fraud prevention more proactive.

Passkeys? Pass what?

Passkeys? Pass what?

Your Essential Introduction to Passwordless Authentication. Tired of password resets, phishing attacks, and frustrated customers? It's time to discover passkeys—the authentication technology that's making passwords obsolete.

S01E08: Click to Pay: Smart, Simple, Secure

S01E08: Click to Pay: Smart, Simple, Secure

Remember the last time you abandoned a purchase because you couldn’t find your card? How much time, energy, and mood did you waste filling in the requested information? Ultimately, you just left your purchase because it was too time-consuming, data-consuming, and energy-consuming. Sound familiar? That’s exactly why Click to Pay was created. In this episode with Suzana Kordumova Nikolova, we explore what makes Click to Pay different from Apple Pay and Google Pay, how it enhances security, and why businesses adopt it.

S01E09: Passkeys, pass what?

S01E09: Passkeys, pass what?

Passwords are becoming a thing of the past. Passkeys deliver a safer, faster, and more seamless way to log in and approve payments. Payment expert Nakjo Shishkov explains how passkeys, 3DS, Click to Pay, and FIDO authentication set new standards for secure digital experiences. Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.