G+D Netcetera manages 1.4 billion tokens
Payment tokenization as prerequisite in e-commerce
SMS OTP authentication takes 20 to 45 seconds — the wait for the message, the context switch, the manual entry. Passkey authentication takes 3 to 8 seconds. A different category of experience, and a different conversion outcome.
Passwords and SMS codes can be phished. A passkey is cryptographically bound to your service's domain, it cannot be entered on a fake website because it does not work anywhere except the legitimate service it was created for. Phishing-resistant by design.
PSD2's dynamic linking requirements are satisfied by Secure Payment Confirmation (SPC). PSD3 is pushing further in the same direction. Getting ahead of that now means not reworking it when the next mandate arrives.
Replace SMS one-time passwords in EMV 3DS challenge flows with passkey authentication. Customers authenticate with biometrics instead of waiting for SMS codes — reducing authentication time from 20-45 seconds to 3-8 seconds. Fewer abandoned transactions. Lower SMS delivery costs.
Secure merchant portal access with phishing-resistant passkey authentication. When merchants authenticate their customers with FIDO, that data can be passed as a trust signal in 3DS requests, driving frictionless approvals downstream.
Support Secure Payment Confirmation (SPC) and Click to Pay passkey integration. Align with the strategic direction of the major card networks that actively deploy passkey-based authentication services — ahead of new regulatory requirements rather than reacting to them.
Passkeys are the authentication method the regulatory and technical ecosystem is converging on. Deploying now means building on a foundation that regulators are mandating and card networks are embracing, not one that will need replacing in a couple of years.
90% faster than SMS OTP Passkeys replace SMS one-time passwords in EMV 3-D Secure challenge flows. When an issuer's Access Control Server requires step-up authentication, customers authenticate with biometrics instead of waiting for an SMS code. The challenge step does not disappear; it just stops being the reason customers abandon.
Best for: issuers and their ACS challenge flow. Available via G+D Netcetera’s 3DS Passkey Server.
Secure Payment Confirmation (SPC) SPC is a W3C standard designed for payment authentication using FIDO and WebAuthn. Transaction details — amount, merchant, payee — are displayed in a browser-native dialog with passkey authentication, meeting dynamic linking requirements. The customer sees exactly what they are authorizing and authenticates with a biometric.
Best for: PSPs and payment networks preparing for PSD3, without the UX cost of legacy challenge flows.
Conversion lift through trust signals When merchants use passkeys for account login, that data can be passed to issuers as a strong trust signal. Issuers who receive it can approve transactions frictionlessly, without an additional challenge step, because the customer has already authenticated at a higher standard than an SMS OTP.
Best for: PSPs improving frictionless approval rates for their merchant customers.
Transaction authentication within Click to Pay Skip 3DS entirely and authenticate with a biometric passkey instead — Face ID, fingerprint, done. The challenge step disappears, the customer stays in the checkout flow, and the transaction moves straight to authorization. A Click to Pay experience that delivers on the 'one click' promise without compromising on security.
Best for: PSPs and merchants running G+D Netcetera's Click to Pay SRCI.
Admin, consumer portals, and mobile apps Passkeys work wherever password-based authentication is currently used. Secure administration access for internal and partner-facing portals. Consumer portal login for self-service banking. Mobile app authentication that replaces PIN entry with a biometric gesture. Each integration point removes a password-based attack surface.
Best for: institutions eliminating passwords beyond the payment transaction itself.
Biometric authentication completes in 3 to 8 seconds. No SMS to wait for, no code to type, no app to switch to. The payment completes in the same gesture that unlocks the phone — the experience customers expect, now the one they can have.
Passkeys work on the devices customers already carry — iPhone, Android, any modern device. No new app to download, no new account to create. One biometric gesture and they are authenticated. Their private key never leaves their device.
Passkeys synchronize securely across a customer's devices through Apple iCloud Keychain or Google Password Manager — using end-to-end encryption. Losing a phone does not mean losing access. Recovery goes through the device account, not a vulnerable password reset.
Passkey authentication integrates directly into transaction flows. Major card networks including Visa and Mastercard are actively deploying passkey-based authentication services, replacing vulnerable SMS OTPs with phishing-resistant biometric authentication. For payment service providers, issuers, and merchants, passkeys offer multiple integration points across the payment ecosystem — from 3-D Secure authentication to Click to Pay checkout experiences.
Passwords are shared secrets — the server stores a version of your password, and the user transmits it during login. That creates two attack surfaces: the server database and the transmission channel. Passkeys eliminate both. Nothing is stored on the server except a public key, which is useless without the corresponding private key on the user's device. Nothing is transmitted during authentication except a signed cryptographic challenge — which cannot be replayed or used elsewhere. A passkey cannot be guessed, stolen from a database, phished, or reused. Passwords can be all four
Yes — and they are more secure than the SMS OTP methods they replace. The private key never leaves the user's device. The passkey is cryptographically bound to the specific service domain, making phishing attacks structurally impossible. Biometric verification adds a possession factor that an SMS code does not provide. Major card networks are deploying passkey-based authentication specifically because the security profile is stronger than existing methods. Financial regulators increasingly treat FIDO2-based authentication as meeting SCA requirements under PSD2 — with PSD3 reinforcing this direction.
Yes. Passkeys built on FIDO2 and WebAuthn are designed to meet SCA requirements under PSD2, including the dynamic linking requirement when implemented via Secure Payment Confirmation (SPC). SPC displays transaction details (amount, merchant, payee) within the biometric prompt, satisfying the requirement that the authentication be bound to the specific transaction. PSD3 is expected to strengthen SCA requirements further in the same direction that passkeys already satisfy. Deploying passkeys now means building on a regulatory-aligned foundation rather than retrofitting for future mandates.
Passkeys integrate with 3DS at three points. First, as a challenge flow replacement: when the ACS requires step-up authentication, it triggers a passkey challenge instead of sending an SMS OTP — reducing authentication time from 20-45 to 3-8 seconds. Second, via Secure Payment Confirmation (SPC): transaction details are shown in a browser-native passkey dialog, meeting dynamic linking requirements. Third, as a frictionless risk signal: when merchants use passkeys for customer login, that data can be passed in the 3DS request, enabling issuers to approve transactions without a challenge step. G+D Netcetera's 3DS Passkey Server handles the first and third; SPC is handled at the browser layer.
Passkeys support account recovery through the user's device ecosystem account — Apple ID, Google Account, Microsoft Account. Passkeys can be synchronized across a user's devices through platform keychains (iCloud Keychain, Google Password Manager) using end-to-end encryption, so losing one device does not mean losing all passkeys. For financial institutions, recovery flows can be designed to match existing identity verification processes — the passkey enrollment is re-established after identity is confirmed, without requiring a vulnerable password reset flow. The private keys themselves are never exposed during synchronization or recovery.
Find out how leading financial institutions implement passkeys, navigate regulation, and measure the results.
Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.