Finance
September 18, 2026

GOV.UK One Login rolls out passkeys to 23 million users

More than 23 million people can now sign in to government services using a fingerprint, face scan or PIN instead of a password.
GOV.UK One Login rolls out passkeys to 23 million users

More than 23 million people can now sign in to government services using a fingerprint, face scan or PIN instead of a password. The Department for Digital, Culture, Media and Sport and the Government Digital Service confirm on 14 September that passkeys are being rolled out across GOV.UK One Login, the shared account system that sits in front of a growing list of public services.

The change follows a trial in which more than 300,000 users switched to the new method. According to the government, nearly one in ten daily One Login sign-ins already use a passkey. Passkeys remain optional, and anyone who prefers a password and text message code can keep using them.

What a passkey actually does

A passkey replaces the password with a pair of cryptographic keys. One key stays on the user's device. The other is held by the service. When someone signs in, the device proves it holds the right key, and the user unlocks that proof with the same face scan, fingerprint or PIN they already use to open their phone.

The biometric data never leaves the device. GOV.UK One Login does not see or store it. What the service receives is confirmation that the correct key is present. This is a different model from a password, which has to be typed, transmitted and stored somewhere, and which can be guessed, reused or captured by a fake website.

The National Cyber Security Centre recommends passkeys wherever they are available. Its Director for National Resilience, Jonathon Ellison, describes them as a highly phishing-resistant alternative to passwords. Because a passkey is tied to a specific website, it does not work on a lookalike page built to harvest credentials. The scam email that asks a user to "confirm your login" has nothing to collect.

Why the account layer matters

GOV.UK One Login is not a single service. It is the front door to more than 250 of them, including State Pension checks, tax accounts, childcare support and driving licence renewal. The Government Digital Service built it to replace more than 190 separate login systems across departments, and all central government services are due to move onto it by the end of 2027.

That scale is the point. A weakness in one departmental login affects the users of that department. A weakness in One Login affects everyone who uses it. The reverse also holds. A security improvement applied once to the shared platform reaches every service behind it without each department having to build its own.

There is a cost argument too. The government says passkey sign-ins can be up to eight times faster than the current combination of username, password and two-step verification code. The shift away from text message codes is already saving close to £600 a day in SMS charges, and GDS expects the savings to run into millions of pounds a year as more users move across. Digital Government Minister Stephanie Peacock frames the change as making services simpler and safer while cutting off a route that fraudsters rely on.

The wider identity picture

The rollout arrives two months after the government cancelled its plans for a national digital ID scheme. That decision has not touched One Login or the GOV.UK Wallet, which stores digital versions of official documents such as the Veteran Card. A House of Commons Library briefing published this month notes there is no indication either programme is affected.

The National Audit Office, in a report earlier in September, argues that the harder problem was never the credential itself. It is the fragmented data behind it. Public services identify the same person through different numbers, from National Insurance to NHS to tax references, and inconsistent standards make it difficult to link one identity to the right record in each system. A better sign-in does not solve that. It does remove one long-standing point of friction and one common attack surface while the bigger questions stay open.

Responsibility for digital identity policy also moved from the Cabinet Office to DCMS in July, alongside GDS and the Office for Digital Identities and Attributes. The passkey rollout is one of the first visible outputs under that new arrangement.

What to watch

Adoption is the measure that counts. One in ten sign-ins is a strong start for an optional feature, but the remaining nine still depend on passwords and SMS. The next test is whether the numbers keep climbing as departments join the platform through 2027, and whether the government publishes regular figures on uptake and cost savings so the claims can be checked.

The other question is how the design holds up. Passkeys close off phishing, but they shift trust onto the device and the accounts that back it up. As One Login becomes the single route into public services, the security of that route becomes a matter of public interest rather than a technical detail.

Continue Reading