GOV.UK One Login Passkeys Roll Out for 23 Million Users
For a lot of people, the hardest part of using an online public service is not the service itself. It is the sign-in. According to GOV.UK, passkeys are now being rolled out across GOV.UK One Login for more than 23 million users, covering everyday tasks such as accessing childcare support or renewing a driving licence. That may sound like a small technical update, but it is really about something most of us recognise straight away: forgotten passwords, one-time codes and locked accounts. When governments talk about improving digital services, this is what that looks like in practice.
A passkey lets you sign in with the security you already use on your own device, such as a fingerprint, Face ID or a PIN, instead of typing a password. GOV.UK says this can make sign-ins up to eight times faster than using a username, password and two-step verification code. **What this means for you:** if you already use your face, finger or PIN to get into your phone or laptop, the same habit can now be used to reach some government services. The aim is not to give you one more code to remember. It is to remove steps.
The rollout has already had a sizeable trial run. GOV.UK says more than 300,000 users switched to passkeys during the early phase, and nearly one in 10 daily GOV.UK One Login sign-ins are now made this way. The same change is also saving money, with the government saying fewer SMS codes are cutting taxpayer costs by nearly £600 a day. Digital Government Minister Stephanie Peacock presented the update in practical terms: people want to reach services quickly, not spend their time waiting for text messages or guessing which password they used last time. That is a simple point, but it matters. Good public technology should respect people’s time.
The security case is just as important as the convenience. The National Cyber Security Centre recommends passkeys because they are much harder to steal or misuse than ordinary passwords. A passkey is tied to a specific device and the genuine website, which means there is no reusable password sitting there for a scammer to grab. **A quick explainer:** phishing is when criminals try to trick you into handing over your details through a fake email, message or website. Passkeys do not stop every kind of online fraud, but they do remove one of the most common weak spots: the password itself.
One part of this story is easy to miss, and it is probably the bit people worry about most. When you use a passkey, the biometric information or PIN used to confirm it stays on your device. According to GOV.UK, that information is not seen or stored by GOV.UK One Login. That distinction matters. Using your fingerprint to confirm a sign-in is not the same as sending your fingerprint to a government database. In everyday terms, your device checks that it is really you, and then confirms the sign-in.
GOV.UK One Login is being used across a growing range of services, including checking a State Pension, managing tax services and accessing childcare support. That makes this more than a niche cyber security update. It affects ordinary parts of life, from family finances to retirement planning. Passkeys are also optional. People who would rather keep using a password can still do that, which means the system is changing without forcing everyone to change their habits at once. For public services, that balance between security and choice is important.
Jonathon Ellison of the National Cyber Security Centre has urged people to switch on passkeys for GOV.UK One Login and anywhere else they are offered. The wider lesson is useful beyond government websites: the safest option is often the one that asks the least of you day to day. **What it means:** this rollout is really a lesson in how digital identity should work. If a service is quicker, clearer and better protected against phishing, more people are likely to trust it and use it. For readers trying to make sense of online safety, that is the big takeaway.