Passkeys

SMS OTPs are slow, phishable, and out of step with how customers expect to authenticate. Passkeys replace them with biometric verification: faster, safer, built into your customers' devices. 
Contact us

What are passkeys and why does authentication need to change?

SMS OTPs were a reasonable solution fifteen years ago. Today they cost you conversions, create phishing exposure, and fall short of where regulation is heading. Passkeys are the upgrade, FIDO2-certified, built into your customers' devices, and designed for payments.
Speed

SMS OTP authentication takes 20 to 45 seconds — the wait for the message, the context switch, the manual entry. Passkey authentication takes 3 to 8 seconds. A different category of experience, and a different conversion outcome. 

Security

Passwords and SMS codes can be phished. A passkey is cryptographically bound to your service's domain, it cannot be entered on a fake website because it does not work anywhere except the legitimate service it was created for. Phishing-resistant by design. 

Regulation

PSD2's dynamic linking requirements are satisfied by Secure Payment Confirmation (SPC). PSD3 is pushing further in the same direction. Getting ahead of that now means not reworking it when the next mandate arrives. 

Benefits of our Passkeys solution

Passkeys solve different but equally important problems for issuers, PSPs, payment networks, and merchants.
Issuers: replace SMS OTP in 3DS

Replace SMS one-time passwords in EMV 3DS challenge flows with passkey authentication. Customers authenticate with biometrics instead of waiting for SMS codes — reducing authentication time from 20-45 seconds to 3-8 seconds. Fewer abandoned transactions. Lower SMS delivery costs. 

PSPs: secure portals, trust signals

Secure merchant portal access with phishing-resistant passkey authentication. When merchants authenticate their customers with FIDO, that data can be passed as a trust signal in 3DS requests, driving frictionless approvals downstream. 

Networks: ahead of the mandates

Support Secure Payment Confirmation (SPC) and Click to Pay passkey integration. Align with the strategic direction of the major card networks that actively deploy passkey-based authentication services — ahead of new regulatory requirements rather than reacting to them. 

Regulatory alignment

Passkeys are the authentication method the regulatory and technical ecosystem is converging on. Deploying now means building on a foundation that regulators are mandating and card networks are embracing, not one that will need replacing in a couple of years. 

Solution overview

Passkeys integrate at several points in the payment flow. Each one solves a specific problem for a specific audience.

Benefits of our Passkeys solution for your customers

No passwords to remember. No codes to wait for. Authentication that takes seconds and cannot be phished. 
No more waiting for a code



Biometric authentication completes in 3 to 8 seconds. No SMS to wait for, no code to type, no app to switch to. The payment completes in the same gesture that unlocks the phone — the experience customers expect, now the one they can have. 

Secure on every device they already own

Passkeys work on the devices customers already carry — iPhone, Android, any modern device. No new app to download, no new account to create. One biometric gesture and they are authenticated. Their private key never leaves their device. 

Protected even if they lose their device

Passkeys synchronize securely across a customer's devices through Apple iCloud Keychain or Google Password Manager — using end-to-end encryption. Losing a phone does not mean losing access. Recovery goes through the device account, not a vulnerable password reset. 

How passkey security actually works

The security comes from the cryptography, not from a policy. What happens at registration and authentication. 
Registration

When a user registers, their device generates a unique cryptographic key pair. The private key stays securely on the device — it is never transmitted and never stored on a server anywhere. 

The public key is registered with your service. This key pair is unique to the combination of user, device, and service, which is exactly what makes it useless to an attacker anywhere else. 

Authentication

When the user authenticates, their device uses the private key to sign a challenge from the server. The user proves they have physical possession of the device — confirmed by biometric verification (fingerprint, Face ID) or device PIN. 

No password is transmitted. No code is sent. Nothing is shared that could be intercepted, replayed, or phished. 

Synchronization and recovery

Modern passkey implementations support synchronization across a user's ecosystem — Apple iCloud Keychain, Google Password Manager — through end-to-end encryption. 

If a user loses their device, recovery happens through their device account, not through a vulnerable password reset flow. Security is maintained throughout because the keys themselves are never exposed during sync.

FAQs

The questions financial institutions ask before deploying passkey authentication — answered by the team that builds it. 
How do passkeys work in payment transactions?

Passkey authentication integrates directly into transaction flows. Major card networks including Visa and Mastercard are actively deploying passkey-based authentication services, replacing vulnerable SMS OTPs with phishing-resistant biometric authentication.  For payment service providers, issuers, and merchants, passkeys offer multiple integration points across the payment ecosystem — from 3-D Secure authentication to Click to Pay checkout experiences. 

How does passkey authentication differ from passwords?

Passwords are shared secrets — the server stores a version of your password, and the user transmits it during login. That creates two attack surfaces: the server database and the transmission channel. Passkeys eliminate both. Nothing is stored on the server except a public key, which is useless without the corresponding private key on the user's device. Nothing is transmitted during authentication except a signed cryptographic challenge — which cannot be replayed or used elsewhere. A passkey cannot be guessed, stolen from a database, phished, or reused. Passwords can be all four

Are passkeys secure enough for banking and payments?

 

Yes — and they are more secure than the SMS OTP methods they replace. The private key never leaves the user's device. The passkey is cryptographically bound to the specific service domain, making phishing attacks structurally impossible. Biometric verification adds a possession factor that an SMS code does not provide. Major card networks are deploying passkey-based authentication specifically because the security profile is stronger than existing methods. Financial regulators increasingly treat FIDO2-based authentication as meeting SCA requirements under PSD2 — with PSD3 reinforcing this direction. 

Do passkeys meet regulatory requirements?

Yes. Passkeys built on FIDO2 and WebAuthn are designed to meet SCA requirements under PSD2, including the dynamic linking requirement when implemented via Secure Payment Confirmation (SPC). SPC displays transaction details (amount, merchant, payee) within the biometric prompt, satisfying the requirement that the authentication be bound to the specific transaction. PSD3 is expected to strengthen SCA requirements further in the same direction that passkeys already satisfy. Deploying passkeys now means building on a regulatory-aligned foundation rather than retrofitting for future mandates. 

How do passkeys work with 3-D Secure?

Passkeys integrate with 3DS at three points. First, as a challenge flow replacement: when the ACS requires step-up authentication, it triggers a passkey challenge instead of sending an SMS OTP — reducing authentication time from 20-45 to 3-8 seconds. Second, via Secure Payment Confirmation (SPC): transaction details are shown in a browser-native passkey dialog, meeting dynamic linking requirements. Third, as a frictionless risk signal: when merchants use passkeys for customer login, that data can be passed in the 3DS request, enabling issuers to approve transactions without a challenge step. G+D Netcetera's 3DS Passkey Server handles the first and third; SPC is handled at the browser layer. 

What happens if a customer loses their device?

Passkeys support account recovery through the user's device ecosystem account — Apple ID, Google Account, Microsoft Account. Passkeys can be synchronized across a user's devices through platform keychains (iCloud Keychain, Google Password Manager) using end-to-end encryption, so losing one device does not mean losing all passkeys. For financial institutions, recovery flows can be designed to match existing identity verification processes — the passkey enrollment is re-established after identity is confirmed, without requiring a vulnerable password reset flow. The private keys themselves are never exposed during synchronization or recovery. 


Related resources

Find out more about our Passkeys solution
Webinar: The next generation of authentication

Find out how leading financial institutions implement passkeys, navigate regulation, and measure the results.

 

Watch the webinar  

Podcast: Passkeys? Pass what?


Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.

 

Listen now


Related solutions 

Passkeys work best as part of a connected payment authentication and checkout stack. 
Click to Pay SRCI

Passkey authentication within Click to Pay eliminates the 3DS challenge step entirely — the customer authenticates biometrically and the transaction moves straight to authorization.

Discover the solution​

eCOM Tokenizer

Passkeys secure the identity verification, tokenization secures the payment credential. Together they cover authentication and data protection across the e-commerce transaction. 

Discover the solution​

3-D Secure Issuer Service 

Modern fraud prevention for issuers, combining the latest EMV 3-D Secure standards, broad multi-scheme certification, and intelligent risk-based authentication. 

Discover the solution​

The G+D Netcetera Email Newsletter

Latest updates and news in your inbox

Subscribe now

Talk to our experts


Related Insights

The Friendly Fraud Problem

The Friendly Fraud Problem

First-party misuse is now the world’s leading type of fraud, yet it is almost impossible to spot at checkout. Discover why friendly fraud is rising, what it costs the payments industry, and how better data sharing could help distinguish genuine disputes from deliberate abuse.

Passkeys? Pass what?

Passkeys? Pass what?

Your Essential Introduction to Passwordless Authentication. Tired of password resets, phishing attacks, and frustrated customers? It's time to discover passkeys—the authentication technology that's making passwords obsolete.

S01E08: Click to Pay: Smart, Simple, Secure

S01E08: Click to Pay: Smart, Simple, Secure

Remember the last time you abandoned a purchase because you couldn’t find your card? How much time, energy, and mood did you waste filling in the requested information? Ultimately, you just left your purchase because it was too time-consuming, data-consuming, and energy-consuming. Sound familiar? That’s exactly why Click to Pay was created. In this episode with Suzana Kordumova Nikolova, we explore what makes Click to Pay different from Apple Pay and Google Pay, how it enhances security, and why businesses adopt it.

S01E09: Passkeys, pass what?

S01E09: Passkeys, pass what?

Passwords are becoming a thing of the past. Passkeys deliver a safer, faster, and more seamless way to log in and approve payments. Payment expert Nakjo Shishkov explains how passkeys, 3DS, Click to Pay, and FIDO authentication set new standards for secure digital experiences. Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.