Passkey
A phishing-resistant sign-in credential based on FIDO standards, unlocked with the device's biometrics or PIN.
A passkey is an authentication credential based on FIDO standards that lets a user sign in to apps and websites with the same action they use to unlock their device, such as a biometric, a PIN or a pattern. It uses public-key cryptography scoped to a specific site, so there is no shared secret to phish or leak from a server. Passkeys are a practical way for a customer to approve a mandate strongly, which improves the evidence behind every action delegated under it.
Agent Minute explains this term on 17 January 2027.
Related terms
Authenticator assurance levelA NIST measure of how strongly an authentication process confirms that the same subject is returning.Strong customer authenticationAuthentication using two or more independent elements from knowledge, possession and inherence.Secure Payment ConfirmationA W3C web standard for confirming a payment's details with a WebAuthn credential, producing signed evidence.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.