The Government Technology Agency of Singapore (GovTech Singapore) announced the rollout passkey on Jun 30, 2026 as a new login method for Singpass, Singapore’s national digital identity platform.
Singpass is every Singapore resident’s trusted digital identity to prove who we are when performing everyday transactions like checking our CPF balance, booking medical appointments, renewing insurance and more. Access over 2,700 services across 800 government agencies and businesses, simply by authenticating with your biometrics or SMS Two-Factor Authentication (2FA).
Created by GovTech as a key enabler of Singapore’s digital economy, Singpass facilitates over 41 million transactions every month. Out of 5 million Singpass users, more than 4.2 million people use the Singpass app to easily log in to services, prove their identity over counters, digitally sign documents and do more on the go.
Passkeys add to existing authentication methods such as QR login, Face Verification, and SMS One-Time Passwords (OTPs). Passkeys are a secure, password-free way to log in to services with Singpass. They are phishing resistant and use device-based authentication such as facial recognition, fingerprint, or app passcode to verify your identity. If a device is lost or stolen, the Singpass app and passkey on it will be automatically deactivated when the user sets up Singpass on another device.

What is a Passkey?
A passkey is a cryptographic key designed to replace passwords. As old passwords could easily be stolen, hacked, or even guessed, passkeys would work on a completely different level, with public-private key pairs authentication. Unlike a password, passkeys cannot be shared, remembered, or written down. This makes it far less vulnerable to the types of attacks that commonly target password-based systems.
While early biometric authentication technologies laid the foundation for identity verification, the journey toward passkeys began in 2012 with the establishment of the FIDO Alliance, with the mission of eliminating passwords.
The passkey revolution began in 2021, when major technology companies adopted the FIDO2 and WebAuthn standards, enabling passwordless authentication. Today, passkeys have become an authentication method accessible to billions of users worldwide.
A significant milestone in the evolution of passkeys was the National Institute of Standards and Technology (NIST) formally recognizing synced passkeys in its supplement to the SP 800-63B guidelines. NIST SP 800-63B Supplement
This recognition highlights the phishing-resistant nature of passkeys, while demonstrating their potential to replace traditional passwords with a more secure, convenient, and user-friendly authentication method.
With NIST’s recognition, passkeys are well positioned for widespread adoption, particularly in highly regulated industries such as banking and healthcare. This is expected to drive the next phase of secure digital identity verification.
The Difference Between Passkeys and Passwords
- Every passkey is inherently strong – Users do not need to worry about whether a passkey is long or complex enough.
- Passkeys cannot be guessed – Based on public-key cryptography, passkeys do not rely on personal data or easily predictable information for authentication.
- Passkeys are not stored on servers – Unlike passwords, passkeys are stored locally on the user’s device and are never shared with the websites or services they sign in to.
- Phishing-resistant by design – WebAuthn ensures that the private key can only be used to authenticate with the correct registered domain. Even if a user interacts with a fake website, that website cannot obtain the user’s credentials.
- Seamless user experience – Passkeys provide a convenient, fast, and frictionless sign-in process, significantly improving the overall user experience.
Types of Passkeys
There are two main types of passkeys, designed for different use cases and, more importantly, different security requirements. Within the digital security ecosystem, the two primary categories are Multi-Device Passkeys and Device-Bound Passkeys. Let’s explore the differences between them.
Multi-Device Passkeys
Multi-Device Passkeys, also known as Synced Passkeys, are well suited for personal use. They can be seamlessly synchronized across multiple devices, such as smartphones, tablets, and laptops, provided those devices are linked to an Apple, Google, or Microsoft account.
This flexibility allows users to access their accounts from any trusted device without having to remember or enter a password.
Device-Bound Passkeys
In contrast, Device-Bound Passkeys can be viewed as a “security shield” for enterprise environments. Because they are bound to a single device and cannot be copied, this type of passkey provides an additional layer of security that is particularly valuable for organizations with strict data protection and access control requirements.
In other words, Multi-Device Passkeys prioritize convenience and flexibility, while Device-Bound Passkeys prioritize stronger control and security.
Benefits of Passkeys
Benefits for Users
- Phishing Protection: Passkeys are designed to resist phishing attacks. They cannot be used on fake websites, providing effective protection against cyber threats.
- No More Password Hassles: Users no longer need to remember or manage passwords. Passkeys enable authentication using biometrics, providing a more seamless and convenient experience.
- Seamless Multi-Device Access: Passkeys make it easy for users to switch between devices within the same ecosystem without interruption.
- Private and Secure Biometric Data: Biometric information remains on the user’s device and is not shared with service providers, helping protect sensitive data.
- Built-in Multi-Factor Authentication: With passkeys, “something you have” (a device) and “something you are” (biometrics) can be combined into a single authentication step, delivering strong security without compromising convenience.
Benefits for Developers
- Stronger Website Security: Passkeys provide phishing-resistant, cryptographic security, helping reduce the risk of account compromise and strengthening overall system protection.
- Improved User Conversion Rates: A seamless and frictionless sign-in process reduces user abandonment and can improve conversion rates across online services.
- Reduced Maintenance Costs: Developers can reduce security management costs by eliminating the need for password recovery and other costly password-based or two-factor authentication processes.
- Easier Compliance with Security Standards: Passkeys eliminate the need to store sensitive authentication credentials, simplifying compliance with data protection regulations and reducing potential risks in the event of a security breach.
As these technologies continue to evolve, more people are asking: What is a passkey, and how does it work? Growing interest in passkeys is encouraging technology innovators to invest significant resources in researching, developing, and advancing this technology.
Passkeys are set to bring profound changes to security and digital identity while shaping how future generations interact with the digital world.
Reference source: https://www.passkeys.com/
Contact us HERE to explore Savyint’s most advanced and secure solutions for authentication and digital identity.






