Passwords are dying on GOV.UK - but only if you opt in to passkeys
The government says millions can now ditch passwords for GOV.UK One Login, but it's a choice, not a mandate, and the security upside depends on your device already having biometrics set up.
What’s actually changing
GOV.UK One Login, the sign-in system behind services like renewing a driving licence or applying for childcare support, is rolling out passkeys to its full user base of more than 23 million people. Passkeys let you log in with a fingerprint, Face ID, or device PIN instead of typing a password and waiting for a text message code.
This isn’t a brand-new pilot. Around 300,000 users already switched over during an earlier trial phase, and the government says that expansion is now moving from “trial” to “available to millions more”. Nearly one in ten daily sign-ins on the platform are now happening via passkey, according to the announcement.
How it’s supposed to work
Passkeys work differently from passwords. Rather than a secret you type and could accidentally hand over to a scam email, a passkey is cryptographic proof tied to your specific device and the specific website it was created for. There’s nothing to guess, nothing to phish, and no code sitting in a database somewhere waiting to be leaked in a breach.
Crucially, the fingerprint or PIN you use to unlock a passkey never leaves your device. GOV.UK One Login doesn’t see or store your biometric data - it only gets confirmation that your device verified you. That’s a meaningfully different security model to a password, which does have to be transmitted and checked against a stored record.
The government also claims passkey logins are up to eight times faster than the old password-plus-SMS-code combination, and that shifting sign-ins away from text messages is saving the taxpayer close to £600 a day in SMS costs - a modest but real efficiency gain given the scale of the platform.
So who is actually affected
If you already use GOV.UK One Login for things like tax, benefits, or vehicle services, you’re in scope, but nothing is being forced on you. This is an opt-in feature, not a replacement that locks out password users overnight. You’ll need a phone, tablet or computer that supports passkeys - most modern smartphones with fingerprint or face unlock already do - and you’ll set one up through your existing account.
If you don’t use GOV.UK One Login at all, or you’re happy sticking with a password and a text code, this change doesn’t touch you. The rollout is about giving people an additional, faster route in, not shutting down the old one.
What to do about it
If you want to try it, look for the passkey option next time you sign in to a GOV.UK One Login service and follow the setup prompts - it typically takes a minute or two on a supported device. There’s no requirement to switch, and no indication in the announcement that password-based login is being phased out entirely.
Worth noting: the specific numbers here - the 23 million user base, the 300,000 early adopters, the “one in ten” sign-in stat, the £600 daily saving - all come from the government’s own release rather than an independent audit. They’re plausible and consistent with how passkeys behave elsewhere, but they haven’t been verified by a third party.
The takeaway
Passkeys genuinely remove some of the weakest links in password-based security - reuse, phishing, and forgettable strings of characters - and GOV.UK making them available at scale is a sensible, low-risk move for anyone who opts in. It’s a convenience upgrade with a real security benefit, not a mandatory overhaul, so there’s no need to panic if you’d rather keep typing your password for now.