By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: YubicoPublished October 13, 2025

TL;DR: Passkeys are moving into digital identity wallets through wwWallet, a passkey-enabled wallet project developed by Yubico and European research partners, with pilots now extending into interoperability, credential decryption, and verifiable credential presentation. The shift matters because wallet security, privacy, and cross-border trust now depend on identity controls that span human, NHI, and cryptographic credential lifecycles.


At a glance

What this is: This is an analysis of how passkey-enabled digital identity wallets change credential handling, privacy, and interoperability for emerging wallet ecosystems.

Why it matters: It matters because identity teams will have to govern wallet authentication, credential storage, and presentation flows with controls that fit both human users and the underlying NHI and cryptographic trust chain.

By the numbers:

👉 Read Yubico's analysis of passkey-enabled digital identity wallets


Context

Passkeys are becoming a default authentication pattern, but digital identity wallets introduce a different control problem. The key issue is no longer only how a person signs in, but how the wallet decrypts stored credentials, verifies presentations, and maintains trust across multiple parties and jurisdictions. That makes this an identity governance problem, not just an authentication improvement.

wwWallet matters because it brings passkeys into the wallet layer, where credential storage, presentation, and interoperability all intersect. For IAM teams, the question is whether current identity programmes can govern the cryptographic and operational dependencies behind wallets, especially when pilots expand across borders and institutions.

The article also signals a broader shift toward wallet-based identity ecosystems that blend human authentication with machine-managed trust components. That is familiar territory for NHI governance, where lifecycle, key management, and third-party exposure already determine whether the control plane is secure or merely functional.


Key questions

Q: How should security teams govern passkey issuance in enterprise identity systems?

A: Security teams should treat passkey issuance as a governed identity event, not a simple enrollment action. That means separating identity proofing from credential binding, logging approvals, and aligning recovery and offboarding with the same assurance level as issuance. Without those controls, phishing-resistant authentication can still be attached to an inadequately verified identity.

Q: Why do digital identity wallets matter for IAM governance?

A: Digital identity wallets matter because they shift governance from storing all identity data centrally to controlling how claims are issued, shared, and expired. That gives IAM teams better privacy options, but it also creates new responsibilities around assurance, consent, and validation. The governance question becomes whether the claim was trustworthy at the moment it was presented.

Q: When do passkey wallets become a governance risk rather than a usability improvement?

A: They become a governance risk when pilots expand beyond a single ecosystem and interoperability, recovery, and revocation are not defined. At that point, the technical success of passkey sign-in can hide policy gaps around trust portability, device replacement, and verifier consistency across organisations.

Q: Should organisations pilot wallet-based identity before formal governance is in place?

A: Only in tightly controlled test environments. Once a wallet can hold credentials, sign presentations, or support cross-border use cases, governance has to cover ownership, assurance, recovery, and auditability. Otherwise, the organisation is scaling an identity workflow without knowing who controls the trust chain.


Technical breakdown

How passkeys secure wallet authentication

Passkeys use public-key cryptography so the secret never leaves the authenticating device or security boundary in the same way as a shared password or reusable secret. In a wallet flow, the passkey can authenticate the user into the wallet, unlock the credential store, and support credential presentation without exposing a password that can be phished or replayed. That changes the trust model from reusable bearer secrets to device-bound proof. For identity teams, the architectural question is not just whether passkeys work, but whether every downstream wallet and verifier can handle them consistently across environments.

Practical implication: map wallet sign-in, decryption, and presentation flows to distinct assurance requirements instead of treating them as one authentication event.

Digital identity wallets and verifiable credential presentation

A digital identity wallet is more than a storage container. It is a system that holds credentials, decrypts them for use, and signs presentations to relying parties. That means wallet security depends on the protection of both the credential store and the cryptographic keys that control access to it. In interoperable ecosystems, the wallet must also prove compatibility across different issuers, verifiers, and policy frameworks. This is why wallet design belongs in identity governance, not just in application security or UX discussions.

Practical implication: require explicit ownership for wallet keys, presentation policies, and revocation handling before pilots expand beyond controlled testbeds.

Why interoperability creates governance pressure

Interoperability is the hardest part of wallet-scale identity because trust has to survive across borders, organizations, and use cases. A wallet that works in one pilot can still fail at the governance layer if credential formats, assurance levels, or revocation signals do not align. Once wallets are used for mobility, press credentials, or legal entities, the identity problem becomes multi-issuer and multi-relying-party by design. That is where lifecycle controls, third-party trust boundaries, and auditability become as important as the cryptography itself.

Practical implication: build policy and audit requirements for cross-border wallet pilots before introducing them into production identity estates.


NHI Mgmt Group analysis

Passkey-enabled wallets move identity risk from password compromise to trust-chain governance. The core change is not simply stronger authentication. It is that the wallet now depends on device-bound keys, credential stores, presentation signing, and external relying parties that all have to stay aligned. Practitioners should treat wallet identity as a governed trust chain rather than a single login control.

Wallet ecosystems create a new NHI-adjacent control surface even when the user is human. The wallet itself, the credential store, verifier integrations, and hosting services all behave like managed identities and secrets infrastructure. That means IAM, PAM, and lifecycle thinking becomes relevant long before the wallet reaches end users. The implication is that wallet programmes need identity governance from day one, not after scale exposes gaps.

Interoperability is the real security test for digital identity wallets. Pilots that work inside a narrow federation can still fail when credentials, assurance policies, and presentation rules cross organizational or national boundaries. This is where identity programmes must distinguish technical compatibility from governance compatibility. The practitioner takeaway is to validate trust portability, not just feature parity.

Zero-knowledge and hardware-backed credentials raise the assurance bar, but they also increase governance complexity. Supporting privacy-preserving proof mechanisms in wallets changes how keys are protected, how presentations are verified, and how recovery is handled. Those are not just cryptographic concerns. They are operational controls that determine whether privacy can coexist with supportability and auditability.

Named concept: wallet trust-chain governance. This is the control problem created when authentication, credential decryption, presentation signing, and third-party verification all sit in one workflow. The concept matters because a failure at any point can undermine the whole wallet experience, even if the passkey itself is sound. Practitioners should govern the chain, not the individual component.

From our research:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly identity exposure is typically remediated.
  • That is why lifecycle controls matter in wallet ecosystems too, as outlined in Ultimate Guide to NHIs.

What this signals

Wallet identity will inherit the same governance gaps seen in NHI programmes if teams treat it as a front-end feature. The control issue is not just authenticating the user but managing the cryptographic and service identities that make the wallet usable. In practice, teams should expect audit, recovery, and third-party trust questions to surface as soon as wallets move from pilot to scale.

Wallet trust-chain governance: the next programme risk is not whether passkeys work, but whether the organisation can prove who owns keys, recovery, and verifier trust across the full wallet lifecycle. That should be mapped alongside zero trust and identity lifecycle controls, not after deployment.

With 96% of organisations storing secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, the industry still struggles with credential hygiene at the infrastructure layer. Wallet programmes will fail for the same reason if the supporting services are not governed as identities.


For practitioners

  • Define wallet trust boundaries Document where authentication ends and credential decryption, presentation signing, and verifier trust begin. Separate those control points so each has an owner, an audit trail, and a clear recovery path.
  • Inventory wallet keys and recovery paths Treat wallet keys as governed cryptographic assets with explicit lifecycle handling, including enrollment, backup, revocation, and device replacement. Align recovery options with your assurance model before any production rollout.
  • Test interoperability under policy variance Validate how wallets behave when assurance levels, credential formats, or revocation signals differ between issuers and relying parties. Use cross-border or cross-organisation pilot conditions, not only single-domain success cases.
  • Apply lifecycle controls to wallet services Review the hosting platform, credential issuance services, and verifier integrations as governed identities with provisioning, offboarding, and third-party access requirements. The operational risk sits in the service chain as much as in the user experience.

Key takeaways

  • Passkey-enabled wallets shift the main security question from password resistance to trust-chain governance across authentication, storage, and presentation.
  • The critical risk is not the passkey itself but the supporting identity and service layers that must be owned, audited, and lifecycle-managed.
  • Interoperability across borders and organisations will determine whether wallet identity becomes a governed control plane or another fragmented trust layer.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Wallet authentication and access control map directly to identity assurance and access governance.
NIST SP 800-53 Rev 5IA-2Passkey-based wallet sign-in depends on strong identification and authentication controls.
NIST Zero Trust (SP 800-207)3.1Wallet trust chains align with continuous verification and least privilege principles.

Apply IA-2 to wallet access and ensure authentication requirements match the assurance level of the credential.


Key terms

  • Passkey-Enabled Wallet: A digital identity wallet that uses passkeys to authenticate the user, unlock stored credentials, and sign credential presentations. The security model shifts from shared secrets to device-bound cryptographic proof, which improves phishing resistance but increases the importance of key governance and recovery design.
  • Wallet Trust Chain: The set of linked controls that make a digital wallet usable and trusted, including authentication, credential decryption, presentation signing, verifier validation, and recovery. If any link is weak, the wallet can fail even when the passkey is technically sound.
  • Verifiable Credential Presentation: The act of proving selected credential attributes to a relying party without exposing the underlying credential unnecessarily. In a wallet context, this requires both cryptographic integrity and policy rules that determine what can be shown, to whom, and under what assurance level.
  • Cross-Border Identity Assurance: The ability to prove and rely on identity decisions consistently when they move between organisations or countries. It depends on more than technology compatibility. Governance, privacy treatment, and provider controls all have to hold together for the assurance to remain valid.

What's in the full article

Yubico's full article covers the implementation and ecosystem detail this post intentionally leaves at the analytical level:

  • The wwWallet pilot structure across EU Large Scale Digital Identity Wallet programmes and how interoperability is being tested in practice
  • The role of YubiKeys in the wallet flow, including how hardware passkeys support the pilots' security and privacy goals
  • The collaboration model with SIROS Foundation, ISRG, and other partners working on zero-knowledge and WebAuthn contributions
  • The specific use cases being explored, including digital press passes, student and professional mobility, and business wallets

👉 Yubico's full article covers the wwWallet pilots, hardware passkey role, and interoperability work in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org