TL;DR: Passkeys and digital identity credentials are moving into the same customer journey, but they solve different problems: passkeys prove access while digital credentials prove attributes, according to Authsignal. The operational challenge is no longer support for each method in isolation, but deciding where each belongs across enrollment, recovery, fallback and regulated verification before expectations harden.
NHIMG editorial — based on content published by Authsignal: Digital identity credentials and passkeys: what businesses need to prepare for next
By the numbers:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should organisations decide when to use passkeys versus digital identity credentials?
A: Use passkeys when the goal is secure account access, and use digital credentials when the business needs a verified attribute such as age, entitlement, or regulated identity evidence.
Q: Why do passkeys improve security but still require IAM governance?
A: Passkeys improve security by reducing phishing and secret theft, but IAM governance is still required because identity risk moves to enrollment, device trust, and recovery.
Q: What breaks when recovery and fallback are not designed for credential-based journeys?
A: Users fall back into weaker methods, support teams improvise exceptions, and attackers target the recovery path instead of the primary authenticator.
Practitioner guidance
- Separate access proof from attribute proof Define which journeys need a passkey, which need a digital credential, and which need both.
- Design fallback paths before launch Document what happens when a customer lacks a credential, loses a device, or cannot present an otherwise valid credential.
- Map issuer trust and attribute minimisation rules Limit the attributes you request to the minimum needed for the transaction, and record which issuers are trusted for each claim.
What's in the full article
Authsignal's full blog covers the operational detail this post intentionally leaves for the source:
- Journey-level examples for when a passkey alone is sufficient and when a digital credential should be requested.
- Operational guidance on handling recovery when a customer has a credential but cannot present it.
- Implementation detail on how wallet-based credentials fit into existing authentication orchestration.
- Practical discussion of customer journey design across app, web, and contact-centre channels.
👉 Read Authsignal's analysis of passkeys and digital identity credentials →
Digital credentials and passkeys: what IAM teams need to prepare for?
Explore further
Passkeys and digital credentials should be treated as different identity primitives, not competing replacements. Passkeys secure account access, while digital credentials prove attributes that may be needed only at onboarding or in higher-risk transactions. Conflating them creates over-verification, bad journeys, and weak control design. Practitioners should build policy that chooses the right proof for the right moment, not a single method for every interaction.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, a reminder that identity assurance failures often surface as operational damage rather than isolated incidents.
A question worth separating out:
Q: Who should own policy for digital credential acceptance in a customer identity programme?
A: Identity, security, privacy, and product teams should share ownership, but identity governance must define the acceptance rules. The business needs clear policy for trusted issuers, minimum attributes, recovery, and exception handling, because these choices shape both risk and user experience.
👉 Read our full editorial: Passkeys and digital credentials are converging in customer identity