TL;DR: Passkeys are moving from pilot to production at scale, with more than 3 billion in use worldwide, but conference sessions showed that the hard problems are enrolment timing, recovery, platform variance, and post-authentication trust, according to OneSpan and FIDO Alliance discussions. Authentication now has to be treated as part of the full account lifecycle, not a single login control.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “FIDO Authenticate 2025 : Ce que j'ai appris sur les passkeys à grande échelle”.
Key questions
Q: What breaks when passkey recovery is not governed properly?
A: The programme falls back to the weakest legacy recovery path, which attackers often target first.
Q: Why do passkey rollouts often look better on mobile than on desktop?
A: Mobile users are already trained to use biometrics and device-bound authentication, so the interaction feels familiar.
Q: How should teams implement passkeys across the full account lifecycle?
A: They should govern enrolment, recovery, device replacement, and post-login session assurance as one lifecycle, not as separate workstreams.
Practitioner guidance
- Map the full account journey Document enrolment, recovery, device change, and sign-in fallback paths as one control chain, then identify where weaker methods can still override a passkey.
- Move enrolment to trusted moments Trigger passkey registration immediately after account creation or a successful sign-in, when the user is already authenticated and more likely to complete the flow.
- Segment adoption by platform Track mobile and desktop adoption separately, and review browser or OS-specific drop-offs before assuming the rollout has a single success rate.
Bottom line: Passkeys reduce login friction only if the surrounding account processes stop undermining them with weaker recovery and reset paths.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passkey programmes fail when teams treat authentication as a point control rather than a lifecycle control. The article shows that the hardest problems appear after the cryptographic login is already working, especially around recovery, device replacement, and fallback authentication. That means the real governance question is not whether passkeys function, but whether the surrounding identity process preserves their assurance under change. Practitioners should govern the whole account journey, not just the login ceremony.
A few things that frame the scale:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
A question worth separating out:
Q: Should organisations replace passwords everywhere before improving password recovery?
A: No. Teams should first make recovery and support paths consistent, because users judge the new authentication model by what happens when something goes wrong. If fallback is messy, passwordless adoption suffers even when the primary login is strong. A clean recovery design is part of the control, not an afterthought.
👉 Read our full editorial: Passkeys at scale expose the gap between login and lifecycle