Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passkeys in digital identity wallets - are IAM controls ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Passkeys are moving into digital identity wallets through wwWallet, a passkey-enabled wallet project developed by Yubico and European research partners, with pilots now extending into interoperability, credential decryption, and verifiable credential presentation. The shift matters because wallet security, privacy, and cross-border trust now depend on identity controls that span human, NHI, and cryptographic credential lifecycles.

NHIMG editorial — based on content published by Yubico: passkey-enabled digital identity wallets and the wwWallet project

By the numbers:

Questions worth separating out

Q: How should security teams govern passkey issuance in enterprise identity systems?

A: Security teams should treat passkey issuance as a governed identity event, not a simple enrollment action.

Q: Why do digital identity wallets matter for IAM governance?

A: Digital identity wallets matter because they shift governance from storing all identity data centrally to controlling how claims are issued, shared, and expired.

Q: When do passkey wallets become a governance risk rather than a usability improvement?

A: They become a governance risk when pilots expand beyond a single ecosystem and interoperability, recovery, and revocation are not defined.

Practitioner guidance

  • Define wallet trust boundaries Document where authentication ends and credential decryption, presentation signing, and verifier trust begin.
  • Inventory wallet keys and recovery paths Treat wallet keys as governed cryptographic assets with explicit lifecycle handling, including enrollment, backup, revocation, and device replacement.
  • Test interoperability under policy variance Validate how wallets behave when assurance levels, credential formats, or revocation signals differ between issuers and relying parties.

What's in the full article

Yubico's full article covers the implementation and ecosystem detail this post intentionally leaves at the analytical level:

  • The wwWallet pilot structure across EU Large Scale Digital Identity Wallet programmes and how interoperability is being tested in practice
  • The role of YubiKeys in the wallet flow, including how hardware passkeys support the pilots' security and privacy goals
  • The collaboration model with SIROS Foundation, ISRG, and other partners working on zero-knowledge and WebAuthn contributions
  • The specific use cases being explored, including digital press passes, student and professional mobility, and business wallets

👉 Read Yubico's analysis of passkey-enabled digital identity wallets →

Passkeys in digital identity wallets - are IAM controls ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Passkey-enabled wallets move identity risk from password compromise to trust-chain governance. The core change is not simply stronger authentication. It is that the wallet now depends on device-bound keys, credential stores, presentation signing, and external relying parties that all have to stay aligned. Practitioners should treat wallet identity as a governed trust chain rather than a single login control.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly identity exposure is typically remediated.

A question worth separating out:

Q: Should organisations pilot wallet-based identity before formal governance is in place?

A: Only in tightly controlled test environments. Once a wallet can hold credentials, sign presentations, or support cross-border use cases, governance has to cover ownership, assurance, recovery, and auditability. Otherwise, the organisation is scaling an identity workflow without knowing who controls the trust chain.

👉 Read our full editorial: Passkeys in digital identity wallets: what wwWallet changes



   
ReplyQuote
Share: