NEWPlatformJul 25, 2026
Bibkins-rabbit moves beyond passwords
A faster, safer sign-in is rolling out without another password to remember.
Passkeys have crossed a scale milestone that changes the authentication conversation. The FIDO Alliance estimates that five billion passkeys are now in use worldwide, while its State of Passkeys 2026 research reports broad consumer awareness and growing enterprise deployment. The numbers do not make passwords obsolete overnight, but they make passwordless sign-in a mainstream product decision rather than an experiment.

FIDO’s five-billion figure is an ecosystem estimate, not a live counter that can identify every credential on every device. The organization paired that estimate with research involving 11000 consumers and 1400 enterprise decision-makers across ten countries. In the survey, 90% of consumers said they were aware of passkeys, 75% had enabled one on at least one account and 49% used them regularly when the option was available. Those are self-reported research results, so they describe the surveyed population rather than universal behavior.
The enterprise findings point in the same direction. FIDO reported that 68% of organizations had deployed passkeys or were actively deploying them for employee sign-ins, and 82% described a fully passwordless workforce as an ultimate goal. Organizations that had deployed passkeys associated them with faster login, stronger security confidence and fewer support problems. At the same time, the report says many workplaces still rely on authentication methods that can be phished, which helps explain why passkey availability and passkey habit are not yet the same thing.
A passkey uses public-key cryptography and is bound to the service for which it was created. The server stores a public key, while the private credential remains protected by the user’s device or credential provider. Sign-in is approved with the same device gesture people already use for local unlock, such as a fingerprint, face check or PIN. Because the credential is scoped to the legitimate site or app, a convincing look-alike page cannot simply collect a reusable secret in the way it can steal a password.
That security improvement also removes several pieces of everyday friction. There is no password to invent, remember, type on a small keyboard or rotate after another company reports a breach. Yet a responsible rollout still needs clear answers for device replacement, account recovery, shared devices and people who cannot use a preferred biometric method. Platforms should keep recovery resistant to social engineering, explain where a passkey is saved and provide an accessible fallback without quietly rebuilding the weakest parts of password authentication.
At five billion estimated credentials, the question is no longer whether major operating systems and browsers can support passkeys. The harder work is helping people recognize the option, understand the prompt and recover confidently when their circumstances change. Services that offer passkeys only after a long trip through security settings will see different results from those that introduce them at a useful moment and explain the benefit in one sentence. Passwords will remain during a long transition, especially on legacy and rarely used accounts. But the combination of reach, phishing resistance and simpler sign-in now gives product teams a credible default to work toward.