Passkeys: moving from pilot to production
Passkeys remove shared secrets from routine authentication, but a production rollout still depends on enrolment, recovery, device coverage and support processes that users can complete safely.
Begin with account states
Map new registration, existing-user enrolment, replacement devices, shared devices and account recovery before changing the sign-in screen. A passkey should be bound to a verified account session, and sensitive enrolment changes should create an auditable notification through an independent channel.
Keep a controlled transition path
Support existing authentication while coverage grows, but do not let the fallback become an easier route around the passkey. Apply equivalent risk checks to password reset and recovery, rate-limit attempts, and record which authenticators and synchronisation models are accepted.
Measure completion and recovery
Track enrolment success, authentication completion, fallback use, device-family failures and support-assisted recovery. Separate users who decline enrolment from those whose platform cannot complete it; they require different product and support responses.
A phishing-resistant primary factor is undermined if an attacker can reach the same account through a weak recovery question or an unverified helpdesk reset.