Skip to main content

What's New on Passkey Central

October 2026

Passkey Central continues to evolve. We have updated the navigation menu to help guide you through the stages of deployment. A new section titled Considerations for Workforce covers what changes when the people signing in are your employees rather than your customers.

A structure that follows your rollout​

The new navigation menu has eight sections, each named for actions you should take at that stage of a deployment. Divider lines in the side navigation group the sections into stages.

The content and existing pages are still live and accessible. No content was removed. The original URLs have been redirected to the new locations, including the Japanese and Korean versions so that your bookmarks, internal wikis, and links in published guidance continue to work. Page titles and their order have been updated to help you reference the content.

The following table outlines these changes:

Current NavigationDeployment StagePrevious NavigationTopics covered
Introduction to PasskeysLearnIntroduction to PasskeysHow Passkeys Work
Passkey Types
Passkey Use Cases
The Passkey Experience
Passkey Security
Build the Business CaseJustifyIdentify Your NeedsBenefits and Costs
Business Metrics
Next Steps
Live Implementations of Passkeys (moved here from Resources and Tools)
Plan Your RolloutDefinePasskey Roll-Out GuidesCompare the FIDO Passkey Roll-Out Guides
Two detailed guides: Gradually Adopt Passkeys and Rapidly Adopt Passkeys
Design User JourneysDefineDesign GuidelinesPrinciples
Patterns: Required, Optional, and Security Key
Communications and Messaging (User Communications, Messaging Guidelines for Passkey Failure States, How to Translate Passkey)
Passkey Accessibility
FIDO's Figma Kits
Launch and GrowExecute and expandDeveloper Documents and Troubleshooting (both formerly top-level), plus pages from Resources and Tools and the roll-out guidesDeveloper Documents
Customer Support
Troubleshooting Guidance
The Future of Passkeys
Prevent Phishing Attacks
Considerations for WorkforceSpecializedNewSpecial Considerations for Workforce Deployments
Workforce Passkey Deployment Guide
Workforce Case Studies
Client Hints for Workforce Deployments
Resources and UpdatesReferenceResources and Tools, News and EventsNews and Events
2025 Wrap-Up: Passkey Upgrades and Improvements
Feedback on Passkey Deployments
FIDO Certified Organizations
Glossary of Terms
FIDO Alliance newsletter
Underwriters

Two changes are worth calling out. First, the material that used to sit in the Resources and Tools section has been placed where it is used: communications, accessibility, and the Figma kits are now design material, customer support and troubleshooting are launch material, and live implementations support the business case. Second, the FIDO Authentication Specifications page was removed from Passkey Central; its old address redirects to the specifications overview on fidoalliance.org.

New content: Considerations for Workforce​

Passkey Central was originally written with a focus on consumer-facing services. This new section addresses organizations who are deciding how to replace passwords and phishable Multi-Factor Authentication (MFA) for their own employees.

WebAuthn and CTAP apply equally to both implementations. However, there are several differences in the context around the credential: who controls enrollment, where credentials may be stored, how recovery works when a help desk is involved, and how policy is enforced. The Considerations for Workforce section is dedicated to these questions.

The section covers:

  • Special Considerations for Workforce Deployments. The section overview page. It covers what stays the same for employees (phishing resistance, a simpler sign-in, privacy by design) and the three areas that need deliberate decisions: the identity provider as the authentication target, lifecycle management under IT control, and the choice between synced and device-bound credentials. A comparison table summarizes where consumer and workforce deployments diverge.
  • Workforce Passkey Deployment Guide. This page is written for organizations that already use a central identity provider for single sign-on. It starts with two prerequisites, assessing your environment and defining success, then walks through the six phases of deployment: planning and infrastructure, building the rollout infrastructure, pilot and iteration, organic opt-in, mandatory enforcement, and post-rollout maintenance.
  • Workforce Case Studies. Published accounts of workforce deployments at Semperis, RSA, MIXI, Wedding Park, Target, and Cloudflare.
  • Client Hints for Workforce Deployments. An FAQ on the WebAuthn hints parameter: what it does, how it differs from authenticatorSelection, why it is advisory rather than an enforcement mechanism, what happens when a client ignores a hint, and how to test across mixed browser and operating-system environments.

What this means for you​

The practical benefit is less hunting. Content is now grouped by the question you are answering, not by the format it happens to be in, so the material for any one stage of a deployment is in one place.

  • If you are building the case internally: Build the Business Case now contains the benefits-and-costs analysis, the metrics to track, and the list of live implementations you can point to, in one section.
  • If you are planning a rollout: Plan Your Rollout keeps the two detailed guides and the comparison between them. Every deployment starts gradually; the guides help you decide how aggressively to move to a rapid transition and what that requires in investment, process, change management, and scope.
  • If you design the user experience: Design User Journeys now includes all content around what the user sees and reads: the required and optional patterns, security key patterns, accessibility, the Figma kits, and the new Communications and Messaging group covering user communications, failure-state messaging, and translation of the term passkey.
  • If you are launching and operating: Launch and Grow brings together the developer documents, customer support guidance, and the six troubleshooting guides, alongside the longer-horizon material on where passkeys are heading and how to move from partial to full phishing prevention.
  • If you are responsible for workforce identity: Considerations for Workforce provides a starting point that is written for your environment, rather than adapted from consumer guidance.

For the Japanese and Korean editions, the structure and redirects are identical.

Where to start​

If you are new to the site, begin with Introduction to Passkeys and work down the sidebar in order. If you are mid-deployment, go straight to the section for your stage; the Home page overview links to each one. If you manage employee authentication, begin with Introduction to Passkeys and then go to Considerations for Workforce.

We are continuously looking at ways to improve Passkey Central. If a link is broken, a page is hard to find, or something you need is missing, you can let us know through the feedback mechanism on the site.