Passkeys and biometrics

This page explains how NHS login uses passkeys and biometric sign-in, and what this means for partner integrations.

For most partners, no change is needed.

Information:

Continue to use your standard NHS login OpenID Connect integration. You do not need to make technical changes to that integration to support FIDO2 passkeys. FIDO1 is not available for partner onboarding.

Passkeys (FIDO2)

NHS login supports passkeys. Passkeys are based on the FIDO2 authentication standard.

A user may unlock a passkey on their device using biometrics, a device PIN or a security key.

NHS login manages the user's biometric or passkey credential as part of the sign-in journey. Your service does not receive the user's biometric data.

If your service has a native mobile app, supporting passkeys can require technical changes in that app.

FIDO2 in WebView apps

WebViews do not support FIDO2 passkeys. If your native mobile app uses a WebView, users cannot add or use passkeys in that WebView. This affects the passkey experience in the app; it does not change your standard NHS login OpenID Connect integration.

To understand what users see when they set up and use a passkey, see the NHS login Help Centre passkey guidance.

Biometric sign-in (FIDO1)

NHS login supports biometric sign-in as part of the NHS login journey. This is sometimes referred to as FIDO1. It is not a separate integration for partner services.

Developer support

If you need help with biometric sign-in, passkeys or an existing FIDO1 integration, contact NHS login developer support.