{"title":"Passkey authentication","category":"default","creationDate":1790074618,"content":"<p>Passkey authentication is a form of Strong Customer Authentication (SCA) that saves a passkey on the cardholder's device. The first time the cardholder authenticates a card transaction by completing an SCA challenge, they register their biometrics or a PIN code as a passkey. For all subsequent transactions on the same device, they authenticate using the registered biometrics or PIN instead of completing a new SCA challenge.<\/p>\n<h2>Requirements<\/h2>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: left;\">Requirement<\/th>\n<th style=\"text-align: left;\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: left;\"><strong>Integration type<\/strong><\/td>\n<td style=\"text-align: left;\"><a href=\"\/issuing\">Adyen Issuing<\/a><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Limitations<\/strong><\/td>\n<td style=\"text-align: left;\"><ul><li markdown=\"1\">Passkey authentication is not supported for card transactions that are enrolled in 3d secure using <a href=\"\/issuing\/3d-secure\/oob-auth-sdk\">Out-of-band authentication<\/a>.<\/li><li markdown=\"1\">Passkey authentication is only supported for native password managers. Native password managers are built-in credential management systems developed directly by the operating system (OS) or hardware manufacturer. Third-party password managers are not supported.<\/li><li markdown=\"1\">You can register a maximum of five passkeys to a single card. To register more than five passkeys, reach out to our <a href=\"https:\/\/ca-test.adyen.com\/ca\/ca\/contactUs\/support.shtml?form=other\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Support Team<\/a>.<\/li><\/ul><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Setup steps<\/strong><\/td>\n<td style=\"text-align: left;\">Before you begin, you must enroll the cardholder's cards in 3d secure using <a href=\"\/issuing\/3d-secure\/password-otp\">One-time password authentication<\/a>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Register a passkey<\/h2>\n<p>The cardholder can register their passkey the first time they make an online payment, and get redirected to a 3D Secure authentication page.<\/p>\n<div class=\"notices green\">\n<p>If no passkey is registered, the cardholder continues to use the <a href=\"\/issuing\/3d-secure\/password-otp\">one-time password authentication method<\/a> for all transactions.<\/p>\n<\/div>\n<p>To register a passkey, the cardholder must:<\/p>\n<ol>\n<li>\n<p>Complete the SCA challenge successfully, using the <a href=\"\/issuing\/3d-secure\/password-otp\">one-time password authentication method<\/a>.<\/p>\n<p><a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/SCA-challenge.png\" src=\"\">\n  <img alt=\"Authenticate using SCA\" src=\"\/images\/3\/d\/0\/1\/7\/3d017f59efc85728e9bfedf8947ee964a56a114f-sca-challenge.png\" \/>\n<\/a><\/p>\n<\/li>\n<li>\n<p>When prompted to register a passkey, select <strong>Create passkey<\/strong>. You can register a maximum of five passkeys to a single card. To register more than five passkeys, reach out to our <a href=\"https:\/\/ca-test.adyen.com\/ca\/ca\/contactUs\/support.shtml?form=other\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Support Team<\/a>.<\/p>\n<p><a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/create-passkey.png\" src=\"\">\n  <img alt=\"Create passkey\" src=\"\/images\/4\/e\/f\/f\/d\/4effd68e2e96358873bed9d84ee125990a0c7df2-create-passkey.png\" \/>\n<\/a><\/p>\n<div class=\"notices green\">\n<p>If the cardholder selects <strong>Continue without passkey<\/strong>, no passkey is registered, and the cardholder continues to use the <a href=\"\/issuing\/3d-secure\/password-otp\">one-time password authentication method<\/a> for future transactions.<\/p>\n<\/div>\n<\/li>\n<li>\n<p>Set up their passkey with their preferred authentication method:<\/p>\n<ul>\n<li>If their device supports biometrics, they can register their biometrics.<\/li>\n<li>If their device does not support biometrics, they must set up a PIN code.<\/li>\n<\/ul>\n<p><a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/set-up-passkey.png\" src=\"\">\n  <img alt=\"Set up passkey\" src=\"\/images\/f\/9\/e\/d\/5\/f9ed51e9be872c06354e3ccfd7807ad607865ecc-set-up-passkey.png\" \/>\n<\/a><\/p>\n<\/li>\n<li>\n<p>Authenticate using the biometrics or PIN code they just registered.<br \/>\n<a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/authenticate-with-biometrics-or-pin.png\" src=\"\">\n  <img alt=\"Authenticate with biometrics or pin code\" src=\"\/images\/6\/8\/a\/6\/f\/68a6fbbb396817f96b658c41edae17003a38c2bd-authenticate-with-biometrics-or-pin.png\" \/>\n<\/a><\/p>\n<\/li>\n<li>\n<p>If successful, the cardholder receives a confirmation that the passkey was created successfully. Select <strong>Continue<\/strong>.<\/p>\n<p><a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/passkey-created.png\" src=\"\">\n  <img alt=\"Passkey created\" src=\"\/images\/1\/4\/6\/6\/2\/14662ce6e83b9012315fdfa37f82c176581e6f89-passkey-created.png\" \/>\n<\/a><\/p>\n<\/li>\n<\/ol>\n<p>The passkey is saved to the cardholder's password manager. For all future transactions on the same device, the cardholder can authenticate using the biometrics or PIN they registered.<\/p>\n<h2>Authenticate using a passkey<\/h2>\n<p>After a cardholder has registered a passkey, they can use it to authenticate all subsequent transactions on the same device. To do this, they must do the following:<\/p>\n<ol>\n<li>\n<p>When prompted to authenticate their transaction, select <strong>Authenticate with Passkey<\/strong>.<br \/>\n<a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/choose-auth-method.png\" src=\"\">\n  <img alt=\"Choose authentication method\" src=\"\/images\/e\/0\/4\/e\/2\/e04e243a4a731659ee0c9a92f76ad9e79f1d9d33-choose-auth-method.png\" \/>\n<\/a><\/p>\n<\/li>\n<li>\n<p>Provide their registered biometrics or PIN code.<br \/>\n<a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/authenticate-with-biometrics-or-pin.png\" src=\"\">\n  <img alt=\"Authenticate with biometrics or pin code\" src=\"\/images\/6\/8\/a\/6\/f\/68a6fbbb396817f96b658c41edae17003a38c2bd-authenticate-with-biometrics-or-pin.png\" \/>\n<\/a><\/p>\n<\/li>\n<li>\n<p>If the authentication is successful, select <strong>Continue<\/strong>. This completes the SCA challenge and the payment becomes ready for authorization.<\/p>\n<p><a rel=\"lightbox\" href=\"\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/authentication-complete.png\" src=\"\">\n  <img alt=\"Authentication complete\" src=\"\/images\/b\/3\/e\/9\/6\/b3e9696ed4d3f3ee027bdf270b173baa6aea32ad-authentication-complete.png\" \/>\n<\/a>.<\/p>\n<\/li>\n<\/ol>\n<p>If the authentication fails, the cardholder can either retry the authentication, or authenticate using the <a href=\"\/issuing\/3d-secure\/password-otp\">one-time password authentication method<\/a>.<\/p>\n<h2>Delete a passkey<\/h2>\n<p>You may want to delete a passkey if:<\/p>\n<ul>\n<li>The device where the passkey is registered is lost, stolen, or no longer in use.<\/li>\n<li>You want to register a new passkey but have already reached the maximum of five passkeys for a single card.<\/li>\n<li>You no longer want to use passkey authentication on a specific device.<\/li>\n<\/ul>\n<p>To delete a passkey, reach out to our <a href=\"https:\/\/ca-test.adyen.com\/ca\/ca\/contactUs\/support.shtml?form=other\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">Support Team<\/a>.<\/p>\n<p>After a passkey is deleted, the cardholder can no longer use it to authenticate transactions. For future transactions on that device, the cardholder will need to authenticate using the one-time password authentication method.<\/p>","url":"https:\/\/docs.adyen.com\/issuing\/3d-secure\/passkeys","articleFields":{"description":"Learn how passkey authentication works for your Adyen-issued cards.","feedback_component":true},"algolia":{"url":"https:\/\/docs.adyen.com\/issuing\/3d-secure\/passkeys","title":"Passkey authentication","content":"Passkey authentication is a form of Strong Customer Authentication (SCA) that saves a passkey on the cardholder's device. The first time the cardholder authenticates a card transaction by completing an SCA challenge, they register their biometrics or a PIN code as a passkey. For all subsequent transactions on the same device, they authenticate using the registered biometrics or PIN instead of completing a new SCA challenge.\nRequirements\n\n\n\nRequirement\nDescription\n\n\n\n\nIntegration type\nAdyen Issuing\n\n\nLimitations\nPasskey authentication is not supported for card transactions that are enrolled in 3d secure using Out-of-band authentication.Passkey authentication is only supported for native password managers. Native password managers are built-in credential management systems developed directly by the operating system (OS) or hardware manufacturer. Third-party password managers are not supported.You can register a maximum of five passkeys to a single card. To register more than five passkeys, reach out to our Support Team.\n\n\nSetup steps\nBefore you begin, you must enroll the cardholder's cards in 3d secure using One-time password authentication.\n\n\n\nRegister a passkey\nThe cardholder can register their passkey the first time they make an online payment, and get redirected to a 3D Secure authentication page.\n\nIf no passkey is registered, the cardholder continues to use the one-time password authentication method for all transactions.\n\nTo register a passkey, the cardholder must:\n\n\nComplete the SCA challenge successfully, using the one-time password authentication method.\n\n  \n\n\n\nWhen prompted to register a passkey, select Create passkey. You can register a maximum of five passkeys to a single card. To register more than five passkeys, reach out to our Support Team.\n\n  \n\n\nIf the cardholder selects Continue without passkey, no passkey is registered, and the cardholder continues to use the one-time password authentication method for future transactions.\n\n\n\nSet up their passkey with their preferred authentication method:\n\nIf their device supports biometrics, they can register their biometrics.\nIf their device does not support biometrics, they must set up a PIN code.\n\n\n  \n\n\n\nAuthenticate using the biometrics or PIN code they just registered.\n\n  \n\n\n\nIf successful, the cardholder receives a confirmation that the passkey was created successfully. Select Continue.\n\n  \n\n\n\nThe passkey is saved to the cardholder's password manager. For all future transactions on the same device, the cardholder can authenticate using the biometrics or PIN they registered.\nAuthenticate using a passkey\nAfter a cardholder has registered a passkey, they can use it to authenticate all subsequent transactions on the same device. To do this, they must do the following:\n\n\nWhen prompted to authenticate their transaction, select Authenticate with Passkey.\n\n  \n\n\n\nProvide their registered biometrics or PIN code.\n\n  \n\n\n\nIf the authentication is successful, select Continue. This completes the SCA challenge and the payment becomes ready for authorization.\n\n  \n.\n\n\nIf the authentication fails, the cardholder can either retry the authentication, or authenticate using the one-time password authentication method.\nDelete a passkey\nYou may want to delete a passkey if:\n\nThe device where the passkey is registered is lost, stolen, or no longer in use.\nYou want to register a new passkey but have already reached the maximum of five passkeys for a single card.\nYou no longer want to use passkey authentication on a specific device.\n\nTo delete a passkey, reach out to our Support Team.\nAfter a passkey is deleted, the cardholder can no longer use it to authenticate transactions. For future transactions on that device, the cardholder will need to authenticate using the one-time password authentication method.","type":"page","locale":"en","boost":17,"hierarchy":{"lvl0":"Home","lvl1":"Adyen Issuing","lvl2":"Enroll cards in 3D Secure","lvl3":"Passkey authentication"},"hierarchy_url":{"lvl0":"https:\/\/docs.adyen.com\/","lvl1":"https:\/\/docs.adyen.com\/issuing","lvl2":"https:\/\/docs.adyen.com\/issuing\/3d-secure","lvl3":"\/issuing\/3d-secure\/passkeys"},"levels":4,"category":"Issuing","category_color":"green","tags":["Passkey","authentication"]},"articleFiles":{"authenticate-with-biometrics-or-pin.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/authenticate-with-biometrics-or-pin.png\" \/>","authentication-complete.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/authentication-complete.png\" \/>","choose-auth-method.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/choose-auth-method.png\" \/>","create-passkey.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/create-passkey.png\" \/>","passkey-created.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/passkey-created.png\" \/>","SCA-challenge.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/SCA-challenge.png\" \/>","set-up-passkey.png":"<img alt=\"\" src=\"https:\/\/docs.adyen.com\/user\/pages\/docs\/07.issuing\/22.3d-secure\/03.passkeys\/set-up-passkey.png\" \/>"}}
