News, events & blog
Passkeys Have Gone Mainstream: Your Authentication Strategy Should Follow
In 2026, the alternative is no longer experimental. According to the FIDO Alliance, an estimated 5 billion passkeys are now in active use worldwide. Its latest research found that 90% of surveyed consumers were familiar with passkeys, 75% had enabled one on at least one account, and 68% of surveyed organisations were deploying, piloting or rolling them out for employee authentication.
The direction is becoming difficult to ignore: authentication is moving away from proving that someone knows a secret and towards proving that the right person controls the right credential. For service providers, however, replacing passwords is only part of the problem.
Why are passwords no longer enough?
Think of a password as a key that can be copied perfectly without its owner noticing. Once someone knows the password, the service receiving it has relatively little information with which to distinguish its legitimate owner from an attacker.
Adding SMS codes improved that model, but it did not fundamentally solve the phishing problem. Users can still be persuaded to enter credentials and one-time codes into fraudulent websites. Passkeys change the architecture.
Instead of sending a reusable secret to a server, FIDO-based authentication relies on public-key cryptography. The private credential remains with the user's authenticator, while the service verifies cryptographic proof during authentication. This makes passkeys inherently resistant to conventional credential phishing. That distinction is becoming increasingly important as phishing itself becomes easier to automate and personalise.
The 2026 FIDO research also illustrates why simply supporting passkeys isn't the same as eliminating the problem: even among organisations that had deployed passkeys, 57% still relied on phishable methods for primary everyday workforce authentication. In other words, adding a secure door does not help much if the old door remains open next to it.
Authentication and identification are not the same thing
There is another distinction service providers should consider.
Authentication answers: Is this the same user who authenticated before?
Identity verification answers: Who is this person in the first place?
A passkey can provide excellent authentication without necessarily telling a business the verified real-world identity behind an account. Imagine issuing extremely secure access cards to an office. The cards might be almost impossible to copy, but that does not help if you never established who received each card.
Digital services increasingly need both layers. A marketplace may need to identify a seller before allowing transactions. A financial service may need to establish the customer's legal identity. A SaaS platform may need stronger authentication for sensitive actions. A cross-border service may need to identify customers from ten different countries using ten different national electronic identity systems.
The technical challenge therefore becomes bigger than simply "adding passkeys". It becomes identity orchestration.
The international identity problem
Strong digital identities already exist across Europe. Estonia has ID-card, Mobile-ID and Smart-ID. Latvia has Smart-ID and eParaksts. Lithuania has Smart-ID and Mobile-ID. Belgium has CSAM. Czechia has MojeID. Portugal has Autenticação.gov. Sweden has Freja+. And European electronic identification continues to develop through eIDAS.
For an international service provider, however, supporting strong national identification can create an architectural problem: every additional identity system can mean another integration, another relationship to maintain and another component of authentication infrastructure to operate.
This is exactly the problem Estonian Internet Foundation designed eeID to simplify.
Instead of integrating separately with multiple identification systems, businesses can connect once and access multiple national and international authentication methods through the same service. eeID currently supports eIDAS alongside electronic identification solutions from Estonia, Latvia, Lithuania, Belgium, Czechia, Portugal and Sweden. For customers beyond supported national systems, global document and video identification is available through Veriff.
The result is less like building ten separate roads and more like connecting your application to an identity interchange.
Where FIDO fits into eeID
Once a person's identity has been established, repeatedly asking them to identify themselves would create unnecessary friction. This is where FIDO-based passwordless authentication becomes particularly useful.
With eeID, a strong digital identity can be established and subsequently used for convenient passwordless authentication. The user does not have another password to remember, while the service provider gains an authentication mechanism designed around modern security standards rather than shared secrets. That creates a useful architecture:
Strong identification → trusted digital identity → passwordless authentication.
The expensive or higher-friction identity check can therefore happen when it actually matters, while subsequent authentication can remain fast. Security and usability stop being opposing requirements.
One integration can also reduce a hidden security problem
Authentication architecture creates operational risk of its own. Every additional identity provider can mean APIs, certificates, keys, configuration, documentation, monitoring and lifecycle management that someone inside the organisation must maintain. The more integrations you operate, the larger the operational surface becomes.
Centralising access to multiple identification methods therefore isn't merely a developer-convenience argument. It can simplify the identity infrastructure that security and engineering teams are responsible for maintaining.
That is one of eeID's core design principles: provide strong identification with international reach while moving much of the administrative complexity associated with individual identity solutions outside the service provider.
Passwordless authentication is becoming infrastructure
Five billion passkeys should change how businesses think about passwordless authentication. Passkeys are no longer a feature being tested by a handful of technology companies. They are increasingly becoming part of the basic identity infrastructure of the internet.
But the more important question for service providers isn't simply:
"Should we support passkeys?"
It is:
"How do we know who our customer is, and how do we authenticate that person securely afterwards - regardless of where in the world they come from?"
Those are two different problems, and modern identity architecture needs to solve both.
eeID brings those layers together: strong electronic identification, international identity methods, global document verification and FIDO-based passwordless authentication through a single service.
If your authentication stack still begins and ends with a password field, 2026 is a good year to reconsider the architecture.
Ready to simplify strong authentication and international identity verification? Explore eeID and see how it can fit into your service
See the latest news and blogs:
News
Statistics
What New .ee Domain Names Reveal About Estonia’s Business Landscape
Estonia’s national domain recorded exceptionally strong growth in the second quarter of 2026. By the end of June, the number of registered .ee domains had reached 199,647, an increase of more than 26,000 domains compared with the same time in 2025. The registry passed the milestone of 200,000 registered .ee domains at the beginning of July.
News
eeID
Identity Fraud Report 2026: Key Stats & How eeID Helps
Veriff's new Identity Fraud Report 2026 has a blunt message: online fraud isn't a background risk anymore. It's a core business threat, and it's getting smarter every month. If your business verifies customers, employees, or partners online, the report is a signal to check how you confirm who's really on the other end. Here's what the data shows, and why eeID is built to answer it.
News
Domain Regulations
Proposed Changes to .ee Domain Rules Now Open for Community Feedback
Estonian Internet Foundation (EIF) has developed proposed amendments to the .ee domain rules, driven by the objectives set out in the 2025–2027 EIF strategy. These changes are intended to help develop registry services that better meet the expectations of the community. We are now also inviting feedback on these proposals from the community.