Definition

A passkey is a passwordless sign-in credential based on the FIDO Alliance and W3C WebAuthn standards, in which a public-private key pair replaces the password and the service stores only the public key.

When a user registers, their device creates a key pair unique to that service. The service keeps the public key; the private key stays in the device's secure hardware or in the user's credential manager, which can sync it across their own devices. To sign in, the service sends a challenge, the user unlocks the passkey locally with a fingerprint, face scan, or device PIN, and the device signs the challenge. The biometric check happens on the device, and the biometric is not sent to the service.

Passkeys resist phishing because each one is bound to the service that created it, so a look-alike site cannot obtain a usable credential, and there is no shared secret to steal in a server breach. Apple, Google, and Microsoft committed to broad passkey support in 2022, and passkeys now work across the major operating systems and browsers.

For patient calls, passkeys are an alternative to knowledge-based questions such as name and date of birth, which are widely exposed and easy for an impostor to answer. A patient can confirm identity on their own phone, and the calling system receives the verification result rather than the credential.

How Consig handles it

Consig verifies patients through Journey.ai's Zero Knowledge Network, using passkeys, device-native biometrics such as Face ID or Touch ID, and one-time passcodes. Where passkeys or device biometrics are used, biometric templates and private-key material remain on the patient's device or authenticator rather than being exposed to Consig or the AI conversation layer.