FIDO Alliance and Payments

Securing Authentication Across the Global Payments Ecosystem

Payment fraud and friction cost the industry and consumers billions annually. Passwords and one-time codes sent via SMS remain the dominant authentication methods in payment flows — yet they are among the easiest to phish and compromise. 

The FIDO Alliance is working with card networks, issuers, merchants, payment service providers, and standards bodies to make phishing-resistant authentication the default for payment transactions.

Key advantages of FIDO-based payment authentication include:

  • Phishing resistance — based on FIDO authentication protocols, passkeys are always unique and cryptographically bound to the originating site or app; they cannot be replicated or stolen through phishing
  • Speed and convenience — users authenticate how they unlock their device (biometrics, local PIN, etc.), eliminating the wait for SMS codes or email one-time passwords
  • Fraud reduction — FIDO protocols provide cryptographic proof of authentication, reducing unauthorized transaction approvals
  • Compliance readiness — FIDO authentication supports compliance with regulatory mandates for strong customer authentication (SCA)

Areas of Focus

The FIDO Alliance’s payments work is carried out through the Payments Technical Working Group (PTWG), which brings together stakeholders from across the payments ecosystem — including card networks, card schemes, issuing banks, payment service providers, digital wallets, and authentication technology providers. The PTWG can support the following use-cases.

Transaction Authentication by Issuing banks

Card issuers can leverage passkeys to authenticate cardholders in 3-D Secure flows using whatever method they use to unlock their device — biometrics, local PIN, and more. This is faster and easier than SMS one-time codes, phishing-resistant by design, and supports compliance readiness for strong customer authentication requirements.

Authentication at Checkout on Merchant website 

Merchants, digital wallets, and Payment Service Providers can implement passkeys to authenticate customers at the point of checkout improving the user experience, reducing fraud through cryptographic proof of authentication, and helping organizations meet applicable regulatory requirements.

Agentic Commerce

As AI agents increasingly act on behalf of users to initiate and complete transactions, new standards are needed to ensure those transactions are explicitly authenticated, verifiable, and executed within user-controlled boundaries. The FIDO Alliance is developing specifications to address this emerging category directly. This work intersects with FIDO’s broader agentic AI initiative. Learn more about FIDO Alliance & Agentic AI

In Practice

  • Mastercard has enabled passkeys to seamlessly authenticate remote commerce transactions. Read the documentation
  • Visa has introduced new payment services using passkeys. Read the article
  • NIST has cited the phishing-resistance of synced passkeys in its Digital Identity Guidelines update. Read the blog

Get Involved

FIDO Alliance’s payments work is open to member participation through the Payments Technical Working Group. FIDO members can engage directly; non-members should explore FIDO membership to get involved.

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.