This white paper is part of a three-part series on preventing phishing attacks through passkey deployment:

  • Part 1: Overview – Introduces the concepts of a passkey journey toward phishing prevention.
  • Part 2: Partial prevention – Details strategies for enforcing passkeys in specific scenarios.
  • Part 3: Full prevention – Explains how to achieve comprehensive phishing resistance.

Making your services phishing-resistant takes more than one day because you are not just adopting a new phishing-resistant authentication method. It is a journey with multiple stages where you improve security by strengthening account login and recovery processes. This paper outlines the passkey journey and defines the authentication and recovery requirements for each stage.

Audience

Relying parties and developers who want to protect their applications from phishing attacks by adopting passkeys.

You can read the white papers on Passkey Central or use the following buttons to download PDF versions.

Part 1: Overview

Introduces the concepts of a passkey
journey toward phishing prevention.

Part 2: Partial Prevention

Details strategies for enforcing passkeys
in specific scenarios.

Part 3: Full Prevention

Explains how to achieve comprehensive
phishing resistance.


More

White Paper: FIDO and the Shared Signals Framework

Orchestrating Agile and Secure IAM Workflows October 2025 Authors: Jacob Harlin, MicrosoftJosh Cigna, YubicoMartin Gallo,…

Read More →

White Paper: Passkeys and Verifiable Digital Credentials: A Harmonized Path to Secure Digital Identity

Editors Christine Owen, 1Kosmos Teresa Wu, IDEMIA Public Security Abstract Around the world, government entities…

Read More →

White Paper: Addressing Cybersecurity Challenges in the Automotive Industry

Abstract As the automotive industry transitions toward software-defined vehicles, autonomous technologies, and connected services, cybersecurity…

Read More →


12316 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.