## Resources and insights

The latest industry news, interviews, technologies, and resources.

.png)](/content/post/mula-x-passkeys-plus-thailand-digital-wallet/index.html)

**Mula-X Chooses Passkeys+ to Replace SMS OTPs Across Its Digital Wallet Platform**  
Mula-X is rolling out Ideem's Passkeys+ across its Thailand digital wallet platform, replacing SMS-based OTPs with biometric, device-bound authentication built on the FIDO standard.

*Maranda Manning*  
*April 7, 2026*  
*4 min read*

**Measuring Passkey Health: 8 Production KPIs Every Bank Should Track**  
The 2026 industry has converged on a small set of passkey production KPIs — enrollment, prompt conversion, login success, conditional UI completion, time-to-auth, fallback, recovery, and ATO reduction — with published benchmark ranges from Corbado, the FIDO Alliance, and major deployments. Banks that adopt these as the standing board report this year will be ahead of regulators in 2027.

*Toby Rush*  
*June 2, 2026*  
*9 min read*

**Passkey Provider Divergence: How Banks Run a Multi-Provider Strategy Without Picking Sides**  
Passkey provider divergence in 2026 is a feature of a healthy open standard, not a problem to be solved by picking sides. Banks win by building a provider-agnostic policy layer that normalizes AAGUID handling, sync/device-bound classification, and per-provider risk routing across Apple, Google, Microsoft, 1Password, Dashlane, Bitwarden, and hardware keys.

*Tim Massey*  
*June 2, 2026*  
*8 min read*

**Ideem and Unifonic Partner to Bring Passwordless Authentication to the GCC**  
Ideem has partnered with Unifonic, the region's leading AI-native customer engagement platform, to bring passwordless, phishing-resistant authentication to enterprises across the GCC. The partnership pairs Unifonic's reach with Ideem's MPC-based device binding to move the region's banks and brands beyond the password and SMS OTP burden.

*Maranda Manning*  
*June 18, 2026*  
*4 min read*

**Step-Up Authentication with Passkeys: Transaction-Bound Signing for High-Value Payments**  
Session-level passkey auth proves a user logged in but not that they approved a specific wire. Transaction-bound signing closes that gap by deriving the WebAuthn challenge from the actual payee and amount so the signature is cryptographically tethered to the transaction itself — and it's exactly what PSD2/PSD3 dynamic linking requires.

*Tim Massey*  
*June 2, 2026*  
*9 min read*

**Discoverable vs. Non-Discoverable Passkeys: How Banks Should Decide (and How Passkeys+ Handles Both)**  
A practical framework for the discoverable-vs-non-discoverable credential decision in 2026: most consumer banking flows should default to discoverable for conditional UI and the synced-passkey ecosystem, but hardware-key fleets and known-identifier employee flows still earn the non-discoverable choice. The platform decision that matters is supporting both under one policy without a re-platform.

*Greg Storm*  
*June 2, 2026*  
*9 min read*

**FIDO Metadata Service (MDS) for Risk-Tiered Onboarding in Financial Services**  
The FIDO Metadata Service lets a bank tell exactly which authenticator created any passkey presented during onboarding. How banks turn MDS metadata into risk-tiered onboarding decisions, build a filtered BLOB, and capture the audit evidence regulators are starting to expect.

*Greg Storm*  
*June 2, 2026*  
*7 min read*

**The Conditional UI Reality Check: Why Passkey Autofill Performance Varies by Browser**  
Conditional UI is the WebAuthn feature that turns passkeys into autofill suggestions and the single biggest lever for bank passkey adoption. An honest engineer's tour of where it works, where it breaks, and how to ship it cleanly.

*Tim Massey*  
*June 2, 2026*  
*7 min read*

**How Passkeys Compare to Every Major Banking Authentication Method: A Six-Part Series Recap**  
Over two months we compared passkeys against every major banking authentication method — SMS OTP, TOTP, hardware keys, fingerprinting, magic links, and synced passkeys. Here is the full series, the cross-cutting takeaways, and where to start by role.

*Maranda Manning*  
*June 2, 2026*  
*9 min read*

**How Banks Vet Passkey Providers: Building a Bank-Grade Trust Framework**  
Banks deploying passkeys are facing a new governance challenge: not all passkeys carry the same weight. A framework for vetting passkey providers, mapping them to trust tiers, and enforcing policy at the authentication layer.

*Greg Storm*  
*June 2, 2026*  
*8 min read*

**Magic Link Authentication Security in Banking**  
Magic links solved a real friction problem for consumer SaaS. They have not held up well for financial services. The security of the link is the security of the email account, the link itself is phishable, and the model has no device binding. Here is what comes next.

*Maranda Manning*  
*May 6, 2026*  
*7 min read*

**Device-Bound vs Synced Passkeys: Banking Comparison**  
Synced passkeys solve a real usability problem and are a clear upgrade from OTP, TOTP, and push. But sync moves the security boundary of the credential to the user's cloud account. For financial services, that matters. Here is why device-bound passkeys close the gap.

*Greg Storm*  
*May 6, 2026*  
*8 min read*

**Device Fingerprinting vs Authentication: Fraud Signal or MFA?**  
Device fingerprinting is a useful fraud signal, not a possession factor for authentication. It is probabilistic, spoofable at scale, and excluded from the regulatory definition of strong authentication. Here is where it fits in a 2026 financial services architecture.

*Toby Rush*  
*May 6, 2026*  
*7 min read*

**Passkeys vs Hardware Security Keys: Cost and Deployment Comparison for Banks**  
Hardware security keys introduce deployment, cost, and usability barriers impractical for consumer banking at scale. Software passkeys deliver equivalent cryptographic security through device secure enclaves while reducing support costs by 75%.

*Greg Storm*  
*May 6, 2026*  
*8 min read*

**TOTP vs Passkeys: Are Authenticator Apps Enough for Banks?**  
TOTP and authenticator apps were a meaningful upgrade from SMS OTP, but the underlying threat model has not changed. AiTM phishing defeats TOTP, the seed is exposed at enrollment, and cloud-synced apps create a single point of failure. Here is what comes next.

*Toby Rush*  
*May 6, 2026*  
*8 min read*

**Why Banks Are Replacing SMS OTP With Passkeys in 2026**  
NIST has classified SMS OTP as a restricted authenticator, adversary-in-the-middle phishing routinely defeats both SMS and email codes, and financial services authentication is moving to phishing-resistant, device-bound credentials. Here is a practical roadmap for the migration.

*Greg Storm*  
*May 6, 2026*  
*8 min read*

**AI Agents Need Authentication Too: The Emerging Passkey and OAuth Problem**  
AI agents are beginning to act on behalf of users inside banking applications - initiating transfers, checking balances, filing disputes. But the authentication infrastructure those agents rely on was designed for humans, not autonomous software. That gap is the next major security problem in financial services authentication.

*Toby Rush*  
*March 6, 2026*  
*9 min read*

**Passkeys and Payment Authentication: Where SPC, 3DS, and FIDO Converge**  
Secure Payment Confirmation, expanding Visa and Mastercard passkey programs, and FIDO2's growing role in 3DS flows are converging toward a single credential layer at checkout. For financial institutions, understanding how these pieces fit together is no longer optional - it is a core architectural question.

*Greg Storm*  
*March 6, 2026*  
*9 min read*

**What Actually Works When Banks Deploy Passkeys: A Practitioner's Playbook**  
The five practices that separate high-adoption passkey deployments from stalled ones. A practitioner's playbook grounded in FIDO Alliance guidance and real implementation patterns.

*Toby Rush*  
*February 10, 2026*  
*7 min read*

**15 Billion Accounts and Counting: What Passkey-Ready Scale Means for Banks**  
The FIDO Alliance reports over 15 billion accounts can now use passkeys. That number changes the calculus for every bank still debating whether to deploy.

*Tim Massey*  
*February 10, 2026*  
*4 min read*

**When Passkeys Fail the User: Common UX Mistakes and How to Avoid Them**

*Maranda Manning*  
*January 8, 2026*  
*4 min read*

**Passkeys in Regulated Products: Usability vs Control is a False Tradeoff**

*Greg Storm*  
*January 8, 2026*  
*6 min read*

**The Passkey Adoption Bottleneck**

*Greg Storm*  
*January 8, 2026*  
*5 min read*

**Making Passkeys the Default Without Breaking Trust**

*Toby Rush*  
*December 22, 2025*  
*6 min read*

**From Enrollment to Everyday Use: Designing Passkeys for People**

*Maranda Manning*  
*December 22, 2025*  
*6 min read*

**Device Binding is the Missing Layer in Passkey Implementations**

*Greg Storm*  
*December 22, 2025*  
*8 min read*

**Encouraging passkey adoption without forcing it**

*Maranda Manning*  
*December 22, 2025*  
*5 min read*

**Cart Abandonment in GCC E-Commerce: Fixing Checkout Drop-Off with Device Binding and Passkeys**

*Toby Rush*  
*December 22, 2025*  
*4 min read*

**Q&A with Andrew Shikiar, CEO of FIDO**

*Maranda Manning*  
*October 1, 2025*  
*5 min read*

**Passkeys in Emerging Markets**

*Toby Rush*  
*September 16, 2025*  
*3 min read*

**MENA Banking’s Next Advantage: Passkeys+**

*Toby Rush*  
*August 25, 2025*  
*5 min read*

**But Wait, There’s More to Passkeys+**

*Toby Rush*  
*July 8, 2025*  
*2 min read*

**Making Passkeys Bank-Grade: The Missing Ingredient**  
This fourth blog in a five-part series that explores the current state of passkeys and why enhanced implementations, what we call Passkeys+, are essential for meeting the security and compliance demands of

*Maranda Manning*  
*July 8, 2025*  
*2 min read*

**Passkeys Alone Are Insufficient for Financial Services**

*Greg Storm*  
*July 3, 2025*  
*3 min read*

**Convenience vs. Control: The Problem with Synced Passkeys**

*Maranda Manning*  
*June 26, 2025*  
*4 min read*

**The Passkey Shift - Passkeys Inevitable Triumph over Passwords**  
For decades, passwords were the default key to the digital world. Easy to implement and familiar to users, they offered convenience, but at a steep cost. As our digital footprints grew, passwords became both a security liability and a user burden. Complex requirements, frequent resets, and rampant reuse opened the floodgates to breaches, phishing attacks, and endless frustration.

*Toby Rush*  
*June 19, 2025*  
*5 min read*

**Microsoft’s Passwordless Push: A Step Forward, but with Major Caveats**

*Maranda Manning*  
*August 11, 2025*  
*2 min read*
