Passkeys are changing the way organizations approach digital identity, with an estimated five billion passkeys in use globally today.¹ But their relevance extends well beyond websites and mobile applications: In the contact center, they can provide a cryptographically-backed authentication event that becomes usable across customer interactions, business processes, and increasingly autonomous systems. This approach creates an opportunity to build authentication around stronger identity evidence, while giving security, fraud, risk, compliance, and technology teams greater control over what happens after a customer has been authenticated.
Previous articles in this series explored why contact center authentication has become a critical control point and why traditional verification can create friction across customer journeys. The next question is what a stronger model should look like. As contact centers automate more interactions, authentication needs to produce evidence that the right assurance step occurred before the business allowed a payment, account change, refund, data disclosure or other sensitive action to proceed.
How passkey authentication provides stronger proof of identity
Many contact center verification methods depend on information or signals that need to be interpreted: a remembered answer, a familiar phone number, a convincing voice, or an agent’s judgment. These methods can provide useful indicators, but the assurance they offer often depends on the quality of the information presented and how it is assessed.
Passkeys operate differently. Rather than asking the contact center to assess information or behavioral signals, they use cryptographic proof to verify that the customer is using a registered credential under their control. The customer approves the authentication locally using their device’s built-in authentication method, often a biometric, device PIN, or unlock pattern. The contact center does not receive or process the biometric data itself, and the service provider does not need to store a shared authentication secret.
This is enabled by public-key cryptography. A passkey is a cryptographic credential associated with the customer’s account. The private key remains protected by the customer’s device or authenticator, while the corresponding public key is held by the service. During authentication, the private key is used to prove possession of the registered credential, and the public key enables the service to verify that proof without the private key itself being exposed or transmitted.
FIDO describes passkeys as cryptographic credentials tied to a user account, with no shared secrets for the service provider to store and no biometric data sent to a remote server. NIST’s guidance on syncable authenticators (including passkeys), describes correctly implemented syncable authenticators as phishing resistant and suitable for both enterprise-facing and public-facing use cases. ²
In a contact center, a customer authentication event becomes an operational control that gives the business something more reliable than a spoken answer, caller cue or agent interpretation: the value sits in delivering a stronger proof event that modern contact center workflows can consistently and systematically rely on.
Stronger assurance against impersonation tactics
A voice deepfake may imitate how someone sounds but does not prove possession and successful use of a registered passkey. A social engineer may know personal information but does not produce a valid cryptographic authentication event. A SIM swap may compromise control of a phone number but does not give the attacker access to a passkey stored and protected by the customer’s device.
Contact centers often sit at the intersection of several risk signals: voice, caller ID, account information, device context and agent judgment. Passkey authentication does not remove the need for layered fraud controls, but it provides a stronger anchor than information that can be copied, coached or redirected.
The regulatory direction around phone-number-based assurance reinforces the point. The FCC has introduced rules requiring wireless providers to use secure methods to authenticate customers before redirecting a phone number to a new device or provider, in response to SIM swap and port-out fraud. NIST also warns that PSTN-based out-of-band methods can divert users toward controls that are vulnerable to phishing.³ In other words, phone-based authentication is useful, but it is not strong enough to be the main proof of identity for high-risk contact center actions. A passkey is stronger because it is tied to a registered device and cryptographic proof, not just control of a phone number.
That does not mean every contact center should abandon existing knowledge-based authentication immediately, nor rip and replace their current workflows. Lower-risk interactions may continue to use lighter controls, while passkey-based step-ups can be introduced where stronger assurance is needed before sensitive actions. The strategic shift is a control that is harder for an impersonator to fake and easier to evaluate consistently based on the nature of the interaction.
Evidence that supports compliance and orchestrated workflows
Security controls are only as useful as the evidence they produce. Traditional contact center authentication can leave uneven records. An agent may confirm that authentication happened, but the evidence may not show the assurance method, policy applied, exception path used or whether the same process was followed across assisted and automated channels. A well-designed passkey-based authentication implementation can:
- Record when authentication was requested
- Whether it succeeded or failed
- Which workflow invoked it
- Which channel was involved
- And what action followed
As contact centers introduce more virtual agents, AI-assisted workflows and automated service paths, traceability becomes more important. Regulation is also moving in that direction. For example, the EU AI Act includes transparency obligations for certain AI systems, including informing people when they are interacting directly with an AI system and disclosing deepfake content in defined circumstances. These obligations do not mandate passkey authentication but they reflect a broader shift: when AI is used in customer-facing workflows, businesses need clearer ways to show what happened, what was disclosed and what controls were applied.
Authentication is one part of that evidence chain. If a virtual agent, AI agent, or automated workflow is allowed to progress a sensitive request, the organization needs to show the basis on which that decision was made. A cryptographic authentication outcome can help by turning customer verification into a recordable control event, rather than relying only on an agent note or conversational judgment.
Passkey-based authentication is well suited to that model because it can produce a defined assurance outcome. The contact center can use that outcome to:
- Allow a low-risk request to continue
- Step up authentication before a payment or account change
- Pass identity context during channel handoff
- Escalate to human review
- Or record the control applied before a sensitive workflow proceeds
Gartner predicts that agentic AI will autonomously resolve 80% of common customer service issues by 2029, reducing operational costs by 30%.⁴ If more systems are expected to act on behalf of the business, they need a reliable authentication state before sensitive actions are performed. That same clarity supports human agents. Instead of interpreting identity signals under pressure, they can work from a clearer authentication state and focus on the customer’s issue. Virtual and AI-enabled workflows receive a machine-readable trust input rather than ambiguous conversation context.
A stronger posture starts with verifiable assurance
Passkeys do not replace every security, fraud or compliance control in the contact center. Organizations still need risk scoring, monitoring, exception handling, fallback journeys and appropriate support for customers who cannot use a specific method.
The case for passkey-based customer authentication is more focused: high-risk contact center interactions need assurance that is harder to impersonate and easier to orchestrate, log and evidence. Cryptographic authentication strengthens the point at which trust is established. It creates a stronger control against impersonation, a clearer signal before sensitive actions, a more traceable record and an authentication method that can support assisted, virtual and AI-enabled workflows.
As contact centers become more automated and more exposed to synthetic impersonation, customer authentication needs to become both stronger and more operationally usable.
For teams assessing how cryptographically-backed assurance could work in assisted and automated contact center interactions, PCI Pal’s Customer Authentication provides a practical way to explore passkey-based verification for modern contact center environments.
See Customer Authentication in action with our interactive product tour.
Sources
- 1. FIDO Alliance: Five Billion Passkeys: FIDO Alliance Reports Mainstream Global Usage on World Passkey Day 2026
-
2. FIDO Alliance: Passkeys
-
3. National Institute of Standards and Technology (NIST): Giving NIST Digital Identity Guidelines a Boost: Supplement for Incorporating Syncable Authenticators
