Skip to content
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
PCI Pal
  • Products
    • Secure & Capture
      • Key to PaySecurely capture card details with keypad entry.
      • Click to PayPay by card, ewallet, and bank through digital links.
      • Speak to PayAccessible payments using AI-powered speech recognition.
    • Verify & Protect
      • Customer AuthenticationVerify customers without time-consuming Q&A.
      • Fraud ManagementDetect high-risk interactions before sensitive steps begin.
    • Services
      • Services and SupportSeamless, reliable services and support every step of the way.
  • Platform
  • Outcomes
    • Industries
      • Financial ServicesDescoping the contact centers from PCI DSS in financial services
      • RetailSecuring omnichannel payments in retail
      • GovernmentPayment compliance for public sector contact centers
      • UtilitiesEnsuring flexible, secure payment experiences for utility companies
      • HealthcareSecuring patient payment interactions in healthcare
      • Travel & LeisureSimplifying and safeguarding transactions for travel and leisure companies
      • BPO / OutsourcedPCI DSS compliance in outsourced and BPO contact centers
      • Logistics & ShippingSecuring delivery and booking payments across every channel
      • Not For ProfitProtecting donations from phone appeals to online giving
  • Partner Ecosystem
    • Partner Directory
    • Partner Hub
  • Resources
    • All Resources
    • Blogs
    • Collateral
    • Events
    • Media Library
    • News
    • Success Stories
    • PCI Pal Glossary
  • About
    • About Us
    • Careers
    • Investors
    • Trust Center
  • Support
Book a demo
Contact Us
Book a DemoContact Us
  1. Resources
  2. Blogs

From KBA to passkeys: modernizing customer authentication in the contact center

Sep 17, 2026
  • Copied!

Passkeys are changing the way organizations approach digital identity, with an estimated five billion passkeys in use globally today.1 But their relevance extends well beyond websites and mobile applications: In the contact center, they can provide a cryptographically-backed authentication event that becomes usable across customer interactions, business processes, and increasingly autonomous systems. This approach creates an opportunity to build authentication around stronger identity evidence, while giving security, fraud, risk, compliance, and technology teams greater control over what happens after a customer has been authenticated.

Previous articles in this series explored why contact center authentication has become a critical control point and why traditional verification can create friction across customer journeys. The next question is what a stronger model should look like. As contact centers automate more interactions, authentication needs to produce evidence that the right assurance step occurred before the business allowed a payment, account change, refund, data disclosure or other sensitive action to proceed.

How passkey authentication provides stronger proof of identity

Many contact center verification methods depend on information or signals that need to be interpreted: a remembered answer, a familiar phone number, a convincing voice, or an agent’s judgment. These methods can provide useful indicators, but the assurance they offer often depends on the quality of the information presented and how it is assessed.

Passkeys operate differently. Rather than asking the contact center to assess information or behavioral signals, they use cryptographic proof to verify that the customer is using a registered credential under their control. The customer approves the authentication locally using their device’s built-in authentication method, often a biometric, device PIN, or unlock pattern. The contact center does not receive or process the biometric data itself, and the service provider does not need to store a shared authentication secret.

This is enabled by public-key cryptography. A passkey is a cryptographic credential associated with the customer’s account. The private key remains protected by the customer’s device or authenticator, while the corresponding public key is held by the service. During authentication, the private key is used to prove possession of the registered credential, and the public key enables the service to verify that proof without the private key itself being exposed or transmitted.

FIDO describes passkeys as cryptographic credentials tied to a user account, with no shared secrets for the service provider to store and no biometric data sent to a remote server. NIST’s guidance on syncable authenticators (including passkeys), describes correctly implemented syncable authenticators as phishing resistant and suitable for both enterprise-facing and public-facing use cases.2

In a contact center, a customer authentication event becomes an operational control that gives the business something more reliable than a spoken answer, caller cue or agent interpretation: the value sits in delivering a stronger proof event that modern contact center workflows can consistently and systematically rely on.

Stronger assurance against impersonation tactics

A voice deepfake may imitate how someone sounds but does not prove possession and successful use of a registered passkey. A social engineer may know personal information but does not produce a valid cryptographic authentication event. A SIM swap may compromise control of a phone number but does not give the attacker access to a passkey stored and protected by the customer’s device.

Contact centers often sit at the intersection of several risk signals: voice, caller ID, account information, device context and agent judgment. Passkey authentication does not remove the need for layered fraud controls, but it provides a stronger anchor than information that can be copied, coached or redirected.

The regulatory direction around phone-number-based assurance reinforces the point. The FCC has introduced rules requiring wireless providers to use secure methods to authenticate customers before redirecting a phone number to a new device or provider, in response to SIM swap and port-out fraud. NIST also warns that PSTN-based out-of-band methods can divert users toward controls that are vulnerable to phishing.3 In other words, phone-based authentication is useful, but it is not strong enough to be the main proof of identity for high-risk contact center actions. A passkey is stronger because it is tied to a registered device and cryptographic proof, not just control of a phone number.

That does not mean every contact center should abandon existing knowledge-based authentication immediately, nor rip and replace their current workflows. Lower-risk interactions may continue to use lighter controls, while passkey-based step-ups can be introduced where stronger assurance is needed before sensitive actions. The strategic shift is a control that is harder for an impersonator to fake and easier to evaluate consistently based on the nature of the interaction.

Evidence that supports compliance and orchestrated workflows

Security controls are only as useful as the evidence they produce. Traditional contact center authentication can leave uneven records. An agent may confirm that authentication happened, but the evidence may not show the assurance method, policy applied, exception path used or whether the same process was followed across assisted and automated channels. A well-designed passkey-based authentication implementation can:

  • Record when authentication was requested
  • Whether it succeeded or failed
  • Which workflow invoked it
  • Which channel was involved
  • And what action followed

As contact centers introduce more virtual agents, AI-assisted workflows and automated service paths, traceability becomes more important. Regulation is also moving in that direction. For example, the EU AI Act includes transparency obligations for certain AI systems, including informing people when they are interacting directly with an AI system and disclosing deepfake content in defined circumstances. These obligations do not mandate passkey authentication but they reflect a broader shift: when AI is used in customer-facing workflows, businesses need clearer ways to show what happened, what was disclosed and what controls were applied.

Authentication is one part of that evidence chain. If a virtual agent, AI agent, or automated workflow is allowed to progress a sensitive request, the organization needs to show the basis on which that decision was made. A cryptographic authentication outcome can help by turning customer verification into a recordable control event, rather than relying only on an agent note or conversational judgment.

Passkey-based authentication is well suited to that model because it can produce a defined assurance outcome. The contact center can use that outcome to:

  • Allow a low-risk request to continue
  • Step up authentication before a payment or account change
  • Pass identity context during channel handoff
  • Escalate to human review
  • Or record the control applied before a sensitive workflow proceeds

Gartner predicts that agentic AI will autonomously resolve 80% of common customer service issues by 2029, reducing operational costs by 30%.4 If more systems are expected to act on behalf of the business, they need a reliable authentication state before sensitive actions are performed. That same clarity supports human agents. Instead of interpreting identity signals under pressure, they can work from a clearer authentication state and focus on the customer’s issue. Virtual and AI-enabled workflows receive a machine-readable trust input rather than ambiguous conversation context.

A stronger posture starts with verifiable assurance

Passkeys do not replace every security, fraud or compliance control in the contact center. Organizations still need risk scoring, monitoring, exception handling, fallback journeys and appropriate support for customers who cannot use a specific method.

The case for passkey-based customer authentication is more focused: high-risk contact center interactions need assurance that is harder to impersonate and easier to orchestrate, log and evidence. Cryptographic authentication strengthens the point at which trust is established. It creates a stronger control against impersonation, a clearer signal before sensitive actions, a more traceable record and an authentication method that can support assisted, virtual and AI-enabled workflows.

As contact centers become more automated and more exposed to synthetic impersonation, customer authentication needs to become both stronger and more operationally usable.

For teams assessing how cryptographically-backed assurance could work in assisted and automated contact center interactions, PCI Pal’s Customer Authentication provides a practical way to explore passkey-based verification for modern contact center environments.

See Customer Authentication in action with our interactive product tour.

 


Sources

  1. FIDO Alliance: Five Billion Passkeys: FIDO Alliance Reports Mainstream Global Usage on World Passkey Day 2026
  2. FIDO Alliance: Passkeys
  3. National Institute of Standards and Technology (NIST): Giving NIST Digital Identity Guidelines a Boost: Supplement for Incorporating Syncable Authenticators
  4. Gartner: Gartner Predicts Agentic AI Will Autonomously Resolve 80% of Common Customer Service Issues Without Human Intervention by 2029



Like what you see? Share with a friend.

  • Copied!
Tags: Customer authentication

Lastest News, Blogs, Events and More

  • New PCI Pal Brand Launch: A Letter From Our CEO
    Blogs

    New PCI Pal Brand Launch: A Letter From Our CEO

    Learn More
  • How passkeys turn contact center authentication from a checkpoint into a service
    Blogs

    How passkeys turn contact center authentication from a checkpoint into a service

    Learn More
  • Architected for Agility: How PCI Pal’s Cloud-Native Foundation Future-Proofs Your CX
    Blogs

    Architected for Agility: How PCI Pal’s Cloud-Native Foundation Future-Proofs Your CX

    Learn More
  • The Modern Payment Security Playbook: The Flexible Approach Powering Market Leaders
    Blogs

    The Modern Payment Security Playbook: The Flexible Approach Powering Market Leaders

    Learn More

Discover the Power of PCI Pal. Trust When It Matters Most.

Book a Demo
  • X
  • LinkedIn
  • YouTube

Products

  • Platform
  • Key to Pay
  • Click to Pay
  • Speak to Pay
  • Customer Authentication
  • Fraud Management
  • Services and Support

Outcomes

  • Financial Services
  • Retail
  • Government
  • Utilities
  • Healthcare
  • Travel & Leisure
  • BPO / Outsourced
  • Logistics & Shipping
  • Not For Profit

Partner Ecosystem

  • Partner Directory
  • Partner Hub

Resources

  • Blogs
  • Collateral
  • Events
  • Media Library
  • News
  • Success Stories
  • PCI Pal Glossary

Company

  • About Us
  • Careers
  • Investors
  • Trust Center

© 2026. PCI Pal. All rights reserved. Company Registration Number: 3869545

  • Cookie Policy
  • Privacy Policy
  • Terms of Use
  • Modern Slavery Act
  • Carbon Reduction Plan
  • Recruitment Data Protection Notice