Singpass has extended its passkey login to Android phones, giving more users a way to authenticate without typing a reusable password or one-time code into a website. GovTech began the phased Android rollout on September 9, 2026, after opening setup to iPhone users on July 1.
4
26
How a Singpass passkey turns a phone into a digital key
A passkey uses a cryptographic pair: a private key held on the phone and a corresponding public key registered with Singpass. Together, they let Singpass verify a login without asking the user to enter a reusable secret on the site.
12 To approve a passkey login, users can verify themselves with a face scan, fingerprint or six-digit Singpass app passcode.
25
The phishing protection comes from where the passkey works. GovTech says Singpass passkeys are bound to its legitimate login domain, so they cannot be used on a fake website. A lookalike page therefore cannot collect the passkey as it might collect a password or one-time code.
26
32 That makes this credential-phishing resistant, not a guarantee against every scam or a compromised device.
What Android users need to do
Android users should update the Singpass app and look for an in-app notification inviting them to create a passkey. GovTech is sending those invitations in phases, so they may not appear for everyone at once.
4 After setup, users can choose passkey login and approve it using their face, fingerprint or six-digit app passcode.
25
GovTech announced the iPhone beta on June 30, with setup available from July 1.
4
26 By the September 9 Android expansion, about 800,000 users had created a Singpass passkey.
12
25
What is not yet available
The Android expansion did not include passkey login on laptop or desktop browsers. Desktop support was planned for the end of 2026.
4
25 The available reporting also does not establish that passkeys have eliminated phishing losses; the feature is a stronger login option, not a measure of how many scams it has prevented.