Singpass passkeys launched in beta on 1 July 2026 for iPhone users. They replace passwords, OTPs and QR approvals with a device bound cryptographic proof that a phishing site cannot reuse, although Android and desktop...
Research answer

Create a landscape editorial hero image for this Studio Global article: What are the details of Singpass's new passkey feature launching July 1, 2026 — how does its public-private encryption key pair work to prev. Article summary: Singpass introduced passkeys in a beta launch on 1 July 2026, initially for iPhone users. The feature replaces a reusable secret—such as a password, OTP, or QR approval—with a device-bound cryptographic proof that is sub. Topic tags: general, documentation, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
Singpass’s passkey feature is a new, optional way to sign in without entering a password, SMS one-time password or QR approval. The beta opened on 1 July 2026 for iPhone users on mobile browsers, with Android and desktop support planned for later phases.
The important distinction is that a passkey does not merely add another secret for a scammer to steal. It uses a device-bound cryptographic credential that is tied to the legitimate Singpass login service, making it substantially more resistant to phishing.
Traditional login methods can expose reusable information. A password can be copied, an OTP can be relayed and a QR code can be manipulated into approving a login initiated by someone else. Passkeys change the exchange so that no password or OTP is entered or transmitted during authentication.
The user still proves control of the device locally, usually with biometrics or a passcode, but the website does not receive the biometric data or the private key. It receives a cryptographic response that can be checked but not reused as a password.
During registration, the iPhone generates a unique public-private key pair:
This is more accurately an authentication use of public-key cryptography than a simple “encryption key exchange.” The private key is not sent to Singpass, while the public key alone cannot be used to impersonate the user. FIDO standards describe this model as origin-bound authentication: the credential is associated with the legitimate service domain, so a look-alike website cannot obtain a response that works for Singpass.
That is why a copied Singpass login page has much less value against a passkey user. There is no reusable password, OTP or QR approval for the fake site to collect and replay.
The initial beta rollout is limited:
This staged approach means an iPhone user can use the passkey on a supported mobile-browser login, but users should not assume that every Singpass service or every device will offer the option immediately.
For the initial iPhone rollout, the registration process is handled in the Singpass mobile app:
Once registered, users authenticate locally with Face ID, Touch ID or fingerprint, or the Singpass six-digit app passcode, depending on the device and available settings. The user does not type a Singpass password into the participating website.
A separate-device scenario creates a different risk: someone might try to persuade a victim to approve a login taking place on a scammer-controlled computer or phone. For cross-device authentication, Singpass can use a short-range Bluetooth check to confirm that the registered phone is physically near the device requesting the login.
The proximity check does not replace the key-pair verification. It adds evidence that the phone holding the passkey is nearby. That makes a purely remote approval flow harder for a scammer to orchestrate—for example, by sending a victim a QR code and coaching them through an approval while the scammer operates elsewhere.
Passkeys are an additional login method during the beta, not an immediate universal replacement. Existing options remain necessary for people without an eligible iPhone, users who have not enrolled, and services or devices that are not yet included in the staged rollout.
Those older methods are still useful for accessibility and coverage, but their security depends more heavily on user behaviour. A person can be manipulated into disclosing a password or OTP, scanning a fraudulent QR code or approving an unexpected request. Singapore Police continue to warn the public never to share Singpass passwords or 2FA details with unknown people.
Passkeys reduce the amount of credential material that can be phished; they do not eliminate every scam tactic. A scammer can still impersonate an organisation, pressure someone into revealing personal information or attempt to exploit a recovery or account-takeover process.
Singpass’s design follows the public-key, origin-bound model associated with FIDO and WebAuthn. FIDO2 is an open authentication standard intended to provide phishing-resistant cryptographic credentials rather than proprietary, reusable secrets.
The standards approach matters because passkeys are designed for interoperability across the broader authentication ecosystem. The FIDO Alliance describes passkeys as credentials tied to an account on a website or application and usable with a phone, computer or hardware security key, subject to the implementation and rollout supported by each service.
For Singpass, the practical security benefit is domain binding: the authenticator is expected to respond for the legitimate service, not for a visually similar phishing domain.
Singapore recorded 37,308 scam cases and approximately S$913.1 million in scam losses in 2025. Those totals cover scams overall, not phishing alone.
The official annual figures reported through Singapore scam-information channels separately list 6,264 phishing cases and S$39.9 million lost to phishing in 2025. That makes phishing a significant part of the wider scam problem, but the figures should not be treated as evidence that all scam losses involved stolen Singpass credentials.
The product decision is therefore targeted: passkeys are designed to make the credential-capture stage of phishing far less useful. Users still need to verify websites, reject unexpected login requests and avoid sharing Singpass details, especially while older authentication methods remain available.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Singpass passkeys launched in beta on 1 July 2026 for iPhone users. They replace passwords, OTPs and QR approvals with a device bound cryptographic proof that a phishing site cannot reuse, although Android and desktop...
Singpass passkeys launched in beta on 1 July 2026 for iPhone users. They replace passwords, OTPs and QR approvals with a device bound cryptographic proof that a phishing site cannot reuse, although Android and desktop... Register by updating the Singpass app, opening its home screen passkey banner and following the setup steps; sign ins are approved with Face ID, Touch ID or the Singpass six digit passcode.
Singapore recorded 6,264 phishing cases and S$39.9 million in phishing losses in 2025, within 37,308 scam cases and S$913.1 million in total scam losses.