Skip to content

Singpass moves to passkeys to take the phishing out of logging in

Singapore's national login began offering passkeys to iPhone users in July and extended them to Android in September. Desktops follow by the end of the year.

By IQGov Editors

Digital Identity, Report. 11 September 2026, 3 min read

Singapore's financial district seen across the water from a waterfront promenade
Photo: Виктор Соломоник / Pexels, Pexels License

Singapore's Government Technology Agency (GovTech) began rolling out passkeys for Singpass, the national digital identity, on 1 July, starting with iPhone users logging in through mobile browsers. In September it extended passkeys to Android, citing the fight against phishing scams.

About 800,000 iPhone users created a passkey in the first weeks. Laptops and desktops are not yet supported; GovTech plans to extend the feature to them by the end of 2026.

Why passkeys

A passkey is bound to the user's device and to the genuine website. There is no code to read out and no password to type into a fake page, which is how most account takeovers start. For a login that opens government services, banks and insurers, closing that route matters.

The stakes are high because Singpass is used for almost everything. According to GovTech, it gives access to more than 2,700 services from 800 government agencies and businesses, and handles over 41 million transactions a month.

IQGov Editors

Research desk, Online

Stories by the IQGov research desk are written from public documents, official data and on-record statements, which are listed and linked at the end of each piece.

Keep reading

More Identity

Liked this story? Get the Monday Briefing.

Weekly, free. Unsubscribe with one click.