Open Editor
Privacy
8 min read

Passkeys in 2026: The Adoption Numbers Are Real, and So Is the Gap

FIDO Alliance says 5 billion passkeys are in active use and 90% of consumers recognize the term. An independent scan of the actual web found passkey support on a few hundred sites out of 100,000 checked. Neither number is wrong.

Metric2026 Figure
Passkeys in active use (FIDO Alliance)~5 billion
Consumer awareness90%
Enabled on at least one account69–75%, depending on survey
Use passkeys as regular sign-in method49%
Confirmed passkey-enabled sites (academic scan of 100,000 top domains)386

Two things are true about passkeys in 2026, and they sit uneasily next to each other. The FIDO Alliance's own State of Passkeys 2026 report counts roughly 5 billion passkeys in active use worldwide, 90% consumer awareness, and 75% of people who've enabled one on at least an account. Separately, a 2026 academic study that actually crawled the web looking for real passkey support found confirmed implementations on 386 websites out of 100,000 top-ranked domains checked. Both figures come from credible sources. They're measuring different things, and the gap between them is the actual story.

Whichever way authentication goes, some tools skip the account entirely — ClearText Editor needs no login and no password, passkey or otherwise, because nothing you type ever leaves your browser.

The Headline Numbers Are Genuinely Strong

By any reasonable measure, passkey awareness climbed fast. FIDO Alliance's 2026 survey of 11,000 consumers found 90% recognize passkeys, up from 75% the year before. Roughly 69–75% of respondents (the exact figure varies slightly by survey wording and sample) have enabled a passkey on at least one account, and regional adoption is uneven but generally high — China and India both around 88%, the UK at 77%, Germany 70%, France 64%. On performance, the case for passkeys over passwords is not close: a measured 93% login success rate versus roughly 63% for passwords, and Google reporting passkey sign-ins succeed about 30% more often than password-based ones across more than 800 million active accounts and 2.5 billion recorded sign-ins.

"Enabled" Is Not the Same as "Used"

The 75% enablement figure is the one that gets quoted most often, and it's the one most likely to be misread. FIDO's own data draws a clear line between enabling a passkey somewhere and actually relying on one: only 49% of consumers say they use passkeys "whenever possible" or "most of the time." The remaining gap is people who turned a passkey on once — often because an app prompted them — and then kept using a password for most of their actual sign-ins. Enablement is a reasonable leading indicator, but it measures exposure to the option, not a completed habit change.

The Number That Undercuts the Story: How Many Sites Actually Support This

Here's where the picture gets genuinely more complicated. A 2026 USENIX Security prepublication described a tool called PASSKEYS-RADAR that scanned 100,000 top-ranked domains and initially flagged 872 as potential passkey-enabled relying parties. After manual review to eliminate false positives, only 386 were confirmed to actually support passkey sign-in, with 208 independent implementations after deduplicating shared authentication backends. Run the math and confirmed passkey support shows up on roughly 0.386% of the sites checked — a figure that sits in sharp contrast to "90% awareness" and "5 billion passkeys in use."

Both statistics are accurate, and neither cancels the other out. Awareness and enablement describe what consumers have done on the small number of large platforms — Google, Apple, Amazon, Microsoft, PayPal — that account for most passkey activity. The website-scan number describes something different: how far that support has actually spread across the ordinary long tail of sites people use every day. Most of the internet hasn't caught up to the platforms driving the headline statistics.

Where the Real Progress Has Happened

The concentration makes sense once the individual rollout numbers are laid out. Google turned on passkeys by default for eligible accounts and now counts 800 million active users and 2.5 billion sign-ins through them. Amazon reports 175 million customers switched to passkeys, with sign-in roughly six times faster than before. FIDO Alliance's own benchmark data draws heavily on activity from exactly five companies — Amazon, Google, Microsoft, PayPal, and TikTok — which collectively account for a large share of the industry-wide figure of roughly 26% of sign-ins now completed via passkey. Availability at the top of the web has genuinely improved too: FIDO reports about 48% of the world's top 100 websites now support passkeys, more than double the 2022 figure. The pattern across every one of these numbers is the same — real, substantial progress, concentrated almost entirely among the largest platforms.

PlatformReported Passkey Rollout Result
Google800M active passkey users; 2.5B sign-ins; ~30% higher success rate than passwords
Amazon175M customers switched; ~6x faster sign-in
Top 100 websites overall~48% support passkeys, more than double the 2022 figure

Enterprise Adoption Is Ahead of the Consumer Long Tail

On the workforce side, adoption looks further along by one measure: 68% of organizations report they're deploying, piloting, or actively rolling out passkeys for employee sign-in, and companies that have made the switch report meaningful operational gains — an average 73% reduction in sign-in time and an 81% drop in login-related support tickets. But a separate, less flattering number from the same body of research puts this in context: 57% of organizations still rely on phishable authentication methods for primary sign-in even as passkey pilots proceed, meaning enterprise "adoption" frequently means running passkeys alongside legacy methods rather than instead of them.

Why the Password Isn't Actually Going Away Yet

Passwords persist for reasons that adoption statistics alone don't capture: account recovery when a device is lost, compatibility with older systems that were never built to support FIDO2 authentication, and the simple fact that a passkey tied to one ecosystem (an iPhone, a Google account) doesn't automatically follow a person to every device and platform they use. Cross-platform passkey syncing has improved but remains inconsistent enough that many services keep a password as a fallback rather than removing it entirely — which is part of why 41% of users, per a separate 2025 Yubico survey, still trust SMS-based authentication despite its well-documented weaknesses.

None of this requires waiting on any particular company's authentication roadmap. Reducing how much personal data touches a server in the first place — rather than only strengthening the login that guards it — is the same logic behind why client-side tools that never transmit your data remain a sound default regardless of which authentication method eventually wins.


The honest summary: passkey adoption in 2026 is real, well-documented, and moving faster than most security transitions typically do — 5 billion in active use, 90% awareness, and genuine operational gains at companies that have rolled them out fully. But that progress is heavily concentrated among a small number of very large platforms. Independent measurement of the actual web found passkey support on well under 1% of the sites checked, and even among people who've enabled a passkey, barely half use one as their regular method. "Passkeys have arrived" and "passwords are gone" are two very different claims, and only the first one currently holds up.

For questions or inquiries contact us at info@cleartexteditor.com