From
Ideem— device-bound passkeys and A2A payment authentication for banks, fintechs, and payment platforms.
Every bank wants passkey adoption. Most pursue it the slow way: launch passkeys as an optional upgrade, put a banner in the app, and wait for users to opt in. The accounts that most need phishing-resistant authentication are often the ones that never tap the banner.
There is a faster path, and it is a timing decision more than a technology decision: enroll the passkey at the moment the user onboards. Silent KYC makes that practical. Options such as silent network authentication (SNA) provide a deterministic credential for enrolling a device at the time of passkey onboarding. Passkeys, combined with device binding via cryptography (that is the plus in Passkeys+), keep that account secure from that moment forward.
Start with two different problems that are easy to conflate. Opening a bank account is an identity question: compliance teams run document checks, biometric matching, and database lookups to satisfy KYC obligations. Accessing that account afterward, every mobile banking login for years to come, is an authentication question. Different problem, different tools, and usually a very different level of investment.
Institutions spend real money on the first problem. Then the second one gets a password and a six-digit code sent over SMS.
KYC Passkeys close that gap on the authentication side. During onboarding, while the user is already in a setup flow, an SNA provider verifies phone possession and a phishing-resistant, cryptographic credential is enrolled on the device. The account starts life with strong authentication already in place, instead of waiting for the user to find an upgrade banner months later.
Three stages, three distinct owners.
1. SNA verification during passkey enrollment. As part of passkey enrollment at onboarding, an SNA provider verifies phone possession silently over the carrier network. There is no OTP for the user to retrieve and no interruption to signup. This is a deterministic possession check performed by the carrier verification layer, and it is the foundation the credential is built on.
2. The credential is enrolled at that same moment. While the SNA check completes, Passkeys+ binds the user's device using MPC-based device binding and enrolls a passkey. The binding runs on ZSM, Ideem's multi-party computation architecture: the cryptographic secret is split so that no complete key ever exists on the device or the server. The passkey is now active on the strong foundation of the SNA authentication that just occurred.
3. Every future strong authentication runs on the passkey. Login, step-up, high-value transaction approval. No SMS fallback, no OTP. The SNA check happened once, at enrollment. From then on, authentication is a cryptographic ceremony between the bound device and your servers.
Optional upgrades convert poorly because they interrupt users who opened the app to do something else. Onboarding is the one moment when setup steps are expected, when the user is already engaged, and when the SNA check can run silently inside a flow that is happening anyway. Enroll there and adoption stops being a campaign you run later. Every account opened this way begins with a phishing-resistant, cryptographic credential in place on day one.
Timing also determines what the credential inherits. A passkey enrolled from a settings page six months after account opening is issued inside a session protected by a password and an SMS code, the exact things the passkey was meant to replace. A passkey enrolled during onboarding is born inside the strongest session that account will ever have.
KYC Passkeys are possession- and inherence-factor authentication: the SNA provider verifies phone possession, an actual KYC-grade check, and the resulting passkey binds that verified moment to the device with cryptography. Then subsequent authentications with Passkeys+ verify that possession and inherence factor. It is authentication, bound by strong auth via the SNA provider.
One clarification on the word KYC, because two kinds of accounts get confused here. KYC Passkeys are not KYC for opening a bank account. Document checks, database lookups, and compliance obligations are unchanged and remain the job of your identity verification providers. KYC Passkeys secure access to the account, the mobile banking logins and step-ups that follow, from the moment it exists. The name marks when the credential is born, during the KYC flow, not what it claims to do.
Not SMS with extra steps. There is no code, no channel to intercept, no phone number in the authentication path after enrollment. The credential is bound to the device with MPC, and it cannot be exported, synced away, or replayed from other hardware.
For fraud teams: the attack window between onboarding and daily authentication, the window where SIM swap and OTP interception live, does not open. There is no SMS in the loop to attack.
For product teams: the friction budget spent on OTP retrieval at every login, checkout, and step-up goes to zero after day one. Verify silently once, authenticate cryptographically from then on.
For the institution: the KYC spend stops depreciating. The assurance you paid for at account opening is still doing work at every authentication, years later.
We are working with partners in banking and payments to deploy KYC Passkeys today. If enrolling passkeys at onboarding is something you are exploring for your own flows, we would love to compare notes.
Most orgs running OTP-based MFA have 3–4 exploitable gaps they don’t know about. Our Authentication Assessment takes 2 minutes and shows you exactly where you stand — plus a phased migration roadmap.
Take the Assessment →Built by Ideem
Device-bound passkeys and A2A payment authentication. One SDK. No OTPs, no redirects.
Our 2-minute assessment scores your authentication setup and shows you exactly where the improvements are.
See Your Score →