The next wave of payment passkey rollouts is likely to land where regulators have put a date on the end of SMS one-time passcodes, not where e-commerce volume is largest. On the evidence of the last six weeks, the pattern suggests at least one further national market receives a named issuer or payment service provider passkey deployment before the end of Q1 2027, and that neither the United States nor the European Union is the market that leads it. That is a deliberately awkward claim, because it inverts the usual assumption that payment technology diffuses from the biggest markets outward. The signals point the other way: compliance deadlines, not gross merchandise value, appear to be setting the running order.
In short
- The prediction: network-scale payment passkey deployments are likely to follow dated SMS-OTP sunsets rather than market size, with at least one additional national market announcing a named issuer or PSP rollout before the end of Q1 2027, and the US and EU unlikely to lead it.
- Signal 1 (August 7, 2026): Visa disclosed the first hard numbers from its India rollout at the FIDO Alliance India working group meetup in Bengaluru, describing checkout authentication falling from roughly 50 seconds to about 20 seconds or less, with user interactions dropping from around eleven to three.
- Signal 2 (same event, independent source): MakeMyTrip reported 61% passkey adoption among repeat users, logins around seven times faster than mobile OTP and a 25% cut in SMS costs, while PhonePe presented a deliberately narrower deployment confined to login.
- Signal 3 (regulatory forcing function): India’s RBI authentication directions took effect on April 1, 2026, and the Central Bank of the UAE set a compliance deadline of March 31, 2026 for moving off SMS and email OTP, making both markets places where banks needed a replacement primitive on a schedule.
- The counter-signal that matters most: PhonePe kept passkeys away from the payment leg entirely, which suggests the largest domestic wallets may satisfy mandates with in-app soft tokens rather than FIDO credentials, and that would slow the export considerably.
Why this matters now
Payment passkeys have been announced repeatedly since 2024 without producing much that a retailer could act on. Mastercard selected India for the global launch of its Payment Passkey Service in August 2024, and Visa has since run issuer deployments in several markets. For most of that period the available evidence was directional rather than quantitative, which made it easy for merchants to file the whole category under “watch, do nothing.”
What changed in August 2026 is that numbers appeared. When a card network moves from describing a capability to publishing authentication times and interaction counts, it is usually preparing to ask issuers, acquirers and merchants to spend money. The disclosure itself is the signal, arguably more so than the metrics inside it. Networks do not typically publish conversion math at a standards-body workshop unless the commercial pitch is close behind.
The timing also matters for a second reason. Retailers in the Northern Hemisphere are locking peak-season checkout configurations now, and authentication changes are among the hardest things to ship in Q4. Any merchant asking whether passkeys belong on the 2027 roadmap needs a view on which markets get them, and in what order.
India is the natural place to look first, because it combines regulatory pressure, enormous transaction volume and a merchant base that has been aggressive about checkout experimentation throughout India’s e-commerce price war. But the interesting question is not whether passkeys work in India. It is what determined that India went first, because whatever that variable is, it likely predicts the second and third markets too.
Signal 1: Visa put numbers on the India rollout, five weeks in
Visa launched Payment Passkey in India in early July 2026, with IDFC FIRST Bank as its first issuer partner. The rollout covered select users across a merchant set that included Myntra, Paytm, MakeMyTrip, Tata Starbucks, Reliance Digital and EatSure, according to the company’s own announcement and subsequent industry coverage. Visa described the service as built on FIDO authentication standards and aligned with the Reserve Bank of India’s 2025 authentication framework. Readers who want the primary text can consult Visa’s India newsroom release.
The launch itself was not the signal. Launches are cheap, and a single-issuer pilot across “select users” is closer to a controlled experiment than a market event. The signal came about five weeks later.
At the FIDO Alliance India Working Group member meetup and workshop, held on Friday August 7, 2026 at Google’s Ananta campus in Bengaluru, Visa presented the first quantified results from the Indian deployment. Per accounts of that session, a checkout authentication that previously took around 50 seconds via OTP was completing in roughly 20 seconds or less, and the number of discrete user interactions required had fallen from about eleven to three. Those are large deltas by payments standards. They are also, notably, framed as friction metrics rather than fraud metrics.
That framing choice is worth dwelling on. Authentication changes have historically been sold to banks on fraud reduction, because fraud is the line item a risk committee already owns. Selling on elapsed time and interaction count is a merchant pitch, not an issuer pitch. It suggests the network is repositioning passkeys from a security upgrade into a conversion product, which is a different sale to a different buyer.
The other detail that reads as intentional is the partner list. The July rollout wired in Juspay, Wibmo, Razorpay, PayU, Pine Labs, BillDesk, M2P Fintech and Paytm Payments Services alongside the single issuing bank. That is the orchestration layer, not the issuing layer. A network that only wanted a pilot would not need eight processors and orchestrators integrated on day one, which is consistent with a deployment designed to scale sideways to further issuers quickly.
This is also of a piece with Visa’s broader pattern of pushing capability into the surfaces where consumers already are, visible elsewhere in Visa’s push into in-app bank experiences. The strategic logic in both cases is the same: own the authenticated moment, wherever it happens.
Signal 2: the merchant side reported adoption, and India’s largest wallet declined
The second signal came from the same event but from independent parties, which is what makes it useful. A network reporting its own pilot results is a press release with a chart. Merchants reporting their own numbers, unprompted, at a technical workshop is closer to evidence.
MakeMyTrip presented results from its passkey rollout showing 61% passkey adoption among repeat users, a login flow running roughly seven times faster than the traditional mobile OTP path, and a 25% reduction in SMS costs. The travel platform’s initial deployment was reported to have covered selected markets outside India, which is itself a small but telling detail about how these programmes sequence. It also shared an enrolment finding that will be familiar to anyone who has run onboarding tests: phrasing the prompt as “skip OTP next time” produced roughly twice as many passkey signups as neutral wording.
That last point is the least glamorous and probably the most operationally useful. It indicates the adoption constraint is presentation rather than capability, and that the consumer-facing framing that works is the removal of a known annoyance rather than the addition of a security benefit. Retailers planning enrolment flows should probably assume the same holds in their markets.
The 25% SMS cost reduction deserves separate attention. SMS OTP is a direct, metered, per-transaction cost that sits in the operations budget of every large merchant and issuer in markets where it is mandatory. In high-volume, low-average-order-value markets, that cost is material enough to fund an integration on its own, independent of any conversion benefit. This creates a self-funding business case that does not exist in markets where SMS OTP was never mandated.
Then there is the disconfirming half of the signal, which is more interesting than the confirming half. PhonePe, one of India’s largest payments platforms, also presented its passkey rollout at the same meetup. Per accounts of the session, PhonePe deployed passkeys for login only, deliberately kept separate from the UPI PIN, with new-device logins still requiring OTP plus a SIM presence check.
That is a considered architectural decision by a company with every incentive to reduce OTP costs. It suggests that the payment leg carries risk, liability and regulatory considerations that the login leg does not, and that large domestic players may adopt passkeys for authentication convenience while leaving transaction authorisation alone. If that posture generalises, the “OTP is finished” narrative is premature by some margin, and the addressable opportunity is narrower than the headline metrics imply.
Signal 3: two regulators, two deadlines, one available replacement
The third signal is the one that ties the first two into a predictive frame, and it is regulatory rather than commercial. Both markets where payment passkeys have moved fastest share a specific characteristic: a central bank put a dated deadline on moving away from SMS OTP.
In India, the Reserve Bank of India issued its Authentication Mechanisms for Digital Payment Transactions Directions on September 25, 2025, with compliance required from April 1, 2026. The directions mandate two distinct authentication factors for domestic digital payment transactions, with at least one dynamically generated, and explicitly encourage device-bound alternatives to SMS OTP. Importantly, the framework does not require discontinuing SMS OTP outright, a nuance that matters a great deal for the caveats below.
In the United Arab Emirates, the Central Bank set a compliance deadline of March 31, 2026 for moving off SMS and email OTP toward risk-based authentication technologies, with FIDO2-based passkeys named among the acceptable replacements alongside in-app cryptographic soft tokens, UAE Pass and biometric options. Reporting indicates UAE banks began moving online card payments to app-based approval from early January 2026. The Middle East was also where Visa ran what was described as its first global PSP-side passkey deployment, with noon payments, in late 2025.
Set against those two, the largest e-commerce markets look conspicuously unhurried. The table below compares the mandate structure across the markets that matter most.
| Market | Regulatory forcing function | Key date | Passkey status as of August 2026 |
|---|---|---|---|
| India | RBI Authentication Directions, 2025: two factors, at least one dynamic, device-bound alternatives encouraged | Compliance from April 1, 2026 | Live: Visa with IDFC FIRST Bank, Mastercard since 2024, quantified results published |
| UAE | CBUAE direction to move off SMS and email OTP to risk-based authentication, FIDO2 named | Compliance by March 31, 2026 | App-based approval widespread; direct passkey transaction approval still limited |
| European Union | PSD2 strong customer authentication, already satisfied by 3-D Secure and app-based flows | No new sunset date | Network-led, not mandate-led: Mastercard tokenisation programme targeting 2030 |
| United States | No federal authentication mandate for card-not-present | None | Issuer and wallet-led, fragmented, no coordinated deadline |
The asymmetry is stark. In India and the UAE, banks faced a dated compliance obligation and needed a replacement primitive that was standards-based, device-bound and already shipping. Passkeys were essentially the only option meeting all three conditions at network scale. In the EU and US, the compliance box is already ticked by incumbent technology, so the passkey business case has to be won on economics alone.
What the pattern suggests
Read together, the three signals describe a diffusion mechanism that is regulatory-first rather than market-first. The sequence appears to run: a central bank dates the end of SMS OTP, banks discover that compliant alternatives are scarce, the card networks arrive with a shipping FIDO-based product, and merchants pick it up because the SMS cost saving funds the integration. Market size influences how much noise a rollout makes, but it does not appear to determine the order.
If that mechanism is real, it produces a testable forecast. The markets most likely to receive the next network-scale payment passkey deployments are those with a dated authentication mandate on the calendar, which points toward further Gulf markets, additional South and Southeast Asian jurisdictions and any market whose regulator follows the RBI template. It points away from the US and EU, despite both being far larger by volume.
The signals matrix below sets out what each observation does and does not establish, since the confidence attached to each varies considerably.
| Signal | Date | Type | What it establishes | Confidence |
|---|---|---|---|---|
| Visa publishes India authentication metrics at FIDO India workshop | August 7, 2026 | Technology adoption disclosure | The network is moving from capability to commercial pitch; framing is conversion, not fraud | High: first-party, quantified, recent |
| MakeMyTrip reports 61% repeat-user adoption, 25% SMS cost cut | August 7, 2026 | Merchant-side proof point | Consumer uptake is achievable and the cost saving is self-funding | Medium-high: single merchant, partly non-India rollout |
| PhonePe confines passkeys to login, not payment | August 7, 2026 | Counter-signal | Large domestic wallets may not extend passkeys to transaction authorisation | High as a fact, uncertain as a trend |
| RBI directions effective; CBUAE deadline set | April 1 and March 31, 2026 | Regulatory | Both fast-moving markets share a dated OTP sunset | High: documented, but correlation not proof of causation |
| Visa India wires eight processors and orchestrators at launch | Early July 2026 | Deployment architecture | Designed to scale sideways to further issuers, not to stay a pilot | Medium: inference from partner list |
Three scenarios seem worth holding simultaneously, with the base case carrying most of the weight but not all of it.
| Scenario | What happens by end of Q1 2027 | What would confirm it early |
|---|---|---|
| Base case: mandate-led diffusion | At least one further market announces a named issuer or PSP passkey deployment, in a jurisdiction with a dated authentication mandate; US and EU do not lead | A Gulf or Asian regulator publishing an OTP sunset, followed within a quarter by a network announcement in that market |
| Alternative: network-led diffusion | Mastercard’s European tokenisation programme pulls passkeys into the EU without a mandate, via Click to Pay enrolment | European Click to Pay enrolment figures cited alongside passkey authentication share in the same disclosure |
| Downside: soft-token substitution | Banks in mandate markets satisfy regulators with in-app push approval instead of FIDO credentials; passkey deployments stall at one or two issuers per market | Mandate deadlines passing with compliance reported and no incremental passkey issuer announcements |
The alternative scenario is a genuine threat to the thesis rather than a courtesy hedge, and it is examined properly in the caveats section. The downside scenario is the one that would make the whole category a footnote.
There is a structural reason to think the networks will keep pushing regardless, which is that passkeys solve a problem beyond checkout friction. That connects to the broader argument that card-network rails rather than closed-loop checkout will carry agentic commerce, and it is where the next section goes.
Wider context: agentic checkout needs a device-bound credential
The conversion story is the one being told publicly. There is a second motivation that is less discussed and probably more durable.
If AI agents are going to initiate transactions on a consumer’s behalf, the network needs a way to prove that a specific human authorised a specific agent to spend on a specific credential. Shared secrets cannot do this, because an agent holding a password or an OTP is indistinguishable from a compromised agent holding the same. A device-bound cryptographic credential with a biometric gesture attached is currently the only primitive that is both shipping at network scale and capable of carrying that proof.
The evidence that networks see it this way is reasonably direct. Visa’s Trusted Agent Protocol and associated Agentic Directory give merchants a cryptographic method to verify that an AI agent is legitimate and acting with user permission, with issuers authorising the resulting transactions using Visa Payment Passkeys. In early July 2026, Worldline, ING and Visa reportedly completed a live end-to-end AI agent payment in Germany authenticated with a Visa Payment Passkey, with both Worldline and ING joining Visa’s Agentic Ready programme.
That German test is a small event with a large implication. It indicates the passkey is being positioned as the authorisation layer for agentic commerce, which means the network has a reason to drive enrolment that has nothing to do with cart abandonment. It also means enrolment breadth becomes strategically valuable ahead of any agentic volume actually materialising.
This reframes the India rollout. Getting tens of millions of consumers to enrol a device-bound credential is slow, and it is much easier to do when a regulator has removed the alternative. Mandate markets are, from this angle, enrolment accelerators. The conversion metrics are real, but they may be the justification rather than the motivation.
It also connects to a wider shift in how identity is handled at checkout, explored previously in the argument that tokenised agent identity becomes the gate for agentic checkout. Passkeys and agent identity are two halves of the same problem: proving who is present, and proving who authorised them.
Implications for retailers, PSPs and platforms
For most retailers outside mandate markets, the correct near-term action is probably not an integration. It is a question to the payment service provider, and the question is specific: what does the PSP’s roadmap say about payment passkey support, and in which markets, on what timeline. The answer separates providers who have done the work from those who have not.
For retailers operating in India, the Gulf or any market with an authentication deadline, the calculus differs. The SMS cost line is measurable today, the conversion delta is now quantified by at least one network, and the integration burden sits mostly with the acquirer and orchestrator rather than the merchant. Where a PSP already supports it, the case for enabling is stronger than the case for waiting.
The enrolment finding from MakeMyTrip generalises cheaply and is worth acting on regardless of market. If passkey prompts land better when framed as removing OTP rather than adding security, that is a copy change, not a project. It costs almost nothing to test.
Payment service providers face the sharper strategic question. The noon payments deployment established that a PSP can offer passkey authentication to its entire merchant base through a single integration, without each merchant rebuilding checkout. That turns passkey support into a competitive differentiator at the acquiring layer, and PSPs in mandate markets that lack it may find themselves explaining why during renewal conversations.
There is a compliance dimension too. Reducing the amount of authentication data flowing through merchant systems changes scope questions that retail teams already wrestle with, a theme covered in more depth in this guide to PCI DSS compliance for retailers without a compliance team. Device-bound credentials shift some of that burden away from the merchant environment, which is a secondary benefit worth quantifying locally.
For platforms and marketplaces, the strategic consideration is enrolment ownership. Whoever prompts the consumer to create the passkey holds a relationship asset, and the networks appear to be routing that prompt through issuers and PSPs rather than merchants. Platforms that want a seat in that flow should probably be asking about it now rather than after the pattern sets.
Caveats: what could go wrong
The prediction rests on a causal claim that the evidence supports but does not prove. India and the UAE both moved quickly and both had dated mandates, but two markets is a thin base for a diffusion law. It is entirely possible that both moved for local reasons, including unusually concentrated payment infrastructure and unusually high SMS costs, and that the mandate is coincidental rather than causal.
The strongest specific counter-signal is PhonePe. A company processing enormous domestic volume, with obvious SMS cost exposure, chose to deploy passkeys for login only and to leave the UPI PIN untouched. If that becomes the standard posture among large domestic wallets in mandate markets, then passkeys colonise authentication but never reach payment authorisation, and the commerce implications shrink to something close to nil.
The soft-token substitution risk is the second serious objection. The RBI framework does not require discontinuing SMS OTP, and the CBUAE framework accepts in-app cryptographic soft tokens alongside FIDO2 passkeys. A bank facing a compliance deadline can satisfy it with an in-app push approval it may already operate, at lower cost and lower integration risk than a passkey enrolment programme. Regulatory pressure creates demand for compliance, not specifically for passkeys, and that distinction could well prove decisive.
Reporting from mid-2026 noted that no major UAE institution had publicly implemented direct passkey-based transaction approval, despite the March deadline having passed. That is a meaningful data point against the thesis. It suggests the UAE satisfied its mandate largely through app-based approval rather than FIDO credentials, which is precisely the substitution scenario described above.
The third objection runs in the opposite direction and would falsify the prediction from the other side. Mastercard’s European programme is substantial and mandate-independent: as of its June 2026 disclosure, three in five European e-commerce transactions were tokenised against a 2030 target of complete elimination of manual card entry, with Click to Pay live in 32 European markets and enrolments reportedly doubling year over year. If passkeys ride into Europe on Click to Pay enrolment, the EU could arrive without any regulator dating an OTP sunset, and the “mandates lead” thesis would be wrong in an important way. The scale of that programme is the single best reason to hold the prediction loosely.
Device fragmentation is a fourth and more mundane risk. Passkeys depend on platform authenticator support and reliable credential sync, and mandate markets skew toward lower-cost Android devices where that support has historically been less consistent. A rollout that works well on flagship hardware and poorly on the devices most consumers actually own will stall regardless of network intent.
Finally, issuer enrolment remains the practical bottleneck. India had one named issuer live several weeks after launch. Whatever the orchestration layer can support in theory, the pace of the second, fifth and twentieth issuer signing on is what determines whether this becomes infrastructure or stays a demonstration.
FAQ
Below are the questions that follow most naturally from the argument above, including several that cut against it.
What exactly is a payment passkey, and how is it different from a passkey for login?
A payment passkey is a FIDO-based, device-bound cryptographic credential used to authenticate a payment transaction, typically confirmed with a fingerprint, face scan or device PIN. The underlying technology is the same as a login passkey, but the context differs: it authorises a specific transaction rather than establishing a session. That distinction carries real liability and regulatory weight, which is why some deployments, including PhonePe’s, use passkeys for login while keeping the payment leg on existing mechanisms.
What is the prediction here, precisely, and how would someone check it?
The prediction is that the next network-scale payment passkey deployments will land in markets with dated regulatory sunsets on SMS OTP rather than in the largest e-commerce markets, with at least one additional national market announcing a named issuer or PSP rollout before the end of Q1 2027, and with neither the US nor the EU leading. It can be checked by tracking network and issuer announcements over the next two quarters and asking, for each, whether that market had an authentication mandate on the calendar. If the next major rollout is a US or EU issuer at scale with no mandate behind it, the thesis is wrong.
Isn’t this just an India story with limited relevance to Western retailers?
Partly, and that is a fair challenge. The immediate operational relevance is concentrated in India and the Gulf, and a US or European retailer will not be changing checkout because of the Bengaluru numbers. The wider relevance is that these markets are functioning as the proving ground for metrics that networks will later use to sell the same product elsewhere, and that the agentic commerce use case is market-agnostic.
Why would the largest markets be slower rather than faster?
Because their compliance obligations are already satisfied. PSD2 strong customer authentication in the EU is met by 3-D Secure and app-based flows that issuers have long since built and amortised, and the US has no federal authentication mandate for card-not-present transactions at all. Without a deadline forcing a change, the passkey business case has to win on economics against incumbent systems that already work, which is a much harder sale.
How reliable are the numbers from the Bengaluru workshop?
They should be treated as directional rather than audited. The authentication timing and interaction-count figures came from Visa describing its own deployment, and the adoption figures came from MakeMyTrip describing its own rollout, with neither subject to independent verification. The MakeMyTrip figures also appear to relate partly to markets outside India, which limits how cleanly they read as evidence about the Indian rollout specifically.
Could banks meet these mandates without adopting passkeys at all?
Yes, and this is the most serious risk to the prediction. The RBI directions do not require discontinuing SMS OTP, and the UAE framework explicitly accepts in-app cryptographic soft tokens alongside FIDO2 passkeys. A bank with an existing mobile app can often satisfy the requirement with push approval at lower cost and lower risk than a passkey enrolment programme, and reporting suggests this is broadly what happened in the UAE.
What should a retailer outside a mandate market actually do now?
Ask the payment service provider for its passkey roadmap by market and by date, and record the answer. Beyond that, the enrolment copy finding is worth testing cheaply wherever passkeys are already offered, because framing the prompt as skipping OTP rather than as a security upgrade reportedly doubled signups in at least one large deployment. Neither step requires a project.
How does this connect to AI agents making purchases?
An agent transacting on a consumer’s behalf needs to prove that a specific person authorised it, and shared secrets such as passwords or OTPs cannot carry that proof. Device-bound cryptographic credentials can, which is why Visa’s Trusted Agent Protocol work pairs agent verification with passkey-based issuer authorisation. The live Worldline, ING and Visa agent transaction in Germany in July 2026 suggests this is being built rather than merely discussed.
What single development would most change this view?
A major European or US issuer announcing a broad payment passkey rollout with published enrolment targets, absent any regulatory deadline. That would indicate the economics alone are sufficient, that mandates are an accelerant rather than a precondition, and that the diffusion order is set by network commercial priorities rather than by regulators. Mastercard’s European tokenisation programme is the most plausible route to exactly that outcome.