Managing One-Click Sign-In with Passkeys

  • Services: IAM
  • Release Date: September 30, 2026

IAM now supports One-Click Sign-In for supported applications.

Important

You must create a Service Request (SR) with the Identity team to enable the required feature flag for this functionality. See Support Requests.

Users with an enrolled, discoverable FIDO passkey can sign in without entering a username. They select a passkey when prompted and verify their identity using a method supported by their authenticator, such as a fingerprint, facial recognition, device PIN, or security key.

Identity domain administrators can enable One-Click Sign-In through the identity provider policy rule that applies to an application. FIDO passkey enrollment must require a WebAuthn resident key so that new passkeys are discoverable. IAM also verifies the none and self attestation statement formats during FIDO enrollment and records the verification outcome.

To use this feature, create a Service Request with the Identity team to enable the required feature flag. Users must enroll a supported passkey before signing in. This release doesn't provide passkey enrollment during one click login or a fallback login factor within the One-Click Sign-In flow.

For more information, see Managing One-Click Sign-In with Passkeys.