The FIDO Alliance spent twelve years trying to stop bots from authenticating. It now has two working groups dedicated to helping agents sign in. That reversal is the cleanest way to understand where identity infrastructure is heading, and it came directly from Andrew Shikiar, CEO and Executive Director of the FIDO Alliance, who called it a juxtaposition in his own organization's history.
Shikiar has a specific claim about why passkeys worked, and it is not the one usually offered. The protocols had existed for close to a decade before passkeys, deployed at scale, used by what he estimates was hundreds of millions of people who had no idea what they were using because every implementer called it something different. What changed was letting the private key sync across devices, giving the thing a name and a logo, and publishing design guidelines so that nobody's first experience of it was a bad one. Three moves, none of them cryptographic.
He is now trying to run the same play on verifiable credentials, and the mechanism he has chosen is worth paying attention to. FIDO's core deliverable in digital credentials is not a specification. It is a wallet certification program, built on a baseline profile for security, privacy, and interoperability, working with protocols that belong to OIDF, ISO, and IETF rather than to FIDO. His argument is that the credential market has never lacked standards. It has lacked a way to know whether anyone implemented them the same way.
The conversation also covers where he expects value to accumulate in the eIDAS ecosystem, why he thinks derived credentials will become a common model that most of the market has not yet absorbed, what a merchant actually needs before it can trust an agent, and why Google and Mastercard handed AP2 and Verifiable Intent to a standards body rather than keeping them. The insights below are drawn directly from that session.
Why Passkeys Actually Worked
- Passkeys succeeded because FIDO changed the underlying model, not just the marketing. For FIDO's first decade the private key could never leave the device, which gave very high assurance that a specific user was on a specific device, but Andrew Shikiar said that model was not scaling for mainstream adoption.
- The unlock was allowing the private key to be securely synchronized across an operating system cloud, such as iCloud Keychain or Google Password Manager, and across credential managers like Dashlane and 1Password. Consumer relying parties had told FIDO directly that device-bound enrollment was a dealbreaker, because a user who enrolls on an iPhone expects the credential to be there on their iPad, MacBook, or PC.
- The second lever was naming. Before passkeys, FIDO had been deployed at meaningful scale and Shikiar estimates hundreds of millions of people were already using WebAuthn or UAF without knowing it, because every implementer called it something different. Introducing the passkey term and a logo program created what he called the connective tissue between one implementation and the next.
- The third lever was user experience research and published design guidelines. FIDO's view was that everyone's first passkey experience had to be a good one or they would not come back, so the guidelines functioned as a cookbook that flattened the relying party learning curve and produced repeatable user journeys.
- Shikiar's estimate is that over 5 billion passkeys are now in use, with consumer awareness of passkeys as a sign-in technology at roughly 85 to 90 percent.
- His read on why FIDO succeeded where earlier attempts failed is that the password problem was profound enough to demand a unified industry approach, pulling in major platforms, chipset vendors, payment networks, top banks, governments, and identity and biometric vendors at the same time.
What a Passkey Proves, and What It Does Not
- A passkey verifies the sign-in of a registered account. It proves that the person holding the device is the one signing in. Shikiar was explicit that it does not necessarily prove identity.
- Identity binding is a separate layer that sits on top of the passkey, typically implemented by the relying party using vendor tooling. This is the gap that digital credentials are being brought in to close.
- Nick Lambert framed passkeys as closer to binary, access or no access, with verifiable credentials adding context. Shikiar agreed that this is a reasonable way to think about it.
FIDO's Move Into Digital Credentials
- FIDO announced its intent to move into digital credentials in December 2025, but spent the whole of 2025 consulting government issuers, private issuers, verifiers, relying parties, and developers first. The question they were testing was whether FIDO could add value rather than duplicate existing work.
- Shikiar's stated premise is to give verifiable credentials a passkey moment: keep the existing foundational protocols, then add the certification program, go-to-market program, consumer awareness, and branding that were missing. He noted that verifiable credentials have been discussed in one form or another for over 20 years with fits and starts, but have not yet been unleashed at scale.
- He pushed back on how the market has framed the choice. It has been presented as passkeys or digital credentials, and in his view it is an "and". Even once credentials are widely deployed, he expects use cases where pseudonymous sign-in with a passkey is the right answer because the information in a credential is not needed.
- The critical scoping point for anyone tracking this: FIDO's core deliverable here is not specifications. It is a certification program, specifically a wallet certification program built around a baseline wallet profile covering security, privacy, and interoperability.
- The difference from the passkey era is that FIDO was commercializing its own protocols with passkeys. With credentials it is working with OIDF, ISO, and IETF to help the industry commercialize collective protocols, verifying that a wallet correctly implements credential formats and presentation protocols so an issuer or relying party can trust a credential irrespective of which wallet holds it.
Regional Divergence and the Interoperability Argument
- Shikiar does not expect the EUDI model to be copied wholesale. He described Europe as the most ambitious example of a regulation-driven approach, said he does not expect that to happen in the US, and pointed to India, Japan, Singapore, and Australia as places where strong centralized identity schemes are emerging and will fill in points along that spectrum.
- The EUDI work is still useful to FIDO because it gives the certification program something concrete to target, with extensibility for in-country requirements. He also flagged that this is not only about government issuers: banks and telcos are planning to issue their own wallets, and credential managers can be seen as wallets too.
- His position is that whether regulation or open market pressure drives adoption is debatable, but the need for interoperability is not.
Derived Credentials as the Value Layer
- Lambert put forward Dock Labs' hypothesis that the commercial opportunity sits above the regulated core: QTSPs and certified wallet providers supply the foundation, and value accrues in the layer where companies anchor against that verified data and issue derived credentials, referred to in EU terminology as electronic attestations of attributes (EAAs).
- Shikiar agreed and went further, saying derived credentials will become a very common model and that he does not think the market has fully absorbed that yet. The government-issued credential is the foundation, but the derived credential is where he expects innovation to happen.
- The mechanic he described: a service pulls the attributes it needs from a credential, combines them with its own first party data, and issues its own credential based on the underlying cryptographic proof. The value is delivering high assurance identity services without reproving identity from scratch every time.
- This is also where he argued interoperability stops being a nice-to-have. An organization can only build on top of a PID if wallets implement the same profile the same way, with the same formats, presentation protocols, trust models, and privacy models, which is precisely what certification is meant to guarantee.
Agents and the Verified Human Behind Them
- Shikiar described the position FIDO is now in as a juxtaposition. It spent its first 12 years trying to prevent bots from authenticating, and now has to work out how to let agents sign in.
- FIDO's chosen focus is deliberately not AI agent identity. It is the identity of the human behind the agent. Shikiar said the service should not need to trust the agent itself so much as the chain tying that agent back to an accountable person, with clear evidence of what the person actually authorized.
- The framework he outlined is verified human identity, then verified user intent and authorization, then phishing-resistant authentication, tied together as a continuous chain of trust.
- On whether agents and humans need to be distinguishable, his view was that there should be visibility into both and context awareness of which is which, but that knowing the verified human behind the agent is the more critical requirement. He connected this to the good bot versus bad bot problem: you trust an agent because there are breadcrumbs leading back to a verified person.
- One of the clearest risk warnings in the session: FIDO's second priority is making sure agents authenticate to third party services in a secure, unphishable way, because the easy path is for the industry to backslide into using human-readable credentials for agent authentication. Shikiar drew the parallel to open banking and said the industry should not go back to screen scraping when cryptographic methods exist.
Agentic Commerce Is a Liability Problem First
- Shikiar dated his own starting point on this to autumn 2024, when an executive sponsor at Mastercard asked how FIDO was thinking about agentic commerce, and he admitted FIDO had not thought about it much at that point.
- His framing is that agentic commerce is as much a legal and liability challenge as a technical one, and he said this has become the front and center issue in industry discussions. He described two hard cases. In the first, a user has an agent transact on their behalf and then wants to contest the result, or the agent simply buys the wrong thing. In the second, the agent goes rogue. Both land on the same set of questions: chargebacks, internal processes, and who actually held the authority to approve the purchase. Banks, issuers, and merchants have spent years working those questions out for e-commerce. Agentic commerce, in his words, multiplies them.
- He was blunt about the analyst projections: the billions or trillions of dollars forecast for agentic commerce will not materialize without a trust layer implemented through technical protocols.
- His timing estimate is that first party agents enabled by the merchant itself exist today, but third party agents transacting at scale are roughly 18 months out. He also expects merchants to start with a walled garden, a parallel store where agents can transact more safely.
- Lambert's counter-hypothesis was that B2B repeat commerce may arrive first, because separate billing relationships avoid the card payment liability question and product catalogs are less complex. Shikiar agreed, on the basis that trust is easier to establish in a one-to-one relationship between two businesses than in an open landscape.
- On catalog readiness, Lambert cited a session at Money20/20 in Amsterdam where a speaker from Adyen described products carrying roughly 10 attributes for a human shopper, and merchants now looking at 30 attributes so an agent can understand what it is buying. Repricing an entire catalog at that depth is not an overnight project.
AP2, Verifiable Intent, and Standards as Commoditization
- FIDO launched a payments working group in the middle of 2025, before any of the agentic contributions, and Shikiar said it quickly became the most active working group in the Alliance, with major payment networks, banks, and merchants involved and work running complementary to EMVCo for payments off the card rails.
- At the beginning of 2026, Google approached FIDO to contribute AP2, the Agent Payments Protocol, on the basis that it had momentum and a strong open community but would benefit from the stewardship of an open body. Mastercard followed with Verifiable Intent, which was built to be complementary to AP2. Both have now been formally transferred into FIDO.
- The division of labor between the two: AP2 lets agents securely initiate and complete payments on a user's behalf using cryptographic mandates that evidence who authorized the payment and under what restrictions. Verifiable Intent creates the record of what the user approved the agent to do. Together they address the problem that once an agent can search, assess, and buy, the merchant or bank can no longer assume the person is present.
- This required FIDO to change how it operates. It has historically been a member-driven standards organization where you had to be a member to contribute to specifications, and it is not an open source community. The GitHub repositories for AP2 and Verifiable Intent will persist, with public review of files, issues, and pull requests, and the public able to create and comment on issues.
- Shikiar said over 60 organizations were part of AP2 before the contribution, which he framed as an expansion of the broader FIDO ecosystem rather than a transfer of a small project.
- His definition of a standard is worth quoting in spirit: an act of collective commoditization, agreeing that a layer of technology carries no competitive advantage on its own and is better established as the shared value line everyone implements on top of. In his reading, that is exactly what Google and Mastercard chose to do.
Pace and Market Discipline
- Asked whether the industry is moving too fast, Shikiar's answer was that you cannot force hyperscalers and AI platforms to slow down and it would not be natural to try. What can be slowed down is the layer he called authentication primitives, where agreeing on shared foundations lets the layers above move at the same pace but more securely and consistently.
- He also said he is a believer in free markets and expects the market to supply the feedback, in the form of meaningful business ramifications when someone moves too quickly and gets burned.
Audience Questions
- On whether organizations working with FIDO are shifting their identity strategies, Shikiar said the strategies are broadening across the whole identity lifecycle rather than changing direction. FIDO focused on sign-in for its first decade because it was the weak spot, and passkeys have largely stopped credential and phishing attacks at that point. Attackers are therefore moving earlier in the chain to account creation and the human behind it, which is why remote identity verification and cryptographic proof of a credential are both now in scope.
- On who is responsible for giving an agent its identity, the user or the platform, his answer was both. A user asserting that something is their agent may not be sufficient for a relying party, which will want the platform or wallet to corroborate that the user did authorize it and that a verified person is behind the agent.
- On whether wallet certification would only be achievable for large providers, Shikiar said any wallet provider can get certified and that FIDO's goal is for certification to be referenced in regulation and in RFPs. He pointed to over 1,500 FIDO certified products in user authentication, where most RFPs now open with a FIDO certification requirement, and to the central bank of Vietnam requiring vendors doing remote IDV to hold FIDO IDV certification. His belief is that certification unlocks the market for smaller vendors who can meet the requirements.
- On privacy, he said FIDO's privacy principles have not changed since its foundation and will carry through into the wallet work. The wallet certification is still being written, and he noted the working group is active, fast-moving, and short of people willing to lean in.






