← 返回新闻首页
新加坡主流

Singpass passkey that turns mobile devices into digital keys to counter scams now available to Android users

Read more at straitstimes.com.

The Straits TimesSarah Koh查看原文 ↗
为加强对网络钓鱼等诈骗的防范,Singpass应用将推出通行密钥(Passkey)作为新的登录方式,用户可在最新版本的Singpass应用上创建通行密钥。当局从2026年7月1日起,逐步让用户使用通行密钥登录。
为加强对网络钓鱼等诈骗的防范,Singpass应用将推出通行密钥(Passkey)作为新的登录方式,用户可在最新版本的Singpass应用上创建通行密钥。当局从2026年7月1日起,逐步让用户使用通行密钥登录。

A user’s passkey cannot be shared or exploited, unlike passwords or QR codes, and will not work on fake websites.

Published Sep 09, 2026, 11:37 AM

Updated Sep 09, 2026, 11:37 AM

SINGAPORE - A new mode of national authentication initially rolled out to Apple iPhone users has now been extended to Android phone users.

National authentication system Singpass’ new passkey feature aims to foil phishing scams that have led to millions in losses by ensuring that access is granted to legitimate websites only.

It works through a unique pair of encryption keys – one residing on the user’s phone and the other on Singpass’ backend server – for every website that is integrated with the national authentication system.

Thus, a user’s passkey cannot be shared or exploited, unlike passwords or QR codes, and will not work on fake websites.

Android users will receive reminders to create their passkeys via notifications from the Singpass app starting Sept 9, said the Government Technology Agency of Singapore in a statement.

Around 800,000 iPhone users have created their passkeys since the initial rollout in July, it added.

GovTech is the agency that operates Singpass, which supports 5.5 million users and is integrated with over 1,400 government agencies and private sector services. They include digital health portal HealthHub, the Inland Revenue Authority of Singapore’s tax portal, the Central Provident Fund Board, DBS Bank and Singtel.

A one-time registration is needed to use passkey authentication.

Android users need to update their Singpass app and click on the “create passkey” banner in the app, and follow the instructions provided to enable their passkeys.

Once the pair of unique passkeys are registered with Singpass, users log in to websites that accept Singpass verification by scanning their face or fingerprint in their Singpass app. Users who have not set up biometric authentication can enter their six-digit passcode in the app.

Singpass’ backend system will verify the private key stored on a user’s device against the public key registered in the system to validate every login.

Users need not register separate pairs of encryption passkeys for every website.

Laptops and desktops currently do not support Singpass passkey. But the feature will be extended to desktop users by the end of 2026, said GovTech.

Singpass passkeys comply with open standards developed by the Fast IDentity Online (Fido) Alliance, an industry association comprising over 250 members. They include tech firms such as Microsoft, Google and Apple, as well as government bodies in Australia, the United Kingdom and the United States.

Many online services, including those from Apple, Google, Microsoft and Adobe, already offer Fido passkey authentication, in addition to traditional passwords and two-factor authentication.

The number of phishing cases in Singapore has fallen to 3,104 cases in the first half of 2026, from 3,772 during the same period in 2025. Monetary losses suffered by victims of phishing scams have also fallen from $30 million to $9.6 million.

GovTech/Government Technology Agency

Technology and research

手机左右滑动,电脑按 ← → 键,也能切换新闻