Visa Develops FIDO-Based Payment Passkey to Replace OTP Authentication in India

Pattern of various antique keys and keyholes arranged on a bright yellow background, representing the concept of security, access, or unlocking solutions.

Visa is developing and implementing alternatives to one-time password (OTP) authentication to enhance payment security and user convenience. The company’s new Visa Payment Passkey solution uses biometric and cryptographic authentication based on the FIDO (Fast Identity Online) standard, enabling users to authenticate payments using fingerprints or facial recognition across devices instead of passwords and OTPs. Initial data shows this approach has achieved nearly 50 percent lower fraud rates compared to traditional OTP-based methods.

The initiative supports Visa’s broader push toward biometric authentication, with previous research showing that more than half of cardholders prefer biometric methods over traditional authentication. The company recently launched its first global merchant payment passkey system in partnership with noon payments, demonstrating its commitment to expanding this technology.

Ramakrishna Gopalan, Visa’s head of products and innovation for South Asia, addressed the current limitations of OTPs, including delays, delivery failures, and vulnerability to phishing attacks. He noted that while OTPs have served India well, the Reserve Bank of India’s (RBI) new framework now allows for interoperable alternatives, creating opportunities for faster and more secure authentication methods.

“The transition away from OTPs will be gradual, moving toward more seamless and secure identity-based authentication,” said Gopalan. He emphasized that the RBI’s principle-based approach allows consumers to choose their preferred authentication method, with OTPs remaining an option for those who find them convenient, while others may opt for biometric alternatives. Financial institutions can enhance security by implementing additional layers of verification, such as device data or transaction history analysis, without impacting user experience.

The RBI’s new regulatory directions, which take effect April 1, 2026, maintain the requirement for two-factor authentication in digital payment transactions while expanding beyond OTP-only solutions. The approved authentication factors now encompass SMS-based OTPs, passphrases, PINs, card hardware, software tokens, fingerprints, and other biometric methods, including both device-native and Aadhaar-based options.

The shift away from OTP-based authentication comes amid growing concerns about SIM swapping attacks, which have seen a dramatic surge of over 1,000 percent in recent years. The financial services industry is exploring additional biometric and AI-driven verification methods, including selfie verification technology. These solutions provide instantaneous authentication with enhanced security features compared to traditional OTP systems, which can be compromised through SIM swapping and phishing attacks.

India’s digital payments ecosystem is already embracing this transition, with the National Payments Corporation of India (NPCI) developing facial recognition capabilities for Unified Payments Interface (UPI) transactions as an alternative to PIN-based verification, signaling a broader shift toward biometric authentication methods across the country’s financial sector.

Sources: Times of India, Entrepreneur India, Surepass