Will SMS OTP Disappear as Passkeys Grow?

July 29, 2026 No Comments

Will SMS OTP Disappear as Passkeys Grow? A 2026 Authentication Guide for Saudi Businesses

Passkeys have quickly moved from an emerging authentication concept to a sign-in method supported across major operating systems, browsers and digital platforms.

According to the FIDO Alliance’s May 2026 report, approximately five billion passkeys were in active use worldwide. The report also found that 68% of surveyed organizations were deploying, piloting or rolling out passkeys for workforce authentication. These figures are global rather than Saudi-specific, but they demonstrate how quickly passkeys are moving into practical use.

Does this mean SMS one-time passwords will disappear?

OTP

No, but their role will change.

Passkeys can reduce the need to send an OTP during every successful sign-in. SMS verification will remain relevant for confirming phone numbers, enrolling new users, recovering accounts, supporting incompatible devices and protecting selected high-risk actions.

What is a passkey?

A passkey is a digital credential associated with a user account and a particular website or application. Instead of typing a password, the user approves the sign-in using the device’s screen lock, such as a fingerprint, facial recognition, PIN or pattern.

Passkeys use public-key cryptography. The service stores a public key, while the private key remains on the user’s device or inside a credential manager. The website does not receive or store the user’s biometric information.

Because a passkey is linked to the website or application for which it was created, it offers stronger resistance to phishing. A deceptive website cannot use a passkey created for the legitimate domain.

Passkeys vs. SMS OTP

Passkeys and SMS OTP do not always solve the same problem.

AreaPasskeysSMS OTP
Primary rolePasswordless account authenticationTemporary verification through a mobile number
User requirementA device or credential manager containing the passkeyAccess to a mobile number that can receive messages
Phishing resistanceHigh because the credential is bound to the legitimate serviceLower because a user may enter the code on a phishing page
User experienceApprove with device unlockWait for and enter a temporary code
Phone-number ownershipNot automatically verifiedUseful for confirming access to a phone number
Recovery useRequires a planned recovery processCan be part of a fallback or recovery process

Google describes passkeys as an easier and safer alternative to passwords and notes that they can remove the need to request an SMS or app-based OTP during sign-in. Google also recommends offering a phone or email fallback so users can recover access after deleting all passkeys or losing access to them.

Will SMS OTP disappear?

A more accurate prediction is that OTP will move from being the default sign-in method to becoming an on-demand verification channel.

In a traditional journey, a user enters a password and receives an OTP during each sign-in. In a modern journey, the user may sign in with a passkey every day and only receive an OTP during enrolment, recovery or an unusual high-risk event.

Security standards do not treat SMS OTP as completely prohibited. NIST classifies authentication delivered through the public telephone network as a restricted authenticator. It requires organizations to understand the risks, provide an alternative method and create a migration plan. NIST also states that out-of-band and manually entered OTP authentication are not phishing-resistant.

The right decision is therefore not to eliminate OTP everywhere or use it everywhere. Businesses should select an authentication method for each specific step.

Where passkeys can replace OTP

Frequent sign-in

Once a passkey has been registered, users can sign in through their device lock without waiting for a new message.

Traditional password-plus-code journeys

A passkey can combine possession of the credential with local user verification, reducing the need for a password followed by a separate code.

Customer-experience friction

Users do not have to leave the application, open their messages, remember the code and return to the sign-in screen.

Phishing protection

The passkey cannot be used on an impostor domain. By contrast, a user can unknowingly type an SMS code into a fraudulent page.

NIST explains that authentication based on manually entering an OTP is not phishing-resistant because the code is not cryptographically bound to the legitimate authentication session.

Five areas where SMS OTP will remain important

1. Phone-number verification

A passkey proves that the user controls a credential associated with an account. It does not automatically prove that a newly entered mobile number is correct or accessible to that user.

SMS OTP remains useful when:

  • Creating an account associated with a phone number.
  • Changing the registered number.
  • Activating phone-based notifications.
  • Validating customer contact information.

2. Initial passkey enrolment

In many journeys, the user must sign in or verify their identity before creating a passkey. SMS OTP may be one of the methods used before binding the new credential to the account.

Google’s implementation journey begins with the user signing in through an existing method before registering a passkey.

3. Account recovery

Users may lose a device, remove their passkeys or attempt to sign in from a device where their credentials are unavailable.

Google recommends offering a fallback method that can deliver a link or code through a phone or email channel, enabling the user to recover access and create a new passkey.

For sensitive accounts, recovery should not be weaker than normal sign-in. A business may need several risk signals rather than relying on SMS alone.

4. Unsupported users and devices

Some customers may use older devices, restricted enterprise environments or configurations that make passkey sign-in difficult.

A controlled fallback prevents unnecessary account lockouts and customer abandonment.

5. High-risk actions

Additional verification may be appropriate when a user:

  • Changes core account details.
  • Adds a new device.
  • Replaces a mobile number.
  • Changes a confirmed delivery address.
  • Performs a high-risk transaction.
  • Adds a beneficiary.
  • Modifies user permissions.

The additional check should be triggered by risk rather than applied to every action.

Saudi Arabia’s Essential Cybersecurity Controls require suitable authentication factors, quantities and techniques to be determined according to an impact assessment of authentication failure and bypass.

A hybrid authentication model

Saudi businesses can design a modern journey in four stages.

Stage 1: Registration

  1. The customer enters a mobile number.
  2. The system sends an OTP to verify access to the number.
  3. The account is created after successful verification.
  4. The customer is invited to create a passkey.

Stage 2: Daily sign-in

  1. Passkeys become the primary sign-in method.
  2. No OTP is sent when the passkey works normally.
  3. A fallback option appears when the passkey is unavailable.

Stage 3: Risk-based verification

  1. The system evaluates the action, device and user behaviour.
  2. Additional verification is requested only when necessary.
  3. SMS OTP or another method is selected according to the risk.

Stage 4: Recovery

  1. Sensitive accounts do not rely on one recovery signal.
  2. The phone number and additional signals are checked where appropriate.
  3. Lost or untrusted credentials are revoked.
  4. A new passkey can be registered after recovery.

SMS OTP security best practices

OTP should not be treated as nothing more than a message containing a few digits.

Make every code single-use

The code should become invalid immediately after successful verification.

Limit attempts

NIST requires rate limiting for short authentication secrets and specifies that generating a new secret should not reset the number of failed attempts.

Control resend requests

Apply a delay between resend requests and set limits per phone number, account, device and network source.

Bind the code to its purpose

A code issued for changing a mobile number should not authorize another action. Registration codes should not be accepted for account recovery.

Monitor risk indicators

NIST recommends considering signals such as device changes, SIM changes and number porting before delivering an authentication secret over the telephone network.

Avoid account enumeration

Use balanced responses that do not reveal whether a particular phone number has an active account.

Measure the complete journey

Track:

  • OTP delivery rate.
  • Delivery time.
  • Verification success rate.
  • Resend requests.
  • Failed attempts.
  • Unusual request spikes.
  • Repeated numbers or devices.
  • Drop-off before successful verification.

Protecting personal data

Phone numbers and authentication records must be handled in line with applicable privacy requirements.

Saudi PDPL guidance includes principles such as purpose limitation, data minimization, storage limitation, and technical and organizational measures to protect the confidentiality, integrity and availability of personal data.

Businesses should:

  • Document why the phone number is collected.
  • Prevent OTP codes from appearing in unnecessary logs.
  • Restrict access to authentication records.
  • Define retention periods.
  • Protect data in transit and at rest.
  • Separate operational verification data from marketing use.

Common mistakes

  • Removing OTP before creating a reliable recovery journey.
  • Forcing every user to adopt passkeys immediately.
  • Using SMS OTP as the only control for every sensitive action.
  • Allowing unlimited verification attempts.
  • Reusing one code across several actions.
  • Failing to state the purpose of the code in the message.
  • Storing raw codes in system logs.
  • Ignoring sudden increases in OTP requests.
  • Measuring delivery without measuring completed verification.
  • Offering no alternative authentication method.

How OurSMS supports authentication journeys

OurSMS provides SMS services that include OTP and activation messages. The platform also supports API and SMPP integrations with applications, CRM systems, ERP platforms and online stores, along with reporting for message activity.

Businesses can use OurSMS OTP and SMS API as part of a hybrid authentication journey, using passkeys as the primary sign-in option for eligible users while keeping SMS available for enrolment, phone-number verification, recovery and controlled fallback scenarios.

Conclusion

Passkeys will not make SMS OTP disappear.

What will gradually decline is the unnecessary use of OTP during every sign-in, particularly when users can authenticate through secure, phishing-resistant cryptographic credentials.

SMS OTP will remain important when a business needs to verify a mobile number, enrol a new user, recover an account, support an incompatible device or add a control to a high-risk action.

The strongest 2026 strategy is not to choose a single winner. It is to build a layered authentication journey:

Passkeys for simple and secure daily sign-in, and OTP for the moments that genuinely require mobile-number verification or a controlled fallback channel.