Google says 400M+ Google Accounts have used passkeys since the rollout, logging 1B+ authentications, and expands passkeys to its Advanced Protection Program
Google is kicking off World Password Day by updating us on its efforts toward replacing the often hacked, guessed, and stolen form of authentication with passkeys.
Context & Ripple Effects
Google’s passkey program moved from account-wide availability to default prompts to create a passkey, shifting the effort from merely offering a password alternative toward driving adoption. The reported usage figures provide a concrete adoption signal for that rollout.
Extending passkeys to Advanced Protection applies the same authentication model to an account-security program built for users needing stronger safeguards. It also follows Google’s earlier broad passkey launch across accounts.
First-order effects
- Google can point to more than 400 million accounts and over one billion passkey authentications as evidence that its rollout is being used at scale.
- Advanced Protection users gain passkey support, making the program’s sign-in flow less dependent on conventional passwords while retaining its high-security focus.
Second-order effects
- The expansion raises the bar for other account providers: passkey availability alone becomes less differentiating than making enrollment and recovery workable for security-sensitive users.
- Greater use of device-based biometric authentication makes the quality of platform passkey support and cross-device account access more consequential to Google account security.
Third-order effects
- If adoption continues, consumer authentication is likely to shift from passwords as the default credential toward cryptographic, device-mediated sign-in, with transition and recovery flows becoming the key remaining friction points.
- Large-platform deployment can accelerate passkey normalization across services, but passwords may persist where users lack compatible devices or cannot easily move credentials between them.
The trend: This is part of the broader migration from reusable passwords to platform-managed cryptographic credentials, with major providers using default prompts and high-security programs to accelerate adoption.