BIO-key Receives FIDO Alliance Full Certification for Passkey:YOU™ Authentication, Unlocking New Markets Including Agentic AI Authenticated Controls
FIDO Alliance Full Certification validates Passkey:YOU as a standards-based, centrally managed biometric authenticator for passwordless enterprise and AI-related access.
Rhea-AI Summary
BIO-key (BKYI) received Full Certification from the FIDO Alliance for its Passkey:YOU™ authenticator, confirming compliance with the FIDO2/WebAuthn/Passkey standard for phishing-resistant, passwordless sign-in.
Passkey:YOU lets employees authenticate with a fingerprint, palm, face, or existing door-access badge, without requiring smartphones or separate hardware tokens. A single enrollment works across passkey-enabled services, including Microsoft Entra ID, Okta, Ping, Duo, BIO-key PortalGuard®, and supported websites, with no separate integrations. The product is centrally managed to give enterprises visibility and control over where credentials are used, and uses BIO-key’s Identity-Bound Biometrics, NIST-tested fingerprint platform, and MobileAuth app to support regulated, shared-workstation, and phone-restricted environments.
Positive
- None.
Negative
- None.
Details
Market Reaction – BKYI
On Sep 23, the day this news came out, the latest delayed price for BKYI is 0.46% below the previous close. Argus tracked a peak move of +5.6% during the session. Our momentum scanner has recorded 8 alerts for this stock so far that day. The latest delayed price is $2.37. Relative volume is exceptionally heavy at 6.3x the average.
Data tracked by StockTitan Argus (15 min delayed). Upgrade to Gold for real-time data.
Key Figures
- Security Assurance Level
- L1
- FIDO Alliance Full Certification for Passkey:YOU
- CTAP specification
- FIDO2 CTAP v2.0
- Specification cited for Passkey:YOU certification
- Hardware security key cost
- $25–$70 each
- Typical cost cited as a comparison for Passkey:YOU’s shared hardware model
Key Terms
fido2 technical
webauthn technical
cmmc regulatory
gdpr regulatory
AI-generated analysis. How Rhea-AI works. Not financial advice.
Passkey:YOU lets employees authenticate with a fingerprint or the door badge they already wear — no phone or hardware token required
HOLMDEL, N.J., Sept. 23, 2026 (GLOBE NEWSWIRE) -- BIO-key® International, Inc. (NASDAQ: BKYI), a global provider of workforce and customer Identity and Access Management (IAM) software featuring passwordless, phoneless and tokenless Identity-Bound Biometrics™ (IBB) authentication, today announced that its Passkey:YOU™ authenticator has received Full Certification from the FIDO Alliance, the industry body behind the FIDO2/WebAuthn/Passkey standard now in widespread use to allow phish-resistant sign in without typing a password.
With Passkey:YOU, an employee authenticates to unlock a shared passkey service by touching a shared fingerprint scanner or tapping the door-access badge they already carry — no smartphone or separate hardware token needed. A single enrollment then works everywhere a passkey is accepted, including enterprise identity platforms such as Microsoft Entra ID, Okta, Ping, Duo, BIO-key's own PortalGuard®, and a growing list of websites, with no separate integration project required for each one. Employees who do carry a phone can authenticate the same way through BIO-key's MobileAuth app on iOS and Android. Passkey:YOU works at any workstation in the enterprise to provide easy, phish-resistant authentication without phones, or tokens.
Passkey:YOU’s design solves a specific problem: most authentication products assume every user carries a smartphone or can be issued and carry a physical token like a security key, which they use to authenticate. Passkey:YOU is built for the people and places where that assumption breaks down — secure facilities where phones aren't allowed, air-gapped networks, shared workstations, manufacturing floors, call centers, retail counters, and healthcare settings. Because the Passkey:YOU authentication hardware lives at the workstation rather than in every employee's pocket, one Passkey:YOU client can serve any number of roving or device-restricted workers.
Full Certification is the FIDO Alliance's formal confirmation that Passkey:YOU meets the technical and security bar — Security Assurance Level L1, conforming to the FIDO2 CTAP v2.0 specification — to work as a standards-based authenticator with any of those destinations, rather than a proprietary system. It's secured by BIO-key's NIST-tested, scanner-interoperable fingerprint platform and its MobileAuth palm and face authentication.
In biometric mode, Passkey:YOU runs on BIO-key's Identity-Bound Biometrics, meaning each employee's own fingerprint, palm, or face becomes their credential — something they can't share, forget, or lose the way they could a password or a token. Biometric data is encrypted to military-grade, quantum-resistant levels, and the platform supports NIST 800-63 and CMMC authentication requirements along with more than 30 interchangeable fingerprint scanners, so organizations aren't locked into a single hardware vendor. One enrollment carries across devices and locations, and enrollment workflows and user-controlled privacy dashboards are built to comply with GDPR and other privacy laws.
Passkey:YOU Means Better Governance and Control for Enterprises
A traditional hardware security key is, by design, invisible to the organization that issued it: once provisioned to a user, IT typically can't see which sites or systems it has been registered with, can't approve new ones, and can't revoke access to a single third-party account without physically collecting the key back. That's a reasonable tradeoff for an individual consumer. For a regulated or enterprise workforce, it's a blind spot.
Because Passkey:YOU is centrally managed, security and compliance teams get the opposite: visibility into which systems employees have authenticated to, the ability to approve new destinations, and the ability to cut off access to any one system instantly — without waiting for someone to physically return a device. It still presents a standard, certified interface to Entra ID, Okta, Ping, Duo, and every other passkey-enabled destination; what changes is what the organization can see and control behind it.
Agentic AI Must Be Controlled by Real People, Not Inanimate Tokens
As AI agents take on the ability to act across applications, data, and payments on a company's behalf, someone has to be accountable for approving what they do — and that accountability breaks down if approval rests on a credential that isn't tied to a specific person, such as a password left in a browser session or a hardware key left plugged into a shared machine.
Passkey:YOU ties that approval to a person’s unique physical features instead: a fingerprint on a shared scanner, or a face or palm scan through MobileAuth, is evidence that a specific, named individual — not an unattended device or delegated user — authorized the action. That decision is then carried to the relevant AI authorization controls using the standardized FIDO-certified, phishing-resistant cryptography behind Passkey:YOU.
Game-Changing Economics
Hardware tokens typically cost
"FIDO gave the world a trustworthy, interoperable way to kill the password. Full Certification means Passkey:YOU now speaks that language as a certified FIDO authenticator," said Jim Sullivan, Chief Legal Officer of BIO-key. "A roving user can tap the badge they already carry or touch a shared fingerprint scanner and authenticate to Entra ID, Okta, Ping, Duo, or any website that accepts FIDO passkeys. Mobile users can do the same from MobileAuth on iOS and Android. Security teams can see, approve, and revoke the relying parties behind those passkeys—something they can’t do with an unmoderated hardware security key in the hands of a user."
"Agentic AI will force a simple question: who approved that action?" Sullivan added. "A security key left in the machine is not an answer. BIO-key Passkey:YOU proves which person was actually present to approve the action."
Learn more about Passkey:YOU, MobileAuth, and Identity-Bound Biometrics at www.bio-key.com.
About the FIDO Alliance (www.fidoalliance.org)
The FIDO Alliance enables identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. The Alliance publishes open technical specifications, certifies secure and interoperable products, and operates global market enablement programs that have made passkeys the leading standard for phishing-resistant, passwordless authentication. FIDO Certified and the FIDO Certified logo are trademarks of the FIDO Alliance.
About BIO-key International, Inc. (www.BIO-key.com)
BIO-key is revolutionizing authentication and cybersecurity with biometric-centric, multi-factor identity and access management (IAM) software securing access for over forty million users. BIO-key allows customers to choose the right authentication factors for diverse use cases, including phoneless, tokenless, and passwordless biometric options. Its cloud-hosted or on-premise PortalGuard IAM solution provides cost-effective, easy-to-deploy, convenient, and secure access to computers, information, applications, and high-value transactions.
Forward-Looking Statements
All statements contained in this press release other than statements of historical facts are forward-looking statements as defined in the Private Securities Litigation Reform Act of 1995. Words such as “estimate,” “project,” “intends,” “expects,” “anticipates,” “believes” and similar expressions identify forward-looking statements. Such statements are based on management’s beliefs and assumptions and information currently available to management. They are not guarantees of future performance and are subject to risks and uncertainties that may cause actual results to differ materially, including those described under “Risk Factors” in BIO-key’s filings with the Securities and Exchange Commission. Readers should not place undue reliance on these statements, which speak only as of the date made. Except as required by law, BIO-key undertakes no obligation to update forward-looking statements.
Engage with BIO-key
| Facebook – Corporate: | https://www.facebook.com/BIOkeyInternational/ |
| LinkedIn – Corporate: | https://www.linkedin.com/company/bio-key-international |
| X – Corporate: | @BIOkeyIntl |
| X – Investors: | @BIO_keyIR |
| StockTwits: | BIO_keyIR |
Media and Investor Contacts
William Jones, David Collins
Catalyst IR
BKYI@catalyst-ir.com or 212-924-9800 x3
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.
What technical level of FIDO certification did Passkey:YOU achieve?
Passkey:YOU received the FIDO Alliance’s Full Certification, meeting Security Assurance Level L1 and conforming to the FIDO2 CTAP v2.0 specification as a standards-based authenticator.
How does Passkey:YOU help organizations without relying on employee smartphones or personal tokens?
Passkey:YOU places authentication hardware at shared workstations and access points. Employees authenticate by touching a shared fingerprint scanner or tapping an existing door badge, and roving or device-restricted workers can use the same shared client instead of individual phones or tokens.
How does Passkey:YOU address governance and compliance for enterprise authentication?
Because Passkey:YOU is centrally managed, security and compliance teams can see which systems employees authenticate to, approve new destinations, and revoke access to specific systems without collecting a physical key back, while still presenting a standard FIDO-certified interface to passkey-enabled services.
In what way is Passkey:YOU positioned for agentic AI controls?
The company states that Passkey:YOU ties approvals for AI agent actions to a specific person’s biometric (fingerprint, face, or palm) instead of an unattended device or shared credential, and then carries that decision through FIDO-certified, phishing-resistant cryptography to relevant AI authorization controls.
What security and privacy standards does Passkey:YOU support?
The platform uses encrypted biometric data at what the company describes as military-grade, quantum-resistant levels, supports NIST 800-63 and CMMC authentication requirements, and includes enrollment workflows and user-controlled privacy dashboards designed to comply with GDPR and other privacy laws.
How does Passkey:YOU aim to reduce authentication deployment costs?
The company contrasts traditional hardware tokens, which typically cost $25–$70 each with additional losses and replacements, with Passkey:YOU’s model of placing authentication hardware at shared access points so many employees can use a single client, which is presented as lowering total deployment cost.