Skip to main content

CIS2 passkey app

A new secure way to authenticate without a smartcard.

The CIS2 AAL3 passkey app is currently for Android only. The AAL3 passkey app for iOS devices is currently in development - read about our AAL3 passkey private beta for iOS.

For synced passkeys not bound to a device, go here.


The CIS2 passkey app offers an AAL3 device-bound passkey with the same cryptographic security benefits of a smartcard.

The passkey is bound to a single device and cannot be cloned or extracted.

Benefits
  • Strong cryptographic secure device-bound passkey
  • Simple and convenient
  • No new technology - you just need the app
  • Replacement for the iPad app or a smartcard on mobile devices

What you'll need

You'll need:

  • Android version 15 (some Android 14 devices may also work)
  • a device with a fingerprint reader (some devices with secure or 3D facial recognition may also work)

How to register a passkey on an Android device

Installing the app

Make sure you've registered for the beta with the Care Identity team. You'll have received a link to download the app, which is not currently available in the public store.

Opening the app for the first time will trigger the setup journey. You'll first need to enable autofill to allow the app to manage passkeys on your device.

CIM register CIS2 Auth passkey Android enable autofill

 

Note: if this does not appear, you’ll need to navigate to the system settings manually to enable autofill.

You should then enable the CIS2 Auth Credential Provider app by toggling the setting on.

CIM register CIS2 Auth passkey Android enable app in preferred services

 

Note: if the list of 'Additional services' does not show the app, you may click the preferred service and select it, before restoring the original preference.

Once you've enable the app in the settings, press the back button to return and you'll be asked to accept the app's terms and conditions. You must select 'Accept' to proceed.

CIM register CIS2 Auth passkey terms and conditions

 

You'll then see the app's main screen, with no passkeys shown.

CIM register CIS2 Auth passkey Android app home screen no passkey shown

 

Registering the passkey

This guidance explains how a Registration Authority user can register the passkey on another user's Care ID. To register the passkey on your own profile as a non-Registration Authority user, follow the guidance on how to self-register the CIS2 Authentication passkey app.

You'll need to set up a meeting with your user, either via video or face-to-face. The passkey registration must be completed in your presence.

They will need to have Bluetooth enabled on their device.

From the Care Identity Management home page, choose 'Find an existing user'.

CIM home page find an existing user highlighted

 

Enter the user's details and select 'Search'.

Care Identity Management find an existing user

 

Choose 'View profile' on the right of the screen.

Care Identity Management user found

 

Go to the 'Authenticators' tab on the user's profile page and select 'Issue other authenticator'.

Shows a list of authenticators, with a button highlighted to Issue other authenticator

 

On the 'Select authenticator type' screen, select 'CIS2 Auth Passkey App (Android)' and 'Continue'.

Note: if the option does not appear, it's likely that the user already has the CIS2 Authentication Android passkey registered to their Care ID.

CIM register CIS2 Auth passkey select type Android highlighted

 

You'll now see a screen with instructions on how to register the passkey.

CIM register CIS2 Auth passkey Android instructions and register button

 

When you've read the instructions and are both ready to proceed, select 'Generate link'.

CIM 7.17 create a passkey link generated

 

Copy the link and send it to the user by email, or paste it into the chat function of the video call software you are using.

When the user opens the link on their Android device, they'll be asked to confirm that they want to save the passkey.

Important:

  • if the app clearly mentions the 'NHSE Passkey App', the user should select 'Continue'.

CIM register CIS2 Auth passkey create passkey central message highlighted

 

  • If the app does not mention the NHSE Passkey App, the user should select 'Save another way'.

CIM register CIS2 Auth passkey save another way highlighted

 

  • And then select CIS2 Auth on the next screen.

CIM register CIS2 Auth passkey Android app create passkey save passkey to CIS2 highlighted

 

Depending on your device settings you may now need to confirm your biometrics.

CIM register CIS2 Auth passkey enable biometrics

 

You should then see a confirmation screen.

CIM register passkey type 3 step 4

 


How to check the device is registered

When the device has been registered you should be able to see it listed as active on the user's profile page in Care Identity Management.

CIM register CIS2 Auth passkey authenticators tab both versions active and highlighted

The user will also see the passkey listed in the app on their device.

CIM register CIS2 Auth passkey Android passkey shown in app


How to authenticate

Once the device is registered, to authenticate the user should navigate to the service they're looking to access, and from the list of login methods select 'Windows Hello'.

AAL3 passkey Android registration step 5

 

The user will then be prompted to either select a device, or if opened on your mobile device presented with a list of passkeys. They should choose the passkey listed as 'CIS2 Auth Credential Provider'.

AAL3 passkey Android registration step 8

 

They can then authenticate using their chosen method of fingerprint or PIN.

AAL3 passkey Android registration step 9

Last edited: 5 October 2026 9:42 am