Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Mercari's 13 Million Passkey Accounts: What Financial Services Can LearnFIDO & Passkeys
4 min readFor IAM Architects

Mercari's 13 Million Passkey Accounts: What Financial Services Can Learn

The Challenge

In 2025, Japan's financial sector was hit by a wave of phishing attacks targeting securities firms. The Financial Services Agency (FSA) responded with guidelines mandating phishing-resistant authentication. Financial institutions had to quickly move away from SMS One-Time Passwords and outdated multi-factor methods. But adopting enterprise passkeys isn't just about changing technology; it's about rethinking identity lifecycle management.

Mercari had already rolled out passkeys to about 13 million accounts on its C2C marketplace platform, achieving a higher sign-in success rate than traditional SMS OTPs. However, when RSA and Mercari representatives met with FIDO Alliance board members in Tokyo on July 22nd, the focus was on a tougher question: why can't enterprises replicate this success?

The Environment and Constraints

Mercari operates in a consumer environment where user convenience is key, and device diversity is expected. Users authenticate from personal devices they control, assuming individual accountability.

Financial institutions face different challenges:

  • Regulatory mandates: The FSA guidelines require phishing resistance with supervisory oversight.
  • Managed vs. unmanaged devices: Employees use corporate laptops, BYOD phones, and sometimes shared workstations.
  • Credential lifecycle complexity: Onboarding, offboarding, device loss, and account recovery need strict policy enforcement.
  • Third-party sync exposure: Cloud-synced passkeys that work for consumers can create control gaps when corporate credentials sync to unauthorized devices.

The Tokyo discussion highlighted a specific technical need: enterprises require granular policy controls to enforce device-bound keys, ensuring authentication stays within the managed corporate perimeter. Consumer passkey systems usually don't offer this level of policy differentiation.

The Approach Taken

The discussion focused on three technical areas where enterprise needs differ from consumer patterns:

Policy-driven credential binding: Enterprises need to designate roles or applications that require device-bound credentials, ensuring the private key stays on a managed device's hardware security module.

Identity lifecycle hardening: Mercari's CISO Naohisa Ichihara and RSA's Field CTO Ingo Schubert stressed that phishing-resistant authentication alone doesn't stop social engineering attacks. The transition to passkeys should rebuild identity workflows, secure employee verification during onboarding, automated but secure account recovery, and binding authenticators to verified devices.

AI agent authentication boundaries: As organizations deploy AI agents, a new trust boundary emerges. How should an AI agent authenticate? Does it inherit the user's passkey or get its own cryptographic identity? The discussion explored whether FIDO2 credential structures can extend to non-human entities or if a new framework is needed.

Results and Metrics

Mercari's deployment to 13 million accounts showed that large-scale passkey adoption is viable. The higher sign-in success rate compared to SMS OTPs confirms the user experience improvement.

For financial institutions under FSA pressure, the key metric isn't just adoption rate, it's how quickly you can transition to phishing-resistant authentication while maintaining audit trails and policy enforcement. The Tokyo dialogue didn't provide a single solution but highlighted the architectural gaps needing standardization.

What They'd Do Differently

The conversation revealed three areas where early enterprise adopters are adjusting:

Don't treat passkeys as a drop-in MFA replacement: If you deploy passkeys but keep legacy recovery flows (security questions, SMS resets), you haven't eliminated the phishing risk. Attackers will exploit the weakest recovery path.

Separate consumer sync from enterprise sync: Using consumer-grade credential sync services for corporate identities leads to unmanaged sprawl. Device-bound keys for high-privilege roles should be policy-enforced, not user-optional.

Plan for non-human identities now: AI agents and automated workflows don't fit neatly into human-centric authentication models. Addressing this post-deployment creates technical debt.

Takeaways for Your Team

If you're planning passkey deployment for a regulated enterprise, consider these principles:

Map your personas to binding policies: Not every user needs the same credential model. Contractors on BYOD devices might use synced passkeys, while privileged administrators should use device-bound keys tied to corporate hardware.

Audit your recovery workflows: Identify every path for account reset or credential re-issuance. If any path lacks cryptographic proof or out-of-band verification, it's a social engineering risk.

Instrument your identity lifecycle: Track credential issuance, device binding, sync events, and recovery attempts. If an attacker bypasses your phishing-resistant authentication, it'll be through a lifecycle management gap, and you'll need logs to investigate.

Engage with FIDO working groups: The enterprise needs discussed in Tokyo, policy-driven binding, lifecycle hardening, AI agent authentication, aren't fully standardized yet. Your input can shape future versions of FIDO2 or WebAuthn to address these gaps.

Mercari's 13 million passkey accounts prove the technology works. The FSA's regulatory pressure confirms the mandate is real. The challenge is adapting consumer-proven cryptography to enterprise identity governance. This isn't just a vendor or standards issue, it's an architecture problem your team needs to solve.

Promotional banner for the Penetration Report Template Kit

You Might Also Like