Banking News

Read the full story

Source: The Hindu BusinessLine

The Hindu BusinessLine
Source
NPCI & Payments
Category
2 min
Read time
11 Sept
Published
NPCI & Payments
2 min read· The Hindu BusinessLine

Zeta, Pluxee launch passkey authentication for RuPay card payments

A new biometric payment system is replacing SMS codes for RuPay cards to stop digital fraud. This technology helps bankers complete transactions faster while keeping customer money much safer than before.

Banking tech firm Zeta and employee benefits company Pluxee have launched a new passkey authentication system for RuPay prepaid cards. Announced in Mumbai on September 11, 2026, this system replaces traditional SMS One-Time Passwords (OTPs) with cryptographic credentials (secure digital keys) stored directly on the user's device. This move was made possible through the National Payments Corporation of India (NPCI) network to make digital payments safer and faster for every Indian user.

The new process is very simple for cardholders. During their first checkout, customers register a passkey once using a single OTP. After that, they do not need to wait for any SMS. They can approve payments using biometrics, such as a fingerprint or facial recognition, or by using their device PIN. This shift removes the common headache of waiting for network signals to receive an OTP, which often leads to payment failures at the counter or online.

The speed difference is significant for daily banking operations. Zeta reports that passkey authentication takes only 5 to 7 seconds to finish. In contrast, the old SMS OTP method usually takes 15 to 25 seconds. Additionally, the registration success rate has reached nearly 99 percent. For bank officers, this means fewer complaints about 'OTP not received' and fewer abandoned transactions (when a customer stops a payment because it takes too long).

This launch is a direct response to the massive increase in digital fraud in India. Statistics show that digital payment fraud crossed ₹21,367 crore in FY2025. This is more than five times the amount stolen in the previous year. Because passkeys are 'device-bound' (linked to a specific phone or laptop), they cannot be phished or intercepted by hackers in the same way an SMS can be read or stolen.

The timing also aligns with new rules from the Reserve Bank of India (RBI). As of April 1, 2026, the RBI has mandated a two-factor authentication (2FA) policy that encourages banks to move beyond SMS OTPs. The regulator wants banks to use dynamic, device-bound methods to protect customers. Passkeys satisfy this rule perfectly while making the user experience much smoother than traditional methods.

For merchants and business correspondents, this technology is a major win. Fewer steps at the checkout page mean fewer 'drop-offs' (when a customer gives up on a purchase). Zeta has confirmed it is currently working with more RuPay card issuers to bring this technology to a larger number of cardholders across India soon. Bankers should expect more card types, including debit and credit cards, to follow this trend as the industry moves away from SMS-based security.

#UPI
Source: The Hindu BusinessLine