FreeThe +45-page Authentication Analytics Whitepaper — measuring real login journeysDownload
Back to Overview

ABN AMRO & Rabobank: FIDO2 Security Keys

ABN AMRO is replacing its card reader with a USB security key. Rabobank's terms provide for physical passkeys. What this means for European banks.

Vincent Delitz
Vincent Delitz

Created: September 15, 2026

Updated: September 15, 2026

ABN AMRO & Rabobank: FIDO2 Security Keys
Key Facts
  • ABN AMRO: e.dentifier users are invited to choose the app or a USB security key between June and December 2026. The first key costs €10.
  • Rabobank: its November 2026 payment terms provide for physical passkeys to approve browser payments. The clause does not set a launch date.
  • For European banks: hardware keys offer a phishing-resistant, standard FIDO option for customers who need an alternative to the banking app.

1. Introduction#

ABN AMRO and Rabobank are bringing physical FIDO credentials into European retail banking. The initial scope is limited, but the direction matters: established banks are considering phishing-resistant authentication for customers who previously relied on proprietary readers.

Corbado's view: these moves could encourage other European banks to evaluate passkeys when replacing legacy authentication. ABN AMRO provides a concrete migration example; Rabobank adds a contractual basis for physical passkeys. Neither establishes a broad rollout of synced passkeys.

2. ABN AMRO: a replacement for the e.dentifier#

In its 15 June 2026 announcement, ABN AMRO said consumer clients using the e.dentifier would receive invitations between June and December 2026 to choose the bank's app or a USB security key. The key is intended for people who cannot or do not want to use a smartphone. Both options cover login and transaction approval.

According to the bank's security key help page, the first key costs €10; additional or replacement keys cost €25 each. Customers must wait for a personal invitation before ordering. Registration uses the existing e.dentifier, and the key is personal: joint account holders each need their own.

The bank describes the device as a standard FIDO key. Customers use it with an email address and PIN, then touch the key to authenticate. An adapter supports USB-A and USB-C connections. The key can be used across compatible computers; it is not tied to one laptop.

The migration includes personal support from 200 banking advisers and more than 530 SeniorWeb locations. ABN AMRO MeesPierson and business clients are outside the initial phase and are scheduled to follow from mid-2027. Those details matter for other banks planning a similar change: distributing hardware is only one part of the work.

3. Rabobank: physical passkeys in the payment terms#

Rabobank's 2026 payment terms, effective 1 November 2026, list a registered physical passkey and its passkeycode as a way to sign payment orders through Rabo Online Bankieren in a browser.

Article 28 gives a USB key as the example and explicitly excludes smartphones from this particular method. The provision applies to both registered and unregistered browsers, alongside existing approval methods.

The clause includes “as soon as we offer it.” It therefore provides a contractual basis for the method, not a launch date. It does not specify pricing, accepted key models or recovery procedures.

The same article also permits online payments with a Mastercard or Visa Payment Passkey, subject to agreement with the bank. That provision has no equivalent availability qualifier. It does not explain whether those credentials are synced or device-bound.

Rabobank is therefore covering two use cases in the same document: physical keys for browser banking and network payment passkeys for online card payments. Their implementation and availability need to be assessed separately.

4. What this means for European banks#

PSD2 compliance has shaped the starting point. The EU's strong customer authentication requirements took effect in September 2019. Banks have already invested in authentication to meet those requirements. PSD2 does not prescribe passkeys, so compliance alone does not create a reason to replace an existing method with FIDO2.

Our assessment is that this existing investment helps explain why a European bank may approach passkeys as a migration decision rather than a first move to stronger authentication. ABN AMRO makes that decision concrete: it is replacing a reader with a standard FIDO device. FIDO2's binding to the legitimate service adds phishing resistance to the authentication flow. Synced passkeys raise a further question: whether a regulator in a given EU country accepts them as compliant is still open to debate, which makes a device-bound key the less contested choice for a first step.

Hardware keys offer a starting point for customers without smartphones. A bank could support FIDO2-capable YubiKeys or comparable devices for customers who previously inserted a bank card into a reader and copied a code. The bank would need to define supported models, enrollment and replacement procedures. This is an implementation option, not confirmation that either bank accepts a particular YubiKey. Our FIDO2 hardware security key overview compares available devices.

A limited rollout can inform a wider passkey programme. Starting with legacy-reader users gives banks experience with registration, support and customer behaviour before deciding whether to extend passkeys to other groups. Hardware keys and synced passkeys differ in portability, provider dependence and recovery; our device-bound vs. synced passkeys comparison explains those choices.

We expect other banks to examine these deployments when their own readers need replacing. That is the potential wider effect: practical migration experience can give the next bank a stronger basis for adopting FIDO2.

5. How Corbado can help#

Banks replacing a card reader need to know whether customers can complete the new flow. Corbado Observe measures authentication on the existing login stack, helping teams find failures and abandonment during a migration.

See Login Funnel in Corbado Observe →
  • Follow the login flow: use the login funnel to see where users stop before completing authentication.
  • Identify platform issues: compare errors by browser and OS in Passkey Errors.
  • Understand registered credentials: use Authenticator Inventory to see which authenticators customers have registered.

Book a demo to see how Observe can support your authentication migration.

6. Conclusion#

ABN AMRO's migration and Rabobank's payment terms give European banks concrete examples of how physical FIDO credentials can fit retail banking. Their wider significance will depend on execution: whether customers can register, use and replace the keys successfully. If that works, these limited deployments could help make passkeys a credible option for the next legacy-system replacement.

Next Step: Ready to implement passkeys at your bank? Our +90-page Banking Passkeys Report is available.

Get the Report

Share this article


LinkedInTwitterFacebook