FreeThe +45-page Authentication Analytics Whitepaper — measuring real login journeysDownload

Corbado Observe · Field notes from the FIDO event in Bengaluru

Five blockers your server logs never show

Two of India's largest apps shipped passkeys in weeks. Every problem that followed happened where their logs could not see.

  • Classified by cause

  • Cancel vs timeout

  • Read-only on your IdP

61%

adoption, repeat users

7x

faster than mobile OTP

5 of 5

invisible to backend logs

MakeMyTrip and PhonePe, reported at the FIDO Alliance India Working Group, 7 August 2026. The 61% was measured outside India.

Field notes · Bengaluru

Five blockers, and where each one shows up

Every one of these reproduces on any large Android fleet, in any market.

No PIN or biometric means there is nothing to build a passkey on. These users never reach the prompt, so they are readiness, not error.

Passkey Errors

Why nobody caught these earlier

Six telemetry layers, one blind spot

Six telemetry layers between them, and the ceremony happens in none of them. Full context in our passkeys in India overview.

Your logs stop at the API

It sees the ceremonies that reach it, never the ones that did not start.

The ceremony runs on the device

Prompt, cancel, manager, device. All of it past your last log line.

One error covers a dozen causes

NotAllowedError covers a cancel, a timeout and a platform reject alike.

Passkey failure FAQ

What teams ask once passkeys are live

Find out which of the five is yours

Classify your passkey failures on real traffic, find the platform pattern behind them and replay any user when a ticket comes in.

  • Every failure mapped to a journey stage
  • Cancel, timeout and system reject told apart
  • Read-only on top of your existing IdP