logo
|
Blog
    BotManagerBusiness Insight

    Will Passkeys Eliminate Bots and Macros?

    Passkeys strengthen authentication, but bots can still act after login. Learn why bot detection remains essential for secure digital services.
    Daniel(원재인)'s avatar
    Daniel(원재인)
    Sep 30, 2026
    Will Passkeys Eliminate Bots and Macros?
    Contents
    Will Passkeys Eliminate Bots and Macros?Malicious Bots Can Still Operate Inside Authenticated SessionsBuilding a Modern Security ArchitectureClose the Security Gap with BotManager

    Will Passkeys Eliminate Bots and Macros?

    Passkey adoption has rapidly expanded, led by major technology companies such as Google and Apple.

    A passkey is a next-generation authentication method that enables users to log in without a password. Instead of entering a complex password, users can authenticate to a website or application using methods already available on their smartphone or computer, such as fingerprint recognition, facial recognition, or a device unlock method.

    When a passkey is created, a private key is stored on the user's device, while a corresponding public key is registered with the service.

    Because passwords themselves are not stored on the server or transmitted over the network during authentication, passkeys significantly reduce the risks associated with password theft. Password-based attacks such as credential stuffing, which uses stolen credentials to attempt unauthorized access, and brute-force attacks also become far less effective.

    However, passkeys do not mean complete security.

    Bots and macros do not disappear simply because passkeys are introduced.
    Bots and macros do not disappear simply because passkeys are introduced.

    Malicious Bots Can Still Operate Inside Authenticated Sessions

    Passkeys can verify possession of a trusted device, but they cannot determine whether the entity moving the mouse and clicking buttons is a real person or an automated script.

    Modern bots can behave like real users through automated browsers, scripts, and APIs.

    Even after successfully completing authentication, automated bots can operate in several ways:

    • Intentional abuse: Resellers can log in normally and then activate preconfigured automation scripts or bot programs to secure high-demand tickets or limited products before legitimate users.

    • Automated browsers (Headless Browsers): Modern bots often run on browser automation tools such as Selenium or Puppeteer. Once authentication is completed and a valid session is established, automation can control the browser and perform actions at machine speed.

    • Session hijacking: Malware on a device can steal session cookies that serve as proof of a successfully authenticated login.

    • Direct API attacks: Instead of accessing a service through a web browser, attackers can use valid authentication tokens to send large volumes of requests directly to server APIs.

    As a result, even when authentication itself is legitimate, bots and macros operating inside authenticated sessions can still cause problems such as web scraping, inventory hoarding, unfair purchasing advantages, server overload, and increased infrastructure costs.

    Building a Modern Security Architecture

    Building a secure digital service requires more than strong authentication such as passkeys. Organizations also need behavioral analysis and bot detection capabilities within the actual service environment.

    CAPTCHA can provide an additional layer of defense, but increasingly sophisticated AI-powered bots can bypass these challenges, while CAPTCHA itself can introduce friction into the user experience.

    This is where a more advanced bot and macro management solution such as BotManager becomes necessary.

    BotManager analyzes incoming traffic in real time at the identifier level. It detects malicious bots hidden within legitimate user traffic that can undermine fairness and distort business data, and then controls them according to configured policies.

    By filtering unwanted automated traffic, organizations can obtain cleaner traffic data that better reflects real user activity while providing fairer access to legitimate users.

    Blocking malicious bot traffic also helps prevent unnecessary server load, reduce the risk of service disruption, and optimize infrastructure operating costs.

    BotManager also provides AI Scoring, which uses AI-powered analysis to assess risk at the identifier level and recommend appropriate actions based on the detected traffic patterns.

    Close the Security Gap with BotManager

    Passkeys can verify who is logging in, but they do not tell you how that authenticated session behaves.

    They cannot determine on their own whether the activity comes from a real person or an automated bot.

    If passkeys answer the question:

    “Who is logging in?” — Identity

    BotManager addresses another critical question:

    “Is this behavior legitimate?” — Intent

    By strengthening identity authentication with passkeys and adding behavioral and intent-based traffic analysis with BotManager, organizations can build an additional layer of protection against automated threats.

    Protect your service from malicious bots and macros without adding unnecessary friction for legitimate users, and create a more secure and reliable digital experience.

    Reference
    Passkeys vs Bots: Do They Really Solve the Human Verification Problem?
    Security Boulevard

    Explore BotManager →
    Share article
    Contents
    Will Passkeys Eliminate Bots and Macros?Malicious Bots Can Still Operate Inside Authenticated SessionsBuilding a Modern Security ArchitectureClose the Security Gap with BotManager

    STCLab Inc.

    RSS·Powered by Inblog