Yes, successfully logging in with a passkey will update the user's last login instant.

However, there are edge cases where a passkey can be used without updating the last login timestamp:

Scenarios where passkey use doesn't update last login:

Login flow interrupted — The user authenticates with the passkey, but the login is stopped before completion due to:

Failed MFA challenge User action requirement (e.g., forced password reset) Account lock or suspension Login validation Lambda or transactional webhook rejecting the login

WebAuthn assertion without login — If the user performed a WebAuthn assertion directly via the API, this counts as using the passkey but does not constitute a full login flow and therefore doesn't update the last login instant. The Complete a WebAuthn Passkey Assertion API validates the WebAuthn ceremony but "does not authenticate the user into an application." This is different from the Complete a WebAuthn Passkey Authentication API, which validates the passkey and authenticates the user, thus updating the last login instant.

Summary

A passkey being "used" is not the same as a completed login. The last login timestamp only updates when the authentication flow completes successfully and issues a token.

Related Documentation Complete a WebAuthn Passkey Authentication - The API that validates passkeys and authenticates users (updates last login) Complete a WebAuthn Passkey Assertion - The API that only validates passkeys without authenticating (does not update last login) Authentication With WebAuthn & Passkeys - Complete guide to WebAuthn/passkey authentication in FusionAuth Update Login Instant API - Manual API for updating login instants when implementing custom SSO Setting Up User Account Lockout - How account lockouts can interrupt login flows