0%
John Hurley
Book Intro

Case Study

Applying B = MAP

Passkey adoption stalled despite being "easy." Shifting to motivation-driven messaging drove a 30% lift and 6M enrollments.

Role

Product Design Engineer & User Researcher

Timeframe

2021 – 2025

passkeys created

+6M

CVS passkey sign-in and enrollment screens, from Face ID prompt to redesigned "Tired of resetting your password?" promo

A passkey sign-in prompt tested "easy" in usability testing and still went mostly ignored. The fix wasn't a better button — it was recognizing that ease was never the problem. Applying B.J. Fogg's Behavior Model to the content strategy drove a 30% lift in adoption and, six months later, +6M passkeys created across CVS.

Password recall was CVS's number one cause of digital sign-in errors — roughly three-quarters of all sign-in errors and about a third of customer support comments, by Adobe Analytics and Medallia's own measurement. Underneath that was a second, quieter cost: three separate CVS business units — Retail, Pharmacy (Caremark and Specialty), and Aetna — each maintained their own authentication codebase, tripling the engineering cost of every future sign-in change.

I led design and research for CVS's passkey (passwordless) sign-in end to end: facilitating the technology-evaluation workshop that selected passkeys over magic links, OTP, MFA, and SSO; designing and shipping the MVP; and then, once adoption stalled, running the research phase that diagnosed why and rebuilt the content strategy around it.

01When "easy" isn't the problem

The MVP tested well and still underperformed — because ease of use was never what was missing.

The MVP passkey prompt shipped after a perception-and-comprehension usability test that rated it easy to use. But post-launch, rejection rates ran 83% on CVS.com, and 70% of CVS Specialty users stayed on email and password rather than switch. Two lines of business, two different entry points into the same idea — neither one giving users a reason to care.

Original CVS.com Go Passwordless prompt beside the CVS Specialty sign-in without a password prompt
Original CVS.com Go Passwordless prompt beside the CVS Specialty sign-in without a password prompt
Before the rewrite: CVS.com's "Go Passwordless" and CVS Specialty's "Sign in without a password" — different lines of business, different messaging, neither naming a reason to switch.

The diagnosis came from B.J. Fogg's Behavior Model, B=MAP: a behavior only happens when Motivation, Ability, and a Prompt converge at the same moment. The MVP had solved Ability — biometric sign-in is objectively less effortful than typing a password — but the heading, "Go Passwordless," named the mechanism, not a reason to want it. Comprehension testing confirmed users were left with only a partial mental model of what a passkey even was. Ability without Motivation doesn't move behavior; B=MAP predicts exactly this failure mode.

02Rewriting for Motivation, Ability, and Prompt

Three separate levers, three separate fixes — validated individually before they were validated together.

Motivation

"Go Passwordless" became "Tired of resetting your password?" — reframed around the pain users already feel and the fear it'll happen again, in their own words from comprehension testing rather than internal terminology.

Ability

One dense, feature-first paragraph became three scannable cards — Simple, Secure, Private — each an icon plus one plain-language sentence, reducing working memory load to parse.

Prompt

The prompt moved from a generic sign-in screen to firing during password reset — when the user was already re-authenticating via one-time passcode, satisfying security review while reaching peak motivation.

Redesigned CVS passkey content with a pain-point heading and Simple, Secure, and Private benefit cards
Redesigned CVS passkey content with a pain-point heading and Simple, Secure, and Private benefit cards
The rewritten content: a pain-point heading (Motivation) paired with scannable, icon-led benefit cards (Ability).

The Prompt change carried its own constraint: security review required the passkey offer to appear only once identity was already verified, not before. Sequencing it into the password-reset flow — after the one-time passcode step, before the new password screen — satisfied that requirement while putting the offer in front of someone at the exact moment they were most motivated to never do this again.

Flow diagram showing the passkey prompt after one-time passcode verification in the password-reset flow
Flow diagram showing the passkey prompt after one-time passcode verification in the password-reset flow
The redesigned trigger logic: the passkey prompt now fires inside the password-reset flow, immediately after the user re-authenticates.

03Proving it before shipping it

An 80-participant, between-subjects usability study, run before the redesign ever reached production.

Rather than ship on conviction, I validated the rewritten content against the original in an unmoderated, between-subjects study: 80 participants split into two groups of 40, recruited via UserTesting.com to matching criteria — signed into CVS.com in the past 30 days, reset a CVS.com password in the past 30 days, iPhone users. One group saw the existing content, the other saw the redesign; both were given the same task: "You don't remember your password. Using this website, find another way to access your account."

Self-reported measureExistingRedesign
Ease of use3.4 / 54.8 / 5
Trust ("passkeys are more secure than passwords")3.0 / 54.4 / 5
Likelihood to recommend3.8 / 54.8 / 5

A separate four-item comprehension battery — whether participants believed they could use a passkey across devices, whether they'd still need a password afterward, whether passkeys were more secure — showed the same pattern, every difference statistically significant at p < .01 or better.

Charts comparing comprehension and perception scores for existing and redesigned passkey content
Charts comparing comprehension and perception scores for existing and redesigned passkey content
Comprehension and perception scores, existing vs. redesigned content — every comparison significant at p < .01 or better.

04What shipped, what it did

+30%lift in passkey adoption post-redesign
+6Mpasskeys created across CVS
-66.96%drop in password-triggered sign-in errors
3 → 1sign-in implementations consolidated to one shared pattern

Six months after rollout: password reset traffic down 18%, password-related support comments down 10%, password-triggered sign-in errors down 66.96%, and locked accounts down 27.18%. Sign-in success rates improved on both properties — CVS.com from 82.17% to 93.31% (+11.14 points), CVS Specialty from 85.6% to 93.57% (+7.97 points) — and the original problem-statement metric, the share of traffic navigating to password reset after a failed attempt, fell from 6% to 3%.

The pattern this research produced didn't stay a CVS.com fix. It scaled to all three lines of business it was originally built to unify — CVS.com, Caremark, and Specialty Pharmacy — replacing what had been three separately maintained sign-in implementations with one shared approach, and cutting the engineering cost of every future authentication change from three updates to one.

This is the shape of it. The full case study goes deeper into the original technology evaluation (why passkeys beat magic links, OTP, MFA, and SSO), the accessibility and inclusive-language work baked into the MVP, and the developer handoff behind the shipped redesign — happy to walk through it in detail.