HealthEquity has moved to passkey-only authentication and now permits exactly one financial data aggregator: Plaid. HealthEquity support has confirmed this in writing to multiple users: "Due to our recent security upgrade to passkey authentication, HealthEquity does not support connections with financial data aggregators."
The result is FDP-108 for every affected member. Alert CTP-16362 has been open since 2/20/26 with no ETA after five months, and there is no action a member can take on HealthEquity's website to resolve it because the setting does not exist. Current guidance is to track the accounts manually.
This is not a HealthEquity-specific bug. Passkeys are phishing-resistant by design, which means credential-replay aggregation stops working the moment an institution adopts them. Every institution that turns on passkeys will break the same way. The industry answer is delegated authorization (FDX / OAuth 2.0), where the member authorizes the aggregator at the institution and no credential is ever shared.
Request: add Plaid as an additional connectivity provider, at minimum as a fallback for institutions that have designated Plaid as their permitted aggregator.
Scale in my case: an HSA, an HSA investment account, two FSAs, two commuter cards, and a reimbursement account. Seven accounts, all with current activity, all stale since 5/31/2025.
Related and worth noting: members migrated through the WageWorks acquisition are hit twice. The legacy WageWorks connector fails with FDP-192 (unsupported MFA method) and the HealthEquity replacement fails with FDP-108. That group has no working path at all.