Skip to main content Skip to search Skip to navigation
Free shipping within Germany · EU from €14.90

Security Keys



13 Items

Frequently Asked Questions about Security Keys

What is a FIDO2 security key and why would I need one?

A small USB or NFC device that secures your logins with public-key cryptography — as a second factor on top of your password or fully passwordless via passkeys. The private key never leaves the hardware and is cryptographically bound to the real domain of the service: on a phishing site it simply doesn't work. That sets it apart from SMS and app codes, which can be phished — which is why hardware-based FIDO authentication is considered the strongest login protection available.

Which services does the key work with?

Any service that supports FIDO2/WebAuthn or U2F — including Google, Microsoft, Apple, Amazon, PayPal, eBay, GitHub and password managers like Bitwarden and 1Password. Bitcoin exchanges such as Kraken and Coinbase also accept security keys as their strongest 2FA method for account logins. A single key works for any number of accounts at the same time; you register it in each service's security settings. No drivers or extra software needed — current browsers and operating systems support FIDO2 natively.

YubiKey 5, Security Key or YubiKey Bio — what's the difference?

The Security Key series covers FIDO2 and U2F — fully sufficient to protect accounts with 2FA and passkeys. The YubiKey 5 series additionally offers smart card functions (PIV), OpenPGP encryption, stored authenticator codes (OATH-TOTP) and Yubico OTP — relevant for SSH keys, email encryption or Windows login. The YubiKey Bio replaces PIN entry with a fingerprint sensor (up to five prints, the data stays on the key), but like the Security Keys it is a FIDO-only device and has no NFC. In short: securing accounts → Security Key; extra protocols → YubiKey 5; fingerprint convenience at the desk → Bio.

YubiKey or Nitrokey?

Both implement the same FIDO2/U2F standard and work with the same services. Nitrokey from Berlin focuses on fully open-source firmware written in Rust, signed firmware updates and manufacturing in Germany; the Nitrokey 3 series carries an EAL6+ certified secure element. Yubico takes the opposite approach: the firmware is deliberately immutable — permanence as a security philosophy — and its ecosystem is the most widespread on the market. Both are solid concepts; if you value open source and digital sovereignty, pick Nitrokey — if you want maximum adoption, pick YubiKey.

Does the key work with my smartphone?

Yes. The NFC models (YubiKey 5 NFC and 5C NFC, Security Key NFC, Nitrokey 3A NFC and 3C NFC) just need to be held against the back of the phone — that works on Android and iPhone. USB-C models plug straight into the USB-C port of Android devices and current iPhones. Only the Nano models, the Nitrokey 3A Mini, the Nitrokey Passkey and the YubiKey Bio lack NFC — they are designed to stay plugged into your computer.

What happens if I lose my key?

Without preparation you can lose access to accounts — hence the standard recommendation: get two keys, register both with all important accounts and store the second one safely. Apple even requires two registered keys to protect an Apple Account. Additionally, keep the recovery codes your services provide. A finder can do very little with the key alone, by the way: they don't know which accounts it belongs to, and FIDO2 logins are additionally protected by your PIN.

Is a security key a hardware wallet?

No. A security key protects logins and accounts — it stores no seeds and manages no Bitcoin. For self-custody you need a hardware wallet; the security key complements it by protecting the accounts around it: exchange, email, cloud storage and password manager. Your email account in particular is the master key to almost every other service — combining a hardware wallet for your coins with a security key for your accounts covers both attack paths.