What Is a Hardware Security Key?

Also called: Security key, Physical security key

Related problems: Need phishing-resistant MFA for admins and executives; Staff on shared or kiosk computers can't use phone-based MFA; Not sure which keys to buy or how many spares we need; Worried about users losing keys and getting locked out

A hardware security key is a small physical device, usually plugged into a USB port or tapped against a phone over NFC, that proves who a user is when they sign in. It holds private cryptographic keys that are designed not to leave the device and signs a challenge from the service after the user touches it, and often enters a PIN or fingerprint. Most current keys implement the FIDO2 and older U2F standards. The best-known product line is Yubico’s YubiKey, and several other manufacturers make comparable keys, so if you’ve been told to buy a YubiKey, this is the product category.

At a glance

  • A physical authenticator that connects by USB-A or USB-C, NFC and, less commonly, Bluetooth or Lightning.
  • Uses FIDO2/U2F public-key credentials bound to each site, a common way to meet phishing-resistant MFA requirements.
  • Some models also act as a smart card for certificate-based sign-in, or generate one-time passwords (OTP).
  • FIDO2 keys can store device-bound passkeys for passwordless sign-in, protected by a PIN or built-in fingerprint reader.
  • Plan for two keys per user, enrollment, lost-key handling and recovery.

What problem it solves

Codes sent by SMS, codes from apps and push approvals can all be relayed by a fake login page or approved by a user worn down by prompts. A security key signs only for the genuine site, so a look-alike domain gets nothing reusable, and the private key is designed not to be copied off the device.

Keys also solve a practical problem: they don’t need a phone. That matters for staff who can’t use personal phones for work, people on shared terminals or kiosks, secure areas where phones aren’t allowed, and administrators who shouldn’t depend on a device that is also used for personal apps.

How it works

FIDO2 and U2F. When a user registers a key with a service, the key creates a new key pair for that service and returns the public key. At sign-in, the browser passes the service’s challenge and the real domain to the key over USB, NFC or Bluetooth, the user touches the key, and the key signs. FIDO2 keys can also check a PIN or fingerprint (user verification) and store discoverable credentials for passwordless sign-in. U2F-only keys act as a second factor after a password.

Smart card and certificates. Many multi-protocol keys can hold certificates, acting like a smart card for Windows sign-in, VPNs or document signing under your public key infrastructure (PKI).

One-time passwords. Some keys can generate HOTP or TOTP codes, usually with a companion app, for systems that only accept codes. These codes are not phishing-resistant.

Attestation and model control. At registration, a FIDO key may return attestation data. An identity provider that validates it against trusted vendor or FIDO Alliance metadata can identify the model and accept only approved ones, such as FIPS-validated keys where a contract or regulation calls for them.

Enrollment. Keys are registered to a user through the identity provider, either by the user after signing in or by IT before the key is handed out. Some identity providers and vendors offer pre-enrolled or supplier-managed programs.

When it matters for buyers

  • For administrators, executives and finance staff. These accounts are the most targeted; keys are a common requirement.
  • At cyber insurance renewal. Insurers that ask about phishing-resistant MFA often treat FIDO2 keys as qualifying. Requirements vary by insurer.
  • For shared, kiosk or phone-free environments. Keys work where phone-based MFA doesn’t.
  • When budgeting. Count keys per user, spares, replacements, shipping to remote staff and support time.
  • When planning recovery. A lost key should be revoked fast, and re-enrollment should require strong identity checks, or attackers will target the help desk instead.
  • When checking compatibility. Confirm connector types for laptops and phones, and which applications, VPNs and desktop logins support keys directly.

Questions to ask vendors

  • Which key models do you support or certify, and do you support FIDO2 with user verification or only U2F?
  • Can we restrict accepted keys by model using attestation?
  • Can keys be pre-enrolled or managed centrally, and how are they shipped to remote staff?
  • How do we revoke a lost key and re-enroll a user, and what identity checks does that use?
  • Which of our systems need smart card or OTP functions rather than FIDO2?
  • Do you require or offer FIPS-validated models for regulated users?

How it differs from passkeys

A passkey is a FIDO credential; a hardware security key is one of the places it can live. Passkeys stored on a security key are device-bound: they stay on that key and are designed not to be exported. Passkeys stored in a phone’s or computer’s credential manager are often synced across devices through a cloud account, which makes them easier to recover but ties their security to that account. Security keys also do things passkeys don’t, such as acting as a smart card or working as a U2F second factor. For managing the laptops and phones that keys and passkeys are used with, see our unified endpoint management overview.

Frequently Asked Questions

Is a YubiKey a security key?
Yes. YubiKey is Yubico's line of hardware security keys and the best-known example of the category. Yubico's FIDO-only Security Key models support FIDO2 and U2F; its multi-protocol YubiKey 5 models add smart card, one-time password and OpenPGP functions. Several other manufacturers make FIDO-certified keys, so compare models on the features you need.
What happens if a user loses their security key?
The key alone usually isn't enough to sign in, since a password or the key's PIN is also needed, but it should be removed from the user's account promptly. Users then sign in with a registered backup key or go through a recovery process, which should include strong identity checks. Many organizations issue two keys per user for this reason.
Do security keys work with phones?
Many do, over NFC or a USB-C or Lightning connector, depending on the key and the phone. Support varies by operating system, browser and app, so test the devices your users carry.
Are security keys better than passkeys on phones?
They are different trade-offs. Security keys hold device-bound credentials that are designed not to be copied, and they don't depend on a phone or a sync account, which suits administrators and shared devices. Synced passkeys are cheaper and easier to recover. Many organizations use keys for high-risk users and passkeys for others.
How much do security keys cost?
Prices vary by model and features, and by volume or subscription programs. Budget for at least one spare per user, replacement of lost keys and the staff time to enroll and support them, not only the unit price.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.