A hardware security key is a small physical device, usually plugged into a USB port or tapped against a phone over NFC, that proves who a user is when they sign in. It holds private cryptographic keys that are designed not to leave the device and signs a challenge from the service after the user touches it, and often enters a PIN or fingerprint. Most current keys implement the FIDO2 and older U2F standards. The best-known product line is Yubico’s YubiKey, and several other manufacturers make comparable keys, so if you’ve been told to buy a YubiKey, this is the product category.
At a glance
- A physical authenticator that connects by USB-A or USB-C, NFC and, less commonly, Bluetooth or Lightning.
- Uses FIDO2/U2F public-key credentials bound to each site, a common way to meet phishing-resistant MFA requirements.
- Some models also act as a smart card for certificate-based sign-in, or generate one-time passwords (OTP).
- FIDO2 keys can store device-bound passkeys for passwordless sign-in, protected by a PIN or built-in fingerprint reader.
- Plan for two keys per user, enrollment, lost-key handling and recovery.
What problem it solves
Codes sent by SMS, codes from apps and push approvals can all be relayed by a fake login page or approved by a user worn down by prompts. A security key signs only for the genuine site, so a look-alike domain gets nothing reusable, and the private key is designed not to be copied off the device.
Keys also solve a practical problem: they don’t need a phone. That matters for staff who can’t use personal phones for work, people on shared terminals or kiosks, secure areas where phones aren’t allowed, and administrators who shouldn’t depend on a device that is also used for personal apps.
How it works
FIDO2 and U2F. When a user registers a key with a service, the key creates a new key pair for that service and returns the public key. At sign-in, the browser passes the service’s challenge and the real domain to the key over USB, NFC or Bluetooth, the user touches the key, and the key signs. FIDO2 keys can also check a PIN or fingerprint (user verification) and store discoverable credentials for passwordless sign-in. U2F-only keys act as a second factor after a password.
Smart card and certificates. Many multi-protocol keys can hold certificates, acting like a smart card for Windows sign-in, VPNs or document signing under your public key infrastructure (PKI).
One-time passwords. Some keys can generate HOTP or TOTP codes, usually with a companion app, for systems that only accept codes. These codes are not phishing-resistant.
Attestation and model control. At registration, a FIDO key may return attestation data. An identity provider that validates it against trusted vendor or FIDO Alliance metadata can identify the model and accept only approved ones, such as FIPS-validated keys where a contract or regulation calls for them.
Enrollment. Keys are registered to a user through the identity provider, either by the user after signing in or by IT before the key is handed out. Some identity providers and vendors offer pre-enrolled or supplier-managed programs.
When it matters for buyers
- For administrators, executives and finance staff. These accounts are the most targeted; keys are a common requirement.
- At cyber insurance renewal. Insurers that ask about phishing-resistant MFA often treat FIDO2 keys as qualifying. Requirements vary by insurer.
- For shared, kiosk or phone-free environments. Keys work where phone-based MFA doesn’t.
- When budgeting. Count keys per user, spares, replacements, shipping to remote staff and support time.
- When planning recovery. A lost key should be revoked fast, and re-enrollment should require strong identity checks, or attackers will target the help desk instead.
- When checking compatibility. Confirm connector types for laptops and phones, and which applications, VPNs and desktop logins support keys directly.
Questions to ask vendors
- Which key models do you support or certify, and do you support FIDO2 with user verification or only U2F?
- Can we restrict accepted keys by model using attestation?
- Can keys be pre-enrolled or managed centrally, and how are they shipped to remote staff?
- How do we revoke a lost key and re-enroll a user, and what identity checks does that use?
- Which of our systems need smart card or OTP functions rather than FIDO2?
- Do you require or offer FIPS-validated models for regulated users?
How it differs from passkeys
A passkey is a FIDO credential; a hardware security key is one of the places it can live. Passkeys stored on a security key are device-bound: they stay on that key and are designed not to be exported. Passkeys stored in a phone’s or computer’s credential manager are often synced across devices through a cloud account, which makes them easier to recover but ties their security to that account. Security keys also do things passkeys don’t, such as acting as a smart card or working as a U2F second factor. For managing the laptops and phones that keys and passkeys are used with, see our unified endpoint management overview.
