A {hardware} safety secret is a bodily gadget—like a USB stick—that offers you an additional layer of safety via multifactor authentication (MFA). While you register to sure companies, you’ll plug it in and both faucet or contact it on a suitable system to verify it’s actually you.
What to Look For in a Hardware Security Key
If you’ve spent any time online, you’ve probably come across two-factor authentication (2FA,) where you log in with your password, then get a code sent to your phone or email that you have to punch in. Sometimes you get it from an authenticator app instead.
Unfortunately, these methods aren’t bulletproof. SMS codes can be intercepted with SIM-swapping attacks, emails can be hacked through social engineering, and authenticator apps are useless if your phone gets stolen—or if you just forget it at a coffee shop.
This is where security keys are helpful as a form of Multi-Factor Authentication (MFA)—you add more than one layer of security to prove it’s really you logging in. Unlike SMS or email codes, physical security keys can’t be intercepted or hacked remotely.
Yes, they can be stolen, but some security keys come with biometrics or require a PIN, so even if someone gets their hands on your key, they cannot access your accounts without your fingerprint or tap.
So, when shopping for a security key, ensure it supports your accounts’ protocols. For example, if you want to secure your Twitter, Google, and Facebook accounts, you’ll need a key that works with all of them.
The most common protocol right now is FIDO2, which almost every major service supports. There’s also FIDO U2F, an older version of FIDO2, but most devices that support FIDO2 are backward compatible with U2F.
Some keys have extra features, like One-Time Passwords (OTP) through protocols such as OATH TOTP or Yubico OTP. Others support OpenPGP, which encrypts your emails so only someone with the right OpenPGP key can read them.
On the other hand, if you don’t care about OTPs or encrypted emails, a simple FIDO2 key will cover almost all of your needs.
Also, make sure your key works with the devices you use the most. If you’re mainly securing stuff on your phone, get a key with NFC for easy tap-and-go access. If you want to use biometrics like Windows Hello, use a security key with a fingerprint scanner.
How Did We Research |
||
Models Evaluated |
Hours Researched |
Reviews Analyzed |
10 |
10 |
22 |
How-To Geek’s product recommendations come from the same team of experts that have helped people fix their gadgets over one billion times. We only recommend the best products based on our research and expertise. We never accept payment to endorse or review a product. Read More »
Execs |
Cons |
Appropriate with plenty of companies and units |
Pricey for individuals who do not want the superior options |
Straightforward to arrange and function |
|
FIDO-certified with superior security measures |
|
Appropriate with Yubico Authenticator app |
The Yubico YubiKey 5 NFC is well among the best safety keys for most individuals who use Google, Home windows, macOS, ChromeOS, or Linux and are severe about their on-line safety. It additionally works with Android and iOS. It offers sturdy two-factor authentication throughout over 300 standard companies, together with password managers and social media platforms. You possibly can test here to see in case your favourite companies are supported.
Setup is straightforward, and when you’re up and operating, utilizing it’s a breeze. Simply plug it right into a USB-A port in your PC or faucet it on a suitable NFC-enabled cellular system when prompted, and also you’re all set.
The YubiKey 5 NFC is a part of Yubico’s Collection 5 keys and works with the Yubico Authenticator app. The app helps FIDO2, FIDO U2F, Yubico OTP, OATH-TOTP, OATH-HOTP, good card (PIV), OpenPGP, in addition to challenge-response authentication. Lastly, with an IP67 water resistance rating, it’s constructed with sturdy supplies that resist water, mud, and tampering.
With large compatibility, multi-protocol help, and USB-A/NFC connectivity, the YubiKey 5 NFC is a strong alternative for locking down your on-line accounts.


Greatest Safety Key General
Yubico YubiKey 5 NFC
The Yubico Yubikey 5 NFC is the perfect safety key for folks in search of the right steadiness of value, options, and performance with FIDO multi-protocol help.
Execs |
Cons |
Inexpensive FIDO {hardware} safety key |
Doesn’t help OTP, TOTP, Good Card (PIV) |
USB-C and NFC connectivity choices |
|
Works with a number of OSs and units |
|
Proof against water, crushing, and tampering |
If you happen to’re on a decent finances however nonetheless need tight safety, the Yubico Security Key C NFC is the right finances safety key. Priced at beneath $30, it’s a steal in comparison with enterprise-grade keys that may value lots of—and even 1000’s—of {dollars}. It’s additionally simple to make use of and, like all of the featured safety keys on our checklist, doesn’t require batteries or Wi-Fi. Simply plug it right into a USB-C port or faucet it on an NFC-compatible system, and also you’re good to go.
This key works with Home windows, macOS, ChromeOS, Linux, and helps Google and Microsoft accounts together with standard password managers. It’s suitable with FIDO2 for password-less login and FIDO U2F for second-factor authentication.
Whereas it doesn’t help OTP and different superior options just like the Yubikey 5 NFC, it’s constructed powerful and can also be immune to water, mud, and tampering. If you happen to’re in search of a easy, budget-friendly key, this one’s a no brainer.


Greatest Finances Safety Key
Yubico Safety Key C NFC
The right method for the common laptop or telephone consumer to enhance their digital safety. The Yubico Safety Key C NFC is suitable with all kinds of units, helps the commonest protocols in FIDO U2F and FIDO2, and is powerful sufficient to outlive life on a keychain. All for lower than $30.
Execs |
Cons |
Primary, beginner-friendly safety key |
Restricted compatibility and no superior security measures |
Straightforward to arrange and easy to make use of |
|
Makes use of FIDO U2F protocol |
|
Inexpensive and sturdy development |
If you happen to’re in search of one thing primary and beginner-friendly, the Thetis FIDO U2F Security Key is value trying out. It’s designed to be easy, so even somebody much less tech-savvy can use it.
Like Yubico safety keys, establishing the Thetis safety secret is easy. To make use of it, plug it right into a USB-A port and press the button to approve your login. It really works with Chrome and Opera (model 40 and later) on Home windows, macOS, and Linux. You are good to go so long as the web site helps FIDO U2F. Meaning standard companies like Google Workspace, Fb, and Salesforce are all suitable.
Nevertheless, this key doesn’t work with any e-mail consumer and isn’t suitable with OTP or UAF protocols. If you happen to want these options, contemplate the Thetis FIDO2 HOTP Security Key as an alternative. However for a primary safety key that will get the job completed, the Thetis FIDO U2F is a superb entry-level possibility at a budget-friendly value that is onerous to beat.


Greatest Primary Safety Key
Thetis Fido U2F Safety Key
The Thetis FIDO U2F Securty Key’s very best for individuals who are new to {hardware} safety keys, who need an reasonably priced, easy, no-frills expertise.
Execs |
Cons |
---|---|
Will sit almost flush in a laptop computer port |
Not suitable with Home windows ARM computer systems |
Home windows Hi there suitable |
No USB-C port |
Appropriate with many standard password managers |
Not suitable with different OSes |
Fingerprint scanners are extremely helpful for protecting your info protected. Nobody can hack your fingerprint, in spite of everything, and all it is advisable to do to unlock it’s faucet the reader. The Kensington Gen2 VeriMark, the brand new model of our previous pick, is the perfect fingerprint key you should purchase.
This USB-A key will sit almost flush in its port, making it very best for laptops and different units the place you do not need a stick poking out. It does, sadly, nonetheless stick out a bit, nevertheless it’s nothing in comparison with the opposite choices on our roundup. You may as well retailer as much as ten fingerprints on the important thing, making it simple so that you can use a number of fingers and provides entry to associates, household, or IT.
As for safety, the VeriMark follows the most recent net requirements and privateness legal guidelines, so you already know your knowledge might be safe. There may be even compatibility for passkeys, making logging in simpler than ever.
That mentioned, this Kensington safety key is not good. For starters, it solely works on Home windows; the fingerprint reader cannot be used with macOS or ChromeOS. On high of that, the scanner can also be incompatible with Home windows ARM computer systems, so hold that in thoughts if you happen to’re utilizing the particular model of the OS. Lastly, there isn’t any USB-C port or model of the Gen2 VeriMark, however given that the majority units you will wish to safe can have a good quantity of USB-A ports, this is not a lot of a dealbreaker.


Greatest {Hardware} Safety Key for Biometrics
Kensington VeriMark Gen2 Fingerprint Reader
This small fingerprint key will hold your laptop computer protected whereas remaining comparatively flush to your system. It is also suitable with Home windows Hi there and quite a lot of password managers.
Execs |
Cons |
Constructed by Google, good for Google companies |
Preliminary setup might be difficult for some customers |
Shops as much as 250 passkeys |
|
FIDO suitable |
|
Appropriate with quite a few companies and units |
If you happen to’re already closely invested within the Google ecosystem, the Google Titan Security Key is your finest guess. Created by Google, it really works completely with the corporate’s companies, however the safety key additionally works with many different platforms.
In contrast to different safety keys that retailer only some fingerprints, the Google Titan can retailer as much as 250 passkeys, making it tremendous versatile, even with non-Google companies. It really works with Google telephones, Chromebooks, tablets, and something that may run Google Chrome. It’s additionally suitable with Google’s Advanced Protection Program, which provides additional safety for high-risk customers.
The Titan Safety Key is available in two variations: USB-A with NFC (and a USB-C adapter) or USB-C with NFC for simply $5 extra. Whichever you go for, you are positive to get good worth on your cash. Constructed on the FIDO protocol, it provides safe two-factor authentication and is hard sufficient to deal with every day put on and tear. Setup might be difficult at first—you may need to repeat some steps—however as soon as it’s prepared, it’s easy crusing.


Greatest Safety Key for Google Providers
Google Titan Safety Key
The Google Titan Safety Key’s your best option for customers who’re acquainted and cozy with the Google ecosystem. FIDO-certified, it has strong options and likewise helps non-Google companies and platforms.
FAQ
Why ought to I take advantage of a {hardware} safety key?
{Hardware} safety keys are extremely really helpful due to the “possession issue”; the truth that you alone possess the technique of entry, on this case, a {hardware} safety key.
What are safety key certifications?
Safety key certifications present how safe a tool is. Every Analysis Assurance Stage (EAL) comes from Widespread Standards safety checks—a worldwide customary for evaluating digital safety—they vary from EAL1 (primary safety) to EAL7 (the very best stage of safety).
What ought to I do if I misplaced my {hardware} safety key?
Throughout preliminary setup, most {hardware} safety keys immediate you to arrange a restoration technique. If you happen to did and also you lose your key, merely remove the key as an authentication device in your account. Alternatively, you should utilize a backup safety key if in case you have one already arrange. In any other case, there’s actually nothing a lot you are able to do.
Can any USB drive be a safety key?
Sure, you possibly can flip nearly any USB drive right into a safety key utilizing instruments like Predator (Home windows), Rohos Logon Key (Home windows, Mac), and USB Raptor (Home windows). Predator and Rohos Logon Key require fee to unlock their full options.