We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
FIDO2 Security Key: How to Protect Google and Other Accounts
We already have a separate guide on choosing U2F/FIDO security keys. Here, we’ll focus on the practical side: you already have a FIDO2 security key, and you need to add it correctly to Google, GitHub, a crypto exchange, or a password manager, set up reliable backup access, and avoid locking yourself out of your accounts. We’ll also explain the difference between a security key and a passkey, and where the protection of a physical key ends.
FIDO2 security key: what it protects — and what it doesn’t
A FIDO2 security key is primarily designed to stop unauthorized sign-ins, even if your password or other login credentials have been stolen or intercepted.
What it protects against:
What it does not protect against:
Second factor vs. passkey: two ways to use the same key
A physical security key can be used in two main ways, and it helps to understand the difference before you start setting it up.
Security key as a second factor. You enter your username and password first, then the service asks you to confirm the sign-in with the physical key. Even an older U2F/FIDO1 key may be enough for this setup: for example, Google accepts both FIDO1 and FIDO2 security keys for 2-Step Verification.
Passkey stored on the security key. A FIDO2 key can store a discoverable credential — a hardware-bound passkey that may replace your password on a compatible service. Signing in usually requires user verification on the key itself, typically with a FIDO2 PIN or biometrics, followed by a touch.
Registering a security key as a regular second factor generally does not use discoverable-credential slots. The storage limit matters specifically for passkeys saved on the key, and it depends on the model and firmware. Hardware-bound passkeys make the most sense for your primary email, password manager, GitHub, and other high-value accounts; where passwordless sign-in is not needed, the same key can simply remain a second factor.
What to do before setting up your security key
Set up backup access before you start relying on a physical key as the main protection for your most important accounts.
Google: three levels of protection
Google lets you use the same physical key as a second factor, as a passkey, or as part of Advanced Protection.
Level 1. Security key as a second factor
In the basic setup, your password stays in place and the physical key becomes the second step of the sign-in process. Right after setup, add a backup key, save your backup codes, and review alternative 2FA methods. If SMS remains available as an alternative second factor, an attacker may try to target that weaker channel. A recovery phone number is a separate setting, so there is no need to remove it automatically just because you disable SMS as a 2FA method.
Level 2. Passkey stored on the key
A FIDO2 security key can store a passkey and use it for passwordless sign-in. In your Google settings, open the passkeys and security keys section, choose to create a passkey on a security key, connect the key, and confirm registration with the key’s PIN and a touch.
Level 3. Advanced Protection
Advanced Protection is Google’s strictest security mode for people at higher risk of targeted attacks. It requires a passkey or security key for sign-in, limits access by unverified third-party apps, adds stronger download checks, and makes account recovery more restrictive.
Advanced Protection no longer requires two physical security keys: you can enroll with a passkey or a FIDO-compatible security key. Google still recommends keeping your recovery email and phone number up to date and having a separate backup passkey or physical key. Advanced Protection may be unnecessary for an ordinary personal account, but it can make sense for journalists, activists, administrators, executives, and anyone protecting especially valuable accounts.
Other services
Microsoft
Personal Microsoft accounts support passkeys and hardware security keys. In Microsoft Entra ID, administrators control which passkey types are allowed through authentication policies. Starting September 1, 2026, Microsoft automatically adds passkeys to the allowed authentication methods for Entra users who previously had SMS or voice calls enabled and prompts them to register a passkey during MFA sign-in; Microsoft does not create the passkey without the user completing registration.
Apple Account
Apple requires at least two FIDO Certified security keys, and you can add up to six to your Apple Account. Devices already signed in to the account must be running iOS 16.3, iPadOS 16.3, macOS Ventura 13.2, or later, and two-factor authentication must already be enabled. Once configured, the physical key replaces the usual six-digit verification code during sign-in.
Store your keys in different locations. If you lose access to all trusted devices and all security keys, Apple warns that you could permanently lose access to your account.
GitHub
GitHub supports security keys as a second factor and passkeys for passwordless sign-in. A passkey can satisfy both the password and 2FA requirements at the same time. If your GitHub account gives access to repositories, CI/CD, or tokens, it is worth adding a hardware-bound passkey or security key and keeping recovery methods separately.
Password managers
Your password manager is one of your most important accounts because compromising it can expose access to many other services. Bitwarden supports FIDO2 WebAuthn for two-step login for all users. After enabling 2FA, save your recovery code outside the vault itself: without it and without another available 2FA method, you may be unable to regain access.
Crypto exchanges
On a crypto exchange, the key question is which actions FIDO2 actually protects: signing in, changing settings, adding a withdrawal address, or withdrawing funds.
Binance lets you use a hardware FIDO2 key as a passkey; on compatible phones, the key can work over NFC or USB. Before setup, check the current options for your platform and app version.
Kraken configures sign-in 2FA, Master Key, and Funding 2FA separately. For withdrawals, Funding 2FA supports a Hardware Security Key or an authenticator app. It is also worth enabling Global Settings Lock: it blocks changes to critical settings and, among other things, helps prevent an attacker from adding new withdrawal addresses after taking over your account.
Other exchanges use different rules, so if you are buying a key for a specific service, check that service’s current documentation first.
Ukrainian services
Universal USB/NFC FIDO2 keys are still uncommon as a standard sign-in method in Ukrainian banking apps, which more often rely on their own approval flows and biometrics. Specialized systems such as DELTA are a separate use case. See our detailed guide to setting up FIDO2 security keys for DELTA.
YubiKey FIDO2 PIN: 8 attempts and what happens after lockout
If you use a YubiKey, it is important to know the FIDO2 PIN retry limit, especially when passkeys are already stored on the key. Yubico allows 8 attempts in total. After three consecutive incorrect PIN entries, you must unplug and reconnect the key; the retry counter does not reset. In practice, that gives you 3+3+2 attempts. A correct PIN resets the counter back to eight.
After the eighth failed attempt, the FIDO2 function is locked and you must perform a FIDO reset to use it again. A FIDO reset deletes the FIDO2 PIN and all FIDO/U2F credentials stored on the key, so you will need to register the key with your services again. There is no separate PUK code for FIDO2. Other authenticators may handle retry limits differently.
How many passkeys can a security key store?
Capacity depends on the model and firmware. If you plan to use hardware-bound passkeys extensively, check the limit before you start.
OnlyKey is different from a typical FIDO-only security key: it combines FIDO2 with a built-in password manager, OpenPGP, SSH, and encrypted backup and restore. That broader feature set can be useful for more advanced setups; if you mainly need FIDO2 for email, GitHub, and exchanges, a simpler security key is usually more convenient.
How to set up a real backup key
A key sitting unregistered in a drawer is not a real backup. On typical hardware-bound security keys, a passkey cannot be copied from one physical key to another, so each key must be registered separately with your critical services while you still have access to the accounts.
About once every six months, use the backup key to complete a real sign-in to at least one critical service. This confirms that the key still works and that you remember the PIN and know where the backup is stored.
What to do if you lose your security key
If you lose your primary key, follow these steps:
If you do not have a backup, the recovery process depends on the service. Google warns that verification after losing a second factor can take 3–5 business days. A crypto exchange may require you to verify your identity again. For Apple, the worst-case scenario is losing access to both every security key and every trusted device.
Which security key should you choose?
If your main goal is FIDO2 for Google, email, GitHub, password managers, and crypto exchanges, Security Key by Yubico with NFC is usually enough. It supports FIDO2/WebAuthn and U2F, but not Yubico OTP, PIV, OpenPGP, or OATH, which makes it a simpler option than the multiprotocol YubiKey 5 Series.
YubiKey 5 Series is the better choice if you also need Yubico OTP, OATH, PIV, or OpenPGP. Security Key Series can also be used for modern FIDO2-based SSH authentication, so SSH alone is not necessarily a reason to move up to a YubiKey 5.
YubiKey Bio is a good fit if you want to approve FIDO2 sign-ins with a fingerprint: you can enroll up to five fingerprints, while the PIN remains a fallback verification method. OnlyKey is worth considering if you want a built-in password manager, FIDO2, OpenPGP, and SSH in one device.
You can buy a key directly from the manufacturer or from Lwallet. The Lwallet catalog includes Security Key by Yubico, YubiKey 5 Series, YubiKey Bio, the FIPS lineup, and OnlyKey, with local support and setup assistance.
Final setup checklist
Related Posts
YubiKey 5.4 vs 5.7+: what changed, and should you replace your key?
How does YubiKey firmware 5.4 differ from 5.7+, and is it worth replacing your key? The hardware looks identical from the outside: USB-A or USB-C, with or without NFC, and the same gold touch sensor. Inside, however, the differences between firmware 5.4.x and 5.7.x are substantial. Before going any further, there is one important point …
Best FIDO2 Security Keys to Buy in 2026
When choosing FIDO2 security keys, specs are only part of the picture. You also need to think about how convenient a key will be to use every day: which connector it uses, whether it has NFC, whether it works well with your laptop and phone, and whether your email provider, crypto exchange, GitHub, or password …
How to set up two-factor authentication on GitHub using Yubikey?
Hello everyone! Setting up two-factor authentication on GitHub with a YubiKey is one of the most reliable ways to keep your developer account safe. Not everyone knows how to ensure this security using modern methods. And to do so, all you need is to be the happy owner of a YubiKey hardware security key for …
Which FIDO2 Keys Are Compatible with Delta?
Compatible devices, recommendations, and common errors FIDO2 keys for Delta are the most reliable way to secure access to the combat situational awareness system of the Armed Forces of Ukraine. Delta uses multi-factor authentication (MFA), and a physical security key based on the FIDO2 standard is the most phishing-resistant method. This guide will help you …