We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Best FIDO2 Security Keys to Buy in 2026
When choosing FIDO2 security keys, specs are only part of the picture. You also need to think about how convenient a key will be to use every day: which connector it uses, whether it has NFC, whether it works well with your laptop and phone, and whether your email provider, crypto exchange, GitHub, or password manager supports it. The key is to match the device to the level of protection you need, the services you want to secure, and the hardware you use.
Today, the terms U2F key and FIDO key usually refer to modern security keys that support FIDO2 and WebAuthn. These standards power passkeys, hardware-based phishing protection, and passwordless authentication. The older U2F protocol works only as a second factor after a password, while FIDO2 can replace the password entirely. In 2026, we recommend focusing on FIDO2-capable models, since U2F-only devices are now a previous-generation option.
In this guide, we’ll explain what to look for before you buy, which models are actually worth considering, and which key makes the most sense for different use cases. We reviewed the current options and checked their specifications to narrow the list down to models that are genuinely practical in everyday use.
If you already have a key and want to move on to setup, we also have a separate guide — FIDO2 Security Key: How to Protect Google and Other Services. It explains how to use a hardware security key to protect Google and other compatible accounts.
First rule: buy two keys from the start
We’ll start with the most important advice in this guide. One key is the minimum, but we do not recommend stopping there. If your only key is lost or fails at the wrong time, you may have to recover access through backup sign-in methods. A much safer setup is to have two keys from the start.
Use one as your primary key and store the other at home, in a safe, or in another secure location. Register both keys with every important account. If your primary key is lost or damaged, the backup lets you keep access without going through a complicated recovery process.
We recommend buying two identical keys, or at least two models from the same product family. That reduces the chance of running into unexpected compatibility differences. If your primary key supports NFC, FIDO2, and the authentication workflows you need, the backup should support the same features. This matters especially if you use additional functions such as OATH/TOTP. Yubico likewise recommends choosing a backup key from the same product family.
Apple Account is even stricter: Apple requires at least two security keys when you set the feature up.
For most users, we recommend two identical Security Key C NFC devices. If you need a multiprotocol option, choose two identical YubiKey 5C NFC keys, or two YubiKey 5C keys if you do not need NFC. Using two matching keys is usually the most predictable setup.
How to choose FIDO2 security keys
Many guides start with the connector: USB-C or USB-A. That matters, but it is better to first define your use case and the features you actually need, then choose the form factor.
1. Define your use case
FIDO-only: passkeys + 2FA. If you mainly need a key for account sign-ins, passkeys, and phishing-resistant authentication, a FIDO-only model is often all you need. Yubico Security Key Series and Google Titan keys support FIDO2/WebAuthn and U2F and work with Google, Apple, Microsoft, GitHub, password managers, and most modern services.
Multiprotocol key: FIDO2 + OTP + PIV + OpenPGP. If you also need TOTP through Yubico Authenticator, smart-card functionality, OpenPGP, or enterprise use cases, look at YubiKey 5 Series or Nitrokey 3. These keys support a broader set of features, but they cost more and require a little more familiarity with what they can do.
Security Key vs. YubiKey 5: what’s the difference?
Security Key Series is FIDO-only: FIDO2/WebAuthn + U2F. It does not support Yubico OTP, OATH-TOTP/HOTP, PIV, OpenPGP, Yubico Authenticator, or Yubico Personalisation Tool. These are straightforward keys for passkeys and 2FA without the extra protocols.
YubiKey 5 Series is multiprotocol. In addition to FIDO2 and U2F, it supports Yubico OTP, OATH-TOTP/HOTP — up to 64 slots on firmware 5.7+ — PIV Smart Card with up to 24 certificates, OpenPGP, and Yubico Authenticator.
If you only need passkeys and 2FA, the underlying FIDO security level is the same across both series. The main difference is the number of supported protocols and use cases.
2. Biometrics
Biometric security keys are useful, but they are not necessary for everyone. The underlying FIDO2 cryptography stays the same; a fingerprint simply adds another layer of local user verification. A PIN can be observed, accidentally disclosed, or revealed under pressure. Fingerprint verification removes some of those risks.
If someone gets hold of a regular key and also knows its PIN, they may be able to access protected accounts. With a Bio model, possession of the key alone is not enough: your fingerprint is required. After three failed fingerprint attempts, the key falls back to PIN verification. The Bio Series makes the most sense for regular desktop use, while an NFC model is usually more practical if you often sign in from a phone.
3. Connector and NFC
Connector. If you use a modern laptop or tablet, USB-C will usually be the most convenient choice. USB-A still makes sense if you mainly use a desktop PC, an older laptop, or workplace hardware where USB-A remains common. A key that needs an adapter every time quickly becomes inconvenient.
NFC. If you sign in from your phone even occasionally, NFC makes a security key much easier to use. For most users, USB-C + NFC is the most practical combination today.
The technical side: what’s inside a security key and why it matters
FIDO2 security keys differ in more than just form factor. If you want to understand the technical differences between models, focus on a few key specifications.
Protocols and standards
Passkey storage
The number of passkeys stored directly on the key (discoverable credentials) matters more as additional services adopt passkeys. Capacity varies significantly across the models in this guide: YubiKey with firmware 5.7+ supports up to 100 passkeys, Google Titan v2 up to 250, Token2 T2F2 up to 300, Nitrokey Passkey more than 100, and Nitrokey 3C NFC up to 35. With Google Titan v2, keep in mind that individual passkeys cannot be deleted after they are created.
FIDO Certification Level
FIDO Alliance certification indicates how thoroughly a product’s FIDO implementation has been evaluated.
YubiKey 5 Series and Security Key Series with firmware 5.7+ have FIDO Level 2 certification. Google Titan v2 is FIDO Level 1. Level 1 is sufficient for many everyday use cases, while Level 2 may matter in enterprise environments or where compliance requirements call for it.
Device and service compatibility
Before buying, check the security settings of the accounts you actually use. This is especially important for exchanges and crypto services: one may support full FIDO2, another only U2F, and another only TOTP.
Security key roundup
Security Key C NFC by Yubico — the best place to start
Security Key C NFC by Yubico
If we had to recommend one key for most people to start with, this would be it. USB-C for modern laptops and NFC for phones make it convenient for everyday use, without paying for features many users will never need.
Yubico Security Key Series supports only FIDO protocols: FIDO2/WebAuthn and FIDO U2F. If you do not need PIV, OpenPGP, OTP, or other enterprise and technical features, you get exactly what you need for passkeys and phishing-resistant sign-in.
With firmware 5.7+, the key stores up to 100 passkeys, supports CTAP 2.1, and is FIDO Level 2 certified. For Google, Apple, Microsoft, GitHub, password managers, and other modern services, it is a well-balanced option for the price.
Best for: anyone who wants a practical, reasonably priced FIDO2 key for a modern laptop and smartphone.
Keep in mind: if you later need OTP, smart-card functionality, OpenPGP, or broader enterprise features, you will need to move up to YubiKey 5 Series.
Security Key NFC by Yubico — the same idea for USB-A
Security Key NFC by Yubico
This is essentially the same concept as Security Key C NFC, but with USB-A. It is a good fit for desktop PCs, older laptops, and workplace hardware where USB-A is still widely used.
USB-A is no longer the most future-proof connector, but it is still common in real workplaces. If your main computer uses USB-A, this model provides the same FIDO functionality as the C NFC version: up to 100 passkeys on firmware 5.7+, FIDO Level 2, and CTAP 2.1.
Best for: a PC or laptop with USB-A when you still want NFC for your phone.
Keep in mind: newer ultrabooks and MacBooks without USB-A will require an adapter. If you rarely need USB-C, that may not be a meaningful drawback.
YubiKey 5C NFC — the most versatile multiprotocol option
Yubikey 5C NFC
YubiKey 5C NFC makes sense if you want a key with room to grow beyond basic FIDO2. In addition to FIDO2/WebAuthn and U2F, it supports Yubico OTP, OATH-TOTP/HOTP, PIV, and OpenPGP, along with other capabilities that can be useful for work, administration, and more advanced setups.
If you are not sure a FIDO-only key will be enough, this is the model we would look at first. It is especially useful when one key needs to cover personal accounts, work access, VPNs, password managers, and technical workflows.
The combination of USB-C + NFC makes the 5C NFC one of the most convenient multiprotocol options for modern devices.
Technical details: on firmware 5.7+, it supports 100 passkeys, up to 64 OATH credentials, up to 24 PIV certificates, CTAP 2.1, FIDO Level 2, RSA-3072/4096, Ed25519, and X25519. Yubico also moved to its own cryptographic library, giving the company full control over the implementation.
Best for: anyone who wants a versatile key with extra capabilities for work and technical use.
Keep in mind: many users will never need a large part of what the 5C NFC can do, so the higher price is not always justified.
YubiKey 5 NFC — the versatile USB-A option
Yubikey 5 NFC
YubiKey 5 NFC is very close to the 5C NFC in capabilities, but it uses USB-A. The protocol set is the same: FIDO2, U2F, OTP, OATH, PIV, and OpenPGP. The main difference is the connector.
We recommend this model if you want YubiKey 5 Series features but your main hardware still uses USB-A. For desktop PCs and many work laptops, it is a convenient option without adapters. Its key specifications match the 5C NFC: 100 passkeys, 64 OATH credentials, 24 PIV certificates, CTAP 2.1, and FIDO Level 2.
Best for: users who want a versatile YubiKey 5 Series model for USB-A hardware.
Keep in mind: if all of your devices have moved to USB-C, the 5C NFC is the more logical choice.
YubiKey Bio / YubiKey C Bio — when you actually want fingerprint verification
Yubikey Bio
Yubikey C Bio
Biometrics in this series add convenience and another layer of local user verification. Instead of confirming a sign-in with a simple touch, you verify with your fingerprint. This is especially convenient if you regularly sign in to work accounts from the same laptop or desktop.
The main advantage of the Bio Series is that possession of the key alone is not enough to approve a sign-in. That can be useful for work accounts, corporate access, and other situations where you want stricter local control. For frequent use with phones and multiple devices, however, NFC models are usually more practical.
Choose a Bio model because fingerprint verification genuinely fits your workflow, not simply because biometrics sound more advanced.
Technical details: Bio Series supports only FIDO protocols — FIDO2 + U2F. After three failed fingerprint attempts, PIN verification is used as a fallback. With firmware 5.7+, the key can store 100 passkeys. There is no NFC; connectivity is USB only.
Best for: users who want biometric verification for work or other high-value accounts and mostly use a laptop or desktop PC.
Keep in mind: Bio models cost more and are less versatile than NFC models. For many people, a regular NFC key is the more practical choice.
YubiKey 5 Nano / 5C Nano — for leaving the key in your laptop
Yubikey 5 Nano
Yubikey 5C Nano
The Nano form factor is designed to stay in a laptop almost all the time. It is convenient if you do not want to carry a separate key and plug it in for every sign-in. You still get the core YubiKey 5 Series capabilities: FIDO2, U2F, OTP, OATH, PIV, OpenPGP, 100 passkeys, CTAP 2.1, and FIDO Level 2.
Because they are so small, Nano models are less convenient if you frequently move the key between devices. We also would not choose one as your only security key; this form factor makes the most sense when the key stays in one laptop most of the time.
Best for: leaving a key in your laptop almost permanently while keeping it as flush with the port as possible.
Keep in mind: this is not the most convenient form factor if you move between multiple devices every day.
YubiKey 5C — USB-C without NFC
Yubikey 5C
YubiKey 5C is a logical choice if you want the full YubiKey 5 feature set over USB-C but do not need NFC. You get the same core capabilities — FIDO2, U2F, OTP, PIV, OpenPGP, and more — in a simpler form factor aimed mainly at laptop and desktop use.
This model is a good fit for a modern USB-C computer if you rarely need to use the key with a phone over NFC.
Technical details: 100 passkeys, 64 OATH credentials, 24 PIV certificates, CTAP 2.1, FIDO Level 2.
Best for: users who want YubiKey 5 features over USB-C without NFC, mainly for a laptop or desktop PC.
Keep in mind: if NFC and phone use matter to you, the 5C NFC is the better fit.
YubiKey 5Ci — a niche option for Lightning devices
Yubikey 5Ci
This is no longer a mainstream model, but it still makes sense if you use an iPhone or iPad with Lightning and want a hardware security key without adapters.
For most users, we would not put the 5Ci near the top of the list today; USB-C or NFC is usually more practical. But if you specifically need Lightning + USB-C in one key, the 5Ci still gives you the full YubiKey 5 Series protocol set.
Best for: users who still rely on Apple devices with Lightning and want a hardware key without adapters.
Keep in mind: for most people, this is now a very specific use case.
Google Titan Security Key — Google’s alternative
Google Titan v2 is a FIDO-only security key available in USB-C + NFC and USB-A + NFC versions. Its main advantage is support for up to 250 passkeys, one of the higher capacities among FIDO2 keys. The firmware is developed by Google, while the keys are manufactured by Feitian. Certification is FIDO Level 1.
Titan works with Google’s ecosystem and other FIDO-compatible services. There are a few caveats: individual passkeys cannot be deleted after creation, and Microsoft Entra passwordless sign-in does not officially support Titan without additional administrator-side configuration. For basic FIDO2 / 2FA use, it is a strong alternative with plenty of passkey capacity.
Best for: users who want a FIDO2 key with a large passkey capacity, use Google services heavily, or simply want an alternative to Yubico.
Keep in mind: FIDO Level 1 rather than Level 2 on Yubico firmware 5.7+ models, no OTP, PIV, or OpenPGP, and individual passkeys cannot be deleted.
Nitrokey — the open-source approach
Nitrokey 3C NFC is a multiprotocol USB-C + NFC key with open-source firmware. It supports FIDO2, U2F, and OpenPGP, while PIV support is still evolving. Its Secure Element is rated EAL 6+ and is used over USB, but not over NFC. The key is made in Germany, and users can update its firmware — a meaningful difference from Yubico, where firmware is fixed at the factory.
Nitrokey Passkey is a budget USB-A key for FIDO2/U2F. It supports more than 100 passkeys and has a compact form factor, but it does not include NFC or a Secure Element.
Best for: users who value open-source firmware, transparency, and the ability to install firmware updates.
Keep in mind: Nitrokey 3C NFC has fewer passkey slots, its software ecosystem is less mature than Yubico’s, and PIV support is still evolving.
OnlyKey FIDO2 — a niche option with an onboard PIN
OnlyKey FIDO2
OnlyKey is different from a conventional Yubico-style security key. The device has six buttons for entering a local PIN and managing stored slots. It is not only a FIDO2/U2F key for account sign-ins; it can also store usernames, passwords, TOTP credentials, and other data, making it closer to a hardware password manager. Its open-source approach will also appeal to some users.
This model makes sense for users who want more control and a broader set of capabilities in one device. After 10 incorrect PIN attempts, the data on the key is completely erased.
If you want the simplest possible security key, a YubiKey is usually easier to live with. OnlyKey becomes more interesting when you want the device to do more than confirm sign-ins.
Best for: users who value open source, want an onboard PIN, and need capabilities beyond a basic FIDO workflow.
Keep in mind: the learning curve is steeper than with a standard YubiKey, it is USB-A only, and many users will not need the extra features.
Token2 — a budget alternative from Switzerland
Token2 T2F2-PIN+ combines USB-C + NFC with FIDO2 + TOTP support. It stores up to 300 passkeys — the highest figure among the models in this comparison. TOTP requires Token2’s separate app. The key is made in Switzerland and can also enforce PIN complexity requirements, which is unusual among budget models.
Best for: users looking for an affordable FIDO2 key with NFC and a large passkey capacity.
Keep in mind: the ecosystem is smaller and less established, and PIV and OpenPGP are not supported.
FIDO2 security keys: comparison table
Where FIDO2 security keys actually work
Google supports both security keys and passkeys; Apple lets you add security keys to Apple Account; Microsoft supports security keys as a full sign-in method; and GitHub actively supports passkeys that can replace both a password and 2FA in a single sign-in flow.
Crypto services are less consistent. Some exchanges support hardware security keys as a second factor (2FA), but the exact implementation varies by service. Before buying, check the security settings for the exchange or crypto service you actually use.
That is why we do not recommend buying a key blindly. Go through the services you rely on — Google, Apple, Microsoft, GitHub, your password manager, crypto exchange, and work accounts — then choose the connector and feature set that fit those services.
Conclusion
If you want a simple recommendation, we suggest two identical Security Key C NFC devices for most users. You get FIDO2, USB-C, and NFC without paying for extra features you may never use.
If you want a key with room for work and more technical use cases, we recommend two identical YubiKey 5C NFC keys. If your main hardware still uses USB-A, look at the equivalent models without the “C” in the name.
If you want a large passkey capacity or an alternative to Yubico, Google Titan is worth a look. If open-source firmware matters most, consider Nitrokey. If you want an onboard PIN and password-manager features, look at OnlyKey. If you want a budget option with a lot of passkey storage, Token2 is worth considering.
We recommend Bio, Nano, and 5Ci models only when their specific form factor or feature clearly matches your use case. Choose FIDO2 security keys around your devices, services, and daily habits — those factors matter more than price or the number of extra features.
And one final rule: if an account truly matters to you, buy two keys from the start. A backup key is a basic part of a sound security setup.
Related Posts
YubiKey 5.4 vs 5.7+: what changed, and should you replace your key?
How does YubiKey firmware 5.4 differ from 5.7+, and is it worth replacing your key? The hardware looks identical from the outside: USB-A or USB-C, with or without NFC, and the same gold touch sensor. Inside, however, the differences between firmware 5.4.x and 5.7.x are substantial. Before going any further, there is one important point …
How to set up two-factor authentication on GitHub using Yubikey?
Hello everyone! Setting up two-factor authentication on GitHub with a YubiKey is one of the most reliable ways to keep your developer account safe. Not everyone knows how to ensure this security using modern methods. And to do so, all you need is to be the happy owner of a YubiKey hardware security key for …
Which FIDO2 Keys Are Compatible with Delta?
Compatible devices, recommendations, and common errors FIDO2 keys for Delta are the most reliable way to secure access to the combat situational awareness system of the Armed Forces of Ukraine. Delta uses multi-factor authentication (MFA), and a physical security key based on the FIDO2 standard is the most phishing-resistant method. This guide will help you …
FIDO2 Security Key: How to Protect Google and Other Accounts
We already have a separate guide on choosing U2F/FIDO security keys. Here, we’ll focus on the practical side: you already have a FIDO2 security key, and you need to add it correctly to Google, GitHub, a crypto exchange, or a password manager, set up reliable backup access, and avoid locking yourself out of your accounts. …