Open-source hardware security key line from Berlin-based Nitrokey, with models ranging from the FIDO2-only Nitrokey Passkey to the Nitrokey 3, which adds PIV smart card, OpenPGP, and TOTP support.
Nitrokey
nitrokey.comA hardened pick. Worth the effort once you have chosen to shrink your footprint on purpose. Enough for most people. Threat levels
Nitrokey’s key differentiator over Yubico is transparency: the firmware is open source and auditable, the hardware designs are published, and the company is based in Germany with no US jurisdiction concerns. The Nitrokey 3 covers the same protocol breadth as the YubiKey 5. The practical catch is ecosystem polish: the companion app and documentation are less refined than Yubico’s, and some enterprise integrations assume a YubiKey. A strong pick for privacy-conscious users who want to verify what runs on their security hardware.
Measures the security configuration of the tool's own website, not the privacy of the product itself. A strong tool can still score low here.
Nitrokey alternatives
Permissive like MIT, with an explicit patent grant and a requirement to flag any changes you make.
Permits
- Commercial use
- Modification
- Distribution
- Patent use
- Private use
Requires
- License and copyright notice
- State changes
Does not provide
- Trademark use
- Liability cover
- Warranty
Why it matters: Permissive licensing lets anyone reuse this, including inside closed products. That is freedom to build on, but no guarantee that downstream copies stay open.
Plain-language summary of the project's license, not legal advice. Read the full text for the exact terms.
* Average ratings will show on this page once the threshold of 5 ratings is reached.