PrivacyTools.io
Reviewed by Gabriel Bachmann
Replace today: SMS codes Authenticator apps

Hardware Security Keys for Phishing-Proof 2FA in 2026

Private alternatives to SMS codes, Authenticator apps, vetted against our public criteria.

How they compare

Tool Protocols Based in Cost
Nitrokey
FIDO2 + OpenPGP Germany Paid
YubiKey 5 Series
FIDO2 + OpenPGP Sweden Paid
Yubico Security Key
FIDO2 only Sweden Paid

A hardware security key is a small device that plugs into USB or taps over NFC to prove it is really you logging in. It is the strongest second factor available, because the secret never leaves the key and it cannot be phished the way a typed code can. For the accounts that would hurt most to lose, email and your password manager first, a key turns a stolen password into a dead end.

Why a typed code can still be phished

A code from an app or a text is only as safe as the page you type it into. A convincing fake login page asks for your password and your code together, then relays both to the real site in real time and walks straight into your account, and no amount of care spots every clone. A security key closes that hole by design. During setup it bonds to the real web address, and when you sign in it checks that address cryptographically before it responds, so it stays silent on an impostor site. That single property stops the most common account takeovers, which is why a key is a genuine step up from an authenticator app rather than just a different flavour of it.

How we pick

Every key here is measured against our public listing criteria. We require support for the open FIDO2 and WebAuthn standards, so you are buying into a protocol rather than a single vendor, and we favour keys whose firmware and tooling are open to inspection. We look at the range of connectors offered, because a key you cannot plug into your devices is useless, and at the extra features some keys add beyond login. We only list a key we would carry on our own keyring, and we note plainly where each one fits.

What to look for in a security key

Start with the standard: FIDO2 and WebAuthn support is the non-negotiable, because that is what delivers the phishing resistance. Then match the connectors to your hardware, whether that is USB-C, USB-A, NFC, or Lightning, and prefer a key that covers a phone as well as a laptop. Decide whether you want a plain login key or one that also handles TOTP, smart-card, or OpenPGP duties, since Nitrokey and the YubiKey 5 carry those extras while a basic key keeps things simple and cheaper. Above all, plan to buy two, because the backup is part of the spec, not an optional add-on.

Do I really need a key if I already use an app?

For most accounts, an authenticator app is already a large improvement over texted codes, so a key is not strictly required. The case for adding one is the handful of accounts that protect everything else, your primary email and your password manager, where a phished code would be a disaster. On those, the key’s address check is worth the small cost and the habit of carrying it. A reasonable middle path is a key on your two or three most sensitive logins and an app on the rest, which raises the floor everywhere without buying a key for every site.

How to set one up

Register the key on your important accounts, email first, by choosing the security-key option in each site’s settings and touching the key when prompted. Then register your second key the same way and store it somewhere separate, one on your keyring and the other at home or in a safe. Keep your authenticator app enrolled too as a fallback for sites that do not yet support keys. From there your logins get both easier, a tap instead of typing a code, and far harder to steal. To round out the account, a password manager gives every login a strong, unique password for the key to guard.

Frequently asked

What happens if I lose my security key?
This is why you register two from the start. If one goes missing, you sign in with the backup and remove the lost key from each account so it can no longer be used. A single key as your only second factor is the one setup mistake to avoid, because there is no way to recover access if it disappears.
Do security keys work with the accounts I actually use?
Most major services now support them, including email providers and password managers, with social networks and banks steadily catching up. The keys speak the open FIDO2 and WebAuthn standards, so support comes from the site rather than from any one key brand. Sites that have not added support yet still accept your app-based codes alongside the key.
Is a security key better than an authenticator app?
For resisting phishing, yes, and that is the main reason to buy one. An app code can still be typed into a convincing fake login page, while a key cryptographically checks the real web address before it responds and simply refuses an impostor site. For everyday convenience the two are close, so many people use a key on their most sensitive accounts and an app elsewhere.
Do I need any software or a subscription to use one?
No. A FIDO2 key works through the browser and operating system support that is already built in, with nothing to install and no account or fee attached to the key. You plug it in or tap it over NFC when a site asks for it. Some keys offer extra features through an optional companion app, but basic login never requires one.
Can one key protect more than one account?
Yes. A single key can be registered to as many sites as you want, each as a separate enrolment, and it keeps them apart with no practical limit for normal use. Registering a new account is the same quick step every time: choose the security-key option in that site's settings, then touch the key to confirm.
Will a security key work on my phone, not just my computer?
Yes, as long as the connector matches. Keys come in USB-C, USB-A, NFC, and Lightning forms, and the NFC ones simply tap against the back of a phone that supports it. The trick is buying the connector your devices actually use, which is why checking your laptop and phone ports before you order matters.