What is a security key, and do you need one?
A security key is a small physical device that proves it's you when you sign in. It's the form of two-step verification that fake websites can't fool. Here's who it's for.
- Written by
- Digital Life Check editorial team
- Reviewed by
- Not yet independently reviewed
- Last checked
On this page
Quick answer: a security key is a small physical device that you plug into your computer or tap against your phone to prove it's you when you sign in. It's the most phishing-resistant form of two-step verification, because it won't work on a fake website. Most people are well protected with passkeys and an authenticator app. A key is an extra step up for people at higher risk. If you get one, buy two.
How a security key works
A security key is one way of doing the second step of two-factor authentication. Instead of typing a code from a text message, you plug the key in or hold it near your phone and touch it when asked.
Apple describes a security key as "a small external device that looks like a flash drive or tag". Microsoft adds that you also confirm with a fingerprint or PIN, so "even if someone has your security key, they won't be able to sign in without your fingerprint or PIN".
Security keys work on open standards set by the FIDO Alliance, an industry group. You may see the terms FIDO2 and WebAuthn on the packaging or in account settings. They're the technical names for the same system that passkeys use, so a key and a website can recognise each other without you doing anything special.
A key can also hold passkeys. The FIDO Alliance says passkeys stored on a hardware security key "offer the highest security assurance", and Yubico says one of its keys can hold up to 25 passkeys. These passkeys stay on that one key and don't sync to your other devices.
Why fake websites can't fool it
A common way accounts get taken over is phishing: a fake login page that looks like your bank or email. You type your password and a text message code, and the criminal passes both on to the real site.
A security key stops this. The FIDO Alliance explains that each login is tied to the website it was created for and only works there. If you're on a lookalike site, the key won't produce a valid login, however convincing the page looks. There's no code to read out or type in, so there's nothing for a scammer to trick you into handing over.
If you've already typed your details into a page you're not sure about, see what to do if you clicked a scam link.
Who benefits most
Apple calls its security key feature an optional extra "designed for people who want extra protection from targeted attacks, such as phishing or social engineering scams". People who might fit that description include:
- anyone whose name or job makes them a likely target, such as public figures
- people who manage money or accounts for someone else, such as an elderly parent
- anyone who has already been targeted, or whose account has been taken over before
Google offers the Advanced Protection Programme for people "with high visibility and sensitive information" who face targeted online attacks. To join, you sign in with a passkey or a security key.
Which accounts support them
These all let you add a security key to your account:
| Account | What the company says |
|---|---|
| Security keys can be used with 2-Step Verification on your Google Account | |
| Apple Account | Works with any FIDO Certified key; you must add at least two and can add up to six |
| Microsoft account | Supports FIDO2 keys, either USB keys you plug in or NFC keys you tap |
Apple's version has some limits. Every device signed in to your Apple Account needs iOS 16.3, iPadOS 16.3, macOS Ventura 13.2 or later, and child accounts and Managed Apple Accounts aren't supported.
Many other services also accept security keys. Look under Security, Sign-in or Two-step verification in each account's settings.
Why you should buy two
A key is a physical object, so you can lose it. Apple won't let you turn the feature on without registering at least two keys, and suggests keeping one at home and one at work.
Yubico, which makes security keys, recommends registering your spare at the same time as your main key. That way you only have to visit each account once, and you can't lose the first key before the spare is set up.
If you lose a key
- Sign in with your spare key, or another second step you've set up.
- Remove the lost key from the account's security settings, so it can't be used.
- Register a replacement as soon as you can.
Keep a second way in for every account, such as a passkey on your phone or backup codes. The NCSC says backup codes are ideal because they work even if you lose your phone, and each one works once. Store them somewhere safe and offline.
Without a backup, recovery gets harder. Google says account recovery can take 3 to 5 business days while it checks it's you. Apple warns that if you lose all your trusted devices and security keys, "you could be locked out of your account permanently".
Choosing the right connector
Keys come with different plugs, and some have more than one. Match the key to the devices you use:
| Connector | Works with |
|---|---|
| USB-C | iPhone 15 or later and most Mac models, according to Apple; check the ports on your other devices |
| Lightning | iPhone 14 and most earlier iPhones |
| USB-A | Older Mac models, and computers with the larger rectangular USB port |
| NFC (tap) | Phones with NFC, including Android phones; for an Apple Account, Apple says NFC keys only work with iPhone |
Several companies make security keys. YubiKey, made by Yubico, and Google's Titan Security Key are two examples. Look for one that's FIDO Certified.
Passkeys: the free alternative
You don't need to buy anything to get phishing-resistant sign-in. A passkey saved on your phone or computer works in a similar way, and you unlock it with your face, fingerprint or screen PIN.
The NCSC recommends passkeys over passwords wherever they're available, and says they're resistant to phishing because they can't be intercepted, reused or stolen like passwords.
For most people, passkeys where they're offered and an authenticator app for everything else is a strong setup. A security key adds a separate physical item that has to be present, which suits people at higher risk.
Next steps
- Keep the passwords behind your accounts strong: how to create a strong password, or test one with our on-device Password Check.
- Storing passwords and passkeys in one place? See are password managers safe?
- See how your overall setup scores with our Security Check.
Sources
- About Security Keys for Apple Account — Apple Support (opens in a new tab)
- Use a security key for 2-Step Verification — Google Account Help (opens in a new tab)
- Advanced Protection Programme — Google (opens in a new tab)
- About Titan Security Keys — Google Titan Security Key Help (opens in a new tab)
- Sign in to your account with a security key — Microsoft Support (opens in a new tab)
- FIDO Passkeys: Passwordless Authentication — FIDO Alliance (opens in a new tab)
- What is a Passkey? — Yubico (opens in a new tab)
- Spare YubiKeys — Yubico (opens in a new tab)
- Passkeys: what you need to know — National Cyber Security Centre (opens in a new tab)
- Setting up 2-Step Verification (2SV) — National Cyber Security Centre (opens in a new tab)
Last checked: 22 September 2026
Optional · commercial links
Tools that can help
The steps above are free. If you would rather have a tool take care of it, these are the ones we link to.