Skip to content
Digital Life Check

What is a security key, and do you need one?

A security key is a small physical device that proves it's you when you sign in. It's the form of two-step verification that fake websites can't fool. Here's who it's for.

Written by
Digital Life Check editorial team
Last checked
On this page
  1. How a security key works
  2. Why fake websites can't fool it
  3. Who benefits most
  4. Which accounts support them
  5. Why you should buy two
  6. If you lose a key
  7. Choosing the right connector
  8. Passkeys: the free alternative
  9. Next steps

Quick answer: a security key is a small physical device that you plug into your computer or tap against your phone to prove it's you when you sign in. It's the most phishing-resistant form of two-step verification, because it won't work on a fake website. Most people are well protected with passkeys and an authenticator app. A key is an extra step up for people at higher risk. If you get one, buy two.

How a security key works

A security key is one way of doing the second step of two-factor authentication. Instead of typing a code from a text message, you plug the key in or hold it near your phone and touch it when asked.

Apple describes a security key as "a small external device that looks like a flash drive or tag". Microsoft adds that you also confirm with a fingerprint or PIN, so "even if someone has your security key, they won't be able to sign in without your fingerprint or PIN".

Security keys work on open standards set by the FIDO Alliance, an industry group. You may see the terms FIDO2 and WebAuthn on the packaging or in account settings. They're the technical names for the same system that passkeys use, so a key and a website can recognise each other without you doing anything special.

A key can also hold passkeys. The FIDO Alliance says passkeys stored on a hardware security key "offer the highest security assurance", and Yubico says one of its keys can hold up to 25 passkeys. These passkeys stay on that one key and don't sync to your other devices.

Why fake websites can't fool it

A common way accounts get taken over is phishing: a fake login page that looks like your bank or email. You type your password and a text message code, and the criminal passes both on to the real site.

A security key stops this. The FIDO Alliance explains that each login is tied to the website it was created for and only works there. If you're on a lookalike site, the key won't produce a valid login, however convincing the page looks. There's no code to read out or type in, so there's nothing for a scammer to trick you into handing over.

If you've already typed your details into a page you're not sure about, see what to do if you clicked a scam link.

Who benefits most

Apple calls its security key feature an optional extra "designed for people who want extra protection from targeted attacks, such as phishing or social engineering scams". People who might fit that description include:

  • anyone whose name or job makes them a likely target, such as public figures
  • people who manage money or accounts for someone else, such as an elderly parent
  • anyone who has already been targeted, or whose account has been taken over before

Google offers the Advanced Protection Programme for people "with high visibility and sensitive information" who face targeted online attacks. To join, you sign in with a passkey or a security key.

Which accounts support them

These all let you add a security key to your account:

AccountWhat the company says
GoogleSecurity keys can be used with 2-Step Verification on your Google Account
Apple AccountWorks with any FIDO Certified key; you must add at least two and can add up to six
Microsoft accountSupports FIDO2 keys, either USB keys you plug in or NFC keys you tap

Apple's version has some limits. Every device signed in to your Apple Account needs iOS 16.3, iPadOS 16.3, macOS Ventura 13.2 or later, and child accounts and Managed Apple Accounts aren't supported.

Many other services also accept security keys. Look under Security, Sign-in or Two-step verification in each account's settings.

Why you should buy two

A key is a physical object, so you can lose it. Apple won't let you turn the feature on without registering at least two keys, and suggests keeping one at home and one at work.

Yubico, which makes security keys, recommends registering your spare at the same time as your main key. That way you only have to visit each account once, and you can't lose the first key before the spare is set up.

If you lose a key

  1. Sign in with your spare key, or another second step you've set up.
  2. Remove the lost key from the account's security settings, so it can't be used.
  3. Register a replacement as soon as you can.

Keep a second way in for every account, such as a passkey on your phone or backup codes. The NCSC says backup codes are ideal because they work even if you lose your phone, and each one works once. Store them somewhere safe and offline.

Without a backup, recovery gets harder. Google says account recovery can take 3 to 5 business days while it checks it's you. Apple warns that if you lose all your trusted devices and security keys, "you could be locked out of your account permanently".

Choosing the right connector

Keys come with different plugs, and some have more than one. Match the key to the devices you use:

ConnectorWorks with
USB-CiPhone 15 or later and most Mac models, according to Apple; check the ports on your other devices
LightningiPhone 14 and most earlier iPhones
USB-AOlder Mac models, and computers with the larger rectangular USB port
NFC (tap)Phones with NFC, including Android phones; for an Apple Account, Apple says NFC keys only work with iPhone

Several companies make security keys. YubiKey, made by Yubico, and Google's Titan Security Key are two examples. Look for one that's FIDO Certified.

Passkeys: the free alternative

You don't need to buy anything to get phishing-resistant sign-in. A passkey saved on your phone or computer works in a similar way, and you unlock it with your face, fingerprint or screen PIN.

The NCSC recommends passkeys over passwords wherever they're available, and says they're resistant to phishing because they can't be intercepted, reused or stolen like passwords.

For most people, passkeys where they're offered and an authenticator app for everything else is a strong setup. A security key adds a separate physical item that has to be present, which suits people at higher risk.

Next steps

Sources

Last checked: 22 September 2026

Optional · commercial links

Tools that can help

The steps above are free. If you would rather have a tool take care of it, these are the ones we link to.

  • Passwords

    Are password managers safe?

    A password manager is much safer than reusing the same few passwords. Here's how they keep your passwords protected, where the real risks are, and how to choose one.

    Last checked 22 September 2026

  • Passwords

    What is two-factor authentication (2FA)?

    Two-factor authentication adds a second check when you log in, so a stolen password isn't enough. Start with your email account.

    Last checked 22 September 2026