The Good News: You Cannot Really Pick Wrong
Every certified FIDO2 key delivers the headline benefit identically: phishing proof login, because the key validates the real domain cryptographically before it ever answers a login request, the mechanism explained in full in our FIDO2 explainer. A ten dollar key and a seventy dollar key are equally unphishable at the core protocol level. What you are actually choosing between is connectors for your specific devices, extra protocols beyond FIDO2, build quality, and brand trust. Whether you need a key at all is a separate question our hardware key guide covers in depth.
FIDO2 Versus Older U2F-Only Keys
One distinction matters more than brand: FIDO2 or WebAuthn support versus older U2F-only hardware. U2F was the first generation standard, and it still works for classic second-factor login on sites that support it, but it cannot store resident credentials, which means it cannot function as a full passkey for passwordless sign-in. FIDO2 is a superset that adds that capability. Nearly everything sold new today is FIDO2 certified, but secondhand or very old stock can still be U2F-only, so check the listing explicitly before buying if you plan to use passkeys, not just old-style two-factor codes, since that is where the practical gap actually shows up.
The Contenders
YubiKey 5 Series (The Full Featured Standard)
The keys everyone else gets benchmarked against. Beyond FIDO2 and WebAuthn, they also speak TOTP storage (dozens of authenticator entries living directly on the key itself, read through the companion Yubico Authenticator app), Smart Card and PIV, OpenPGP, and the legacy Yubico OTP protocol. Variants cover USB-A, USB-C, Lightning, and NFC in various combinations, including tiny Nano versions meant to live permanently in a laptop's port. Priced accordingly, generally in the fifty to seventy dollar range depending on connector and NFC. Buy this one specifically if you want a single device that carries your TOTP codes in hardware and also handles enterprise or developer protocols like PIV smart card login.
Yubico Security Key Series (The Right Default for Most People)
Yubico's budget line strips things down to FIDO2, WebAuthn, and NFC, minus the extra protocols above. For protecting Gmail, Microsoft accounts, GitHub, social media, and exchange accounts, it does everything that actually matters at roughly half the flagship price, typically in the twenty five to thirty dollar range. This is the correct first key for most people, full stop, and the extra protocols on the 5 series are genuinely unnecessary for anyone who is not also using a key for enterprise smart card login or PGP signing.
Google Titan (The Google-Ecosystem Pick)
Google's own keys, sold in USB-A plus NFC and USB-C plus NFC configurations, are solid FIDO2 devices with generous passkey storage capacity, priced competitively with Yubico's budget line. They are a natural fit for heavy Google account users and anyone enrolled in Google's Advanced Protection Program, which in some configurations specifically expects Titan or another certified key. No TOTP storage and no extra protocols beyond FIDO2 and U2F compatibility.
SoloKeys (The Open Source Option)
SoloKeys is a fully open source hardware and firmware project, meaning both the circuit design and the code running on the key are publicly auditable rather than a black box, which matters to buyers who want the same transparency principle from Bitwarden or KeePass applied to their hardware key too. Pricing sits in the budget-to-mid range, generally cheaper than a YubiKey 5 but comparable to or slightly above the Yubico Security Key. Firmware updates and community support move slower than a company the size of Yubico or Google, which is the realistic trade for openness, but the core FIDO2 certification means the cryptography itself is standard regardless.
Budget Certified Keys (Thetis, Token2, TrustKey, and Similar)
Legitimate FIDO2 certified keys exist for well under twenty dollars, and certification means the underlying cryptography meets the same standard as the expensive options. The trade-offs are build quality, documentation quality, and company longevity, not security. These are fine as backup keys, or for outfitting an entire family affordably where a name brand is not essential; buy from official channels regardless of which brand you choose.
The Comparison Table
| Key | FIDO2 | NFC | TOTP storage | Extra protocols | Open source | Price band |
|---|---|---|---|---|---|---|
| YubiKey 5 series | Yes | Most models | Yes | PIV, PGP, OTP | No | Premium |
| Yubico Security Key | Yes | Yes | No | None | No | Mid |
| Google Titan | Yes | Yes | No | None | No | Mid |
| SoloKeys | Yes | Some models | No | None | Yes, hardware and firmware | Budget to mid |
| Budget certified | Yes | Varies | Rarely | Varies | Varies | Low |
How to Actually Choose
- Match connectors to your life. A modern laptop plus an Android phone or iPhone: USB-C with NFC covers essentially everything, since NFC taps handle the phone side. An older desktop: USB-A. Heavy iPhone user who wants a wired option instead of a tap: Lightning exists in the YubiKey line specifically.
- Decide on TOTP-on-key. If carrying your authenticator codes physically in hardware, surviving a phone loss entirely, genuinely appeals to you, that is YubiKey 5 exclusive territory, paired with the Yubico Authenticator app. Otherwise save the money and go with the plain Security Key or Titan line.
- Buy two, not one. This is not optional advice, it is the actual rule: one key on your keychain for daily use, one registered on every account and stored somewhere physically separate, like a drawer at a family member's house rather than your own desk. The lost-key story with a working backup is a minor errand; without one it becomes our recovery playbook in full, which is a far worse afternoon.
- Buy from official channels only. Manufacturer stores or authorised resellers, nothing else. Security hardware bought from an unverified third party marketplace listing is a supply chain risk you do not need to accept for a twenty dollar savings.
The common sizing mistake is buying the premium key first and telling yourself the backup key comes "later." Two mid-range keys registered together beat one flagship key with no backup, every single time. The registration effort per account is identical either way, so there is no real cost to doing it right from the start.
Setting Up Whichever You Buy
The flow is nearly identical across every site that supports security keys: security settings, then two-factor or passkeys, then add security key, then insert and touch. Do email accounts first, since email is the master key to resetting everything else (Gmail, Microsoft), then finance, then everything else in whatever order matters to you. Register both keys on every account in the same sitting rather than coming back later; verify your browser handles WebAuthn correctly first with our passkey tester. Keep TOTP or printed backup codes as the fallback layer underneath each account regardless (stored properly), because a key and its backup can both be lost in the same house fire or theft.
Frequently Asked Questions
Do these keys work with iPhones?
Yes: NFC keys tap against the top edge of the phone, and USB-C or Lightning keys plug in directly depending on the phone model. iOS supports FIDO2 natively in both Safari and third party apps that implement WebAuthn.
Are keys with built in fingerprint readers, the "bio" versions, worth the extra cost?
They add user verification directly on the key itself, which is nice for shared computers and certain passwordless flows, at a real price premium over the standard model. For most personal use, the simple touch-plus-PIN model of a standard key is entirely sufficient; the account's own policy decides when a PIN is demanded regardless of which key you use.
How many accounts fit on one key?
For standard security key login, effectively unlimited, since the key derives a unique per-site credential mathematically rather than storing a separate entry for each account. Stored items do have real limits: resident passkeys and TOTP entries have per-model storage capacities, which mainly matters for passkey-everything power users, and the manufacturer's spec sheet states the exact numbers for each model.
What is the gold or silver disc actually checking when I touch it?
Nothing biometric on a standard key; it is a simple presence test proving a human is physically at the device in that moment, so malware running on the computer cannot invoke the key silently in the background without a person there. The cryptographic operation happens inside the key regardless of the touch; the touch itself is purely consent.
Can one key serve an entire family?
Technically a single key can hold credentials for many different people's accounts, but sharing one physical key defeats the entire possession factor, since whoever is holding it at any moment effectively is everyone. Budget certified keys make per-person ownership genuinely affordable, so the sharing shortcut is not worth taking even to save money.
Is a key with more protocols always the better buy?
No. Extra protocols like PIV smart card and OpenPGP on the YubiKey 5 line are valuable specifically for developers, IT administrators, and anyone doing certificate-based authentication or email signing; for everyone else they sit unused while you pay a premium for silicon you never touch. Buy the simpler Security Key or Titan line unless you already know you need one of those specific extra protocols.