Hardware security keys for two-factor authentication can make account sign-ins more resistant to phishing, but the right pick depends on your devices and the sign-in methods your accounts support. I rank the Yubico YubiKey 5 NFC as the best overall for its mix of USB-A, NFC, and broad authentication options. The Thetis Pro FIDO2 with USB-A, USB-C, and NFC suits people who want more connection choices, while the Thetis FIDO2 USB-A 2-Pack gives buyers a straightforward spare-key option. The main tradeoffs are FIDO2 support versus OTP-only use, device compatibility, and whether a compact design or multiple connection types matter more. Read on for the full breakdown and advice on choosing a key that fits your accounts and backup plan.
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Key Takeaways
- Connection flexibility separates the broadest picks: YubiKey 5 NFC and Thetis Pro models combine USB with NFC, while most Nano and folding models are limited to one USB connector.
- FIDO2 and U2F are the main phishing-resistant choices in this lineup: Symantec VIP is an OTP token, so its sign-in flow differs from browser-based security-key authentication.
- USB-C convenience depends on your actual devices: TrustKey T120 and Yubico Security Key C NFC fit USB-C equipment, but USB-A and NFC may matter for older computers or phones.
- Buying a pair addresses loss and lockout risk: The Thetis FIDO2 USB-A 2-Pack and Nano-C business 2-Pack make a registered spare easier to plan for.
- More features only help when accounts support them: Thetis Pro PinPlex and HyperFIDO HOTP add specialized options, but many buyers will get more practical value from a simpler FIDO2 key.
| Thetis FIDO2 Security Key, USB-A, 2-Pack | ![]() | Best for a Spare-Key Setup | Quantity: 2 keys | Connector: USB-A | Authentication standard: FIDO2 Level 1 | VIEW LATEST PRICE | See Our Full Breakdown |
| Yubico YubiKey 5 NFC Security Key | ![]() | Best for Protocol Versatility | Connection: USB-A, NFC | Authentication protocols: FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart Card (PIV), OpenPGP | Power: No batteries required | VIEW LATEST PRICE | See Our Full Breakdown |
| Symantec VIP Hardware Authenticator OTP Token | ![]() | Best for Symantec VIP OTP | Authentication standard: OATH-compliant TOTP | Code format: 6-digit OTP | Code indicator: Countdown time bar | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis Nano-C FIDO2 USB-C Security Key | ![]() | Best Compact USB-C Pick | Connector: USB-C | Dimensions: 0.73 × 0.60 × 0.30 inches | Standards: FIDO and FIDO2 | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis FIDO2 Security Key with Folding USB-A Design | ![]() | Best Folding USB-A Design | Authentication: FIDO2, U2F, HOTP | Interface: USB Type-A | Compatibility: Windows, macOS, Linux, Chrome OS | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis Nano-A FIDO2 USB-A Security Key | ![]() | Best for Passkey and TOTP Capacity | Interface: USB 2.0, USB Type-A | Standards: FIDO and FIDO2 | Authentication: Passkeys, OATH-TOTP, HOTP | VIEW LATEST PRICE | See Our Full Breakdown |
| TrustKey T110 FIDO2 and U2F USB-A Security Key | ![]() | Best for Straightforward PIN-and-Touch Sign-In | Authentication standards: FIDO2, U2F | Connector: USB Type-A | Verification: PIN and touch; non-biometric | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis FIDO U2F Security Key with Folding Aluminum Cover | ![]() | Best for Basic Website U2F | Connector: USB-A | Protocol: FIDO U2F only | Compatibility: Windows, macOS, and Linux with the latest Chrome | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis Pro FIDO2 Security Key with USB-A, USB-C, and NFC | ![]() | Best for Mixed USB and Mobile Devices | Authentication: FIDO2, HOTP | Connectors: USB-A, USB-C | NFC: Mobile authentication only; not supported on macOS or Windows | VIEW LATEST PRICE | See Our Full Breakdown |
| HyperFIDO Pro Mini U2F/FIDO2/HOTP Security Key | ![]() | Best for Compact Multi-Protocol Coverage | Authentication standards: FIDO2, FIDO U2F | One-time password support: OATH HOTP (event-based) | Design: Compact mini | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis Nano-C USB-C FIDO2 Security Key for Business, 2-Pack | ![]() | Best Two-Key USB-C Set | Pack size: 2 keys | Certification: FIDO2 Level 1 | Interface: USB Type-C | VIEW LATEST PRICE | See Our Full Breakdown |
| Thetis Pro FIDO2 Security Key with USB-A, USB-C, NFC, and PinPlex | ![]() | Best for Mixed Devices | Connectors: USB-A and USB-C | Wireless connectivity: NFC | Authentication standards: FIDO2, FIDO U2F, WebAuthn, CTAP2 | VIEW LATEST PRICE | See Our Full Breakdown |
| TrustKey T120 FIDO2 and U2F USB-C Security Key | ![]() | Best Simple USB-C Pick | Model: T120 | Authentication standards: FIDO2, U2F | Connection: USB-C | VIEW LATEST PRICE | See Our Full Breakdown |
| Yubico Security Key C NFC, USB-C and NFC, FIDO Certified | ![]() | Best Compact Phone-Friendly Key | Model: 100957 | Connectivity: USB-C and NFC | Authentication standards: FIDO2/WebAuthn and FIDO U2F | VIEW LATEST PRICE | See Our Full Breakdown |
| GoTrust Idem Key A USB-A and NFC Security Key | ![]() | Best Rugged USB-A Pick | Connectivity: USB-A and NFC | Certifications: FIDO2 Level 2; FIPS 140-2 Level 3 secure element; TAA compliant | Supported protocols: FIDO2, U2F, OTP, PIV, Mini Driver, smart card | VIEW LATEST PRICE | See Our Full Breakdown |
More Details on Our Top Picks
Thetis FIDO2 Security Key, USB-A, 2-Pack
The two-key bundle suits buyers who want a backup ready if their main key is lost, while keeping sign-in based on FIDO2 passkeys rather than codes that can be phished. Its rotating metal cover and resistance to water, crushing, and tampering make it a more rugged carry choice than the Thetis Nano-C, though that model is designed for USB-C devices and adds OATH-TOTP slots. Both require checking that a service and device support the chosen authentication method. This pair connects only through USB-A and has no NFC, so it is less flexible for phones than the YubiKey 5 NFC. PIN setup uses Thetis Manager App, and the listed Windows Hello and ID Austria limitations narrow its fit for some buyers. I’d choose it for compatible USB-A accounts where a ready spare matters more than mobile tap-in.
Pros:- Includes two FIDO2 Level 1 keys, providing a ready backup
- Supports passkeys and hardware-based authentication on compatible services
- Rotating metal cover and stated water, crush, and tamper resistance
- Needs no battery or network connection
Cons:- USB-A only, with no NFC for phone tap-in
- PIN setup depends on the Thetis Manager App
- Windows Hello and ID Austria support are limited
Best for: USB-A users who want a second FIDO2 key ready for account recovery and sign-in on compatible services
Not ideal for: People who mainly authenticate on NFC-equipped phones, need ID Austria, or expect broad Windows Hello support
- Quantity:2 keys
- Connector:USB-A
- Authentication standard:FIDO2 Level 1
- PIN setup:Thetis Manager App
- Durability:Water-, crush-, and tamper-resistant
- Power:No batteries required
- Network connectivity:Not required
- NFC:Not supported
Our verdict“Choose this pair if you want a durable USB-A FIDO2 key with a spare included and do not need NFC.”
Yubico YubiKey 5 NFC Security Key
The YubiKey 5 NFC is the broadest fit here for buyers who need one key to cover more than passkey sign-in: it supports FIDO2/WebAuthn, U2F, OTP, OATH codes, PIV smart card, and OpenPGP. That protocol range separates it from the more focused Thetis FIDO2 Security Key with Folding USB-A Design, which lists FIDO2, U2F, and HOTP. USB-A and NFC also give this YubiKey two ways to connect, making it more convenient across compatible computers and phones than USB-A-only options such as the Thetis FIDO2 Security Key, USB-A, 2-Pack. The tradeoff is that its many modes only help when the account or service supports them; compatibility still depends on the device and service. I’d favor it for people managing varied work and personal authentication needs, and pair it with a spare key to protect against lockout.
Pros:- Supports a broad range of authentication protocols, including PIV and OpenPGP
- Connects through USB-A or NFC
- Works without batteries or an internet connection
- Designed for phishing-resistant authentication
Cons:- Protocol support varies by service and device
- A spare key is recommended to reduce account lockout risk
Best for: People who need one hardware key for a mix of FIDO sign-in, OTP, smart-card, and OpenPGP workflows
Not ideal for: Buyers seeking a simple, narrowly focused passkey key or those whose devices and services do not support its protocols
- Connection:USB-A, NFC
- Authentication protocols:FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart Card (PIV), OpenPGP
- Power:No batteries required
- Internet connection:Not required
- Compatibility:Google, Microsoft, Apple, and 1,000+ accounts
- Phishing resistance:Designed for phishing-resistant authentication
Our verdict“Pick the YubiKey 5 NFC if you need broad protocol support and both USB-A and NFC connectivity.”
Symantec VIP Hardware Authenticator OTP Token
This token fits a specific authentication setup: it generates six-digit, time-based OTP codes for Symantec VIP Access, with a countdown bar to show when a code is nearing expiration. That makes it different from the Thetis FIDO2 Security Key, USB-A, 2-Pack, which uses FIDO2 hardware authentication and can work with a range of compatible services. This Symantec token needs no software installation, but it does not offer the broader provider compatibility listed for the YubiKey 5 NFC, or that key’s USB and NFC sign-in options. Its keychain-sized form is handy for people whose organization specifically requires VIP Access. The main tradeoff is provider lock-in: it is incompatible with other MFA providers, including Duo, Microsoft Entra ID, and Okta. I’d skip it unless Symantec VIP is already part of your account or workplace setup.
Pros:- Generates six-digit time-based OTP codes
- Countdown indicator shows the remaining code window
- Requires no software installation
- Portable keychain-sized design
Cons:- Works only with Symantec VIP Access
- Incompatible with other MFA providers, including Duo, Microsoft Entra ID, and Okta
Best for: Employees or account holders whose organization specifically uses Symantec VIP Access for OTP authentication
Not ideal for: People who want a reusable FIDO2 passkey key or need compatibility with Duo, Microsoft Entra ID, Okta, or other MFA providers
- Authentication standard:OATH-compliant TOTP
- Code format:6-digit OTP
- Code indicator:Countdown time bar
- Design:Portable keychain size
- Software installation:Not required
- Compatibility:Symantec VIP Access only
Our verdict“Choose this token only when Symantec VIP Access is the required OTP system for your accounts.”
Thetis Nano-C FIDO2 USB-C Security Key
At 0.73 × 0.60 × 0.30 inches, the Nano-C is the compact choice for buyers whose everyday devices use USB-C. It supports FIDO2 passkeys alongside WebAuthn, CTAP2, and OATH-TOTP, with capacity for 200 FIDO2 passkeys and 50 OATH-TOTP entries. Those slots add room for multiple credentials, while the Thetis FIDO2 Security Key with Folding USB-A Design is a better match for older USB-A ports. The Nano-C’s listed platform range includes Windows, Mac, Android, USB-C iPhone, and Linux, but compatibility still depends on the particular device, service, and operating system. Its Windows Hello requirement and lack of ID Austria support also limit its usefulness for some buyers. I’d pick it for a small USB-C carry key that can hold both passkeys and OTP entries, provided your services support them.
Pros:- Compact dimensions suit portable and keychain use
- Supports FIDO2 passkeys and passwordless sign-in
- Stores up to 200 FIDO2 passkeys and 50 OATH-TOTP entries
- Listed compatibility spans Windows, Mac, Android, USB-C iPhone, and Linux
Cons:- Compatibility varies by service, device, and operating system
- Windows Hello requires Enterprise edition with Entra ID
- ID Austria is not supported
Best for: USB-C laptop and mobile users who want a compact key with room for multiple FIDO2 passkeys and OATH-TOTP entries
Not ideal for: People with USB-A-only devices, ID Austria accounts, or Windows Hello setups outside the stated Enterprise and Entra ID support
- Connector:USB-C
- Dimensions:0.73 × 0.60 × 0.30 inches
- Standards:FIDO and FIDO2
- Authentication:WebAuthn, CTAP2, OATH-TOTP
- FIDO2 passkey slots:200
- OATH-TOTP slots:50
- Compatible platforms:Windows, Mac, Android, USB-C iPhone, Linux
- Limitations:Windows Hello requires Enterprise edition with Entra ID; ID Austria is not supported
Our verdict“Choose the Nano-C if your devices use USB-C and you want a compact key with both passkey and OTP capacity.”
Thetis FIDO2 Security Key with Folding USB-A Design
The folding aluminum cover gives this USB-A FIDO2 key a clear practical role: it protects the connector when carried loose on a keychain. The key supports passwordless FIDO2 sign-in, U2F, and HOTP, making it more versatile than a FIDO2-only description might suggest, though it does not match the broader protocol set of the YubiKey 5 NFC. It also lacks NFC, so the Thetis Nano-C is a better fit for USB-C devices and compatible mobile use. The listed operating systems include Windows, macOS, Linux, and Chrome OS, but FIDO2 does not support Mac login, and Windows Hello is limited to enterprise users with Azure Active Directory. I’d choose this model for a straightforward USB-A key that needs connector protection, while checking account and login compatibility first.
Pros:- Supports FIDO2 passwordless sign-in and U2F authentication
- HOTP adds another listed authentication method
- Rotating aluminum alloy cover protects the USB connector
- Listed compatibility includes Windows, macOS, Linux, and Chrome OS
Cons:- No NFC or USB-C connection
- FIDO2 does not support Mac login
- Windows Hello support is limited to enterprise users with Azure Active Directory
Best for: USB-A users who carry a hardware key on a keychain and want a folding cover plus FIDO2, U2F, and HOTP support
Not ideal for: USB-C or NFC-first users, or Mac owners expecting FIDO2 to log them into the computer itself
- Authentication:FIDO2, U2F, HOTP
- Interface:USB Type-A
- Compatibility:Windows, macOS, Linux, Chrome OS
- Material:Aluminum alloy cover
- Color:Black
- Dimensions:0.39 × 0.59 × 1.73 inches
Our verdict“Pick this folding key if you want a protected USB-A connector for compatible FIDO2, U2F, or HOTP sign-in.”
Thetis Nano-A FIDO2 USB-A Security Key
Its standout advantage is account capacity: the Nano-A holds up to 200 FIDO2 passkeys and 50 OATH-TOTP slots, giving people who manage many accounts room for both passwordless sign-in and one-time codes on a single key. Its tiny USB-A form also suits a keychain or a port where it can stay plugged in. Compared with the TrustKey T110, which focuses on FIDO2 and U2F with PIN and touch verification, this Thetis adds explicit TOTP support and a stated passkey-slot count. That makes it a better fit for someone consolidating credentials than for a buyer who wants only a basic second factor. The tradeoff is its older connector: devices without USB-A need an adapter, and passkey availability depends on each service.
Pros:- Stores up to 200 FIDO2 passkeys and 50 OATH-TOTP entries.
- Supports passwordless sign-in on compatible services.
- Very compact design suits keychain carry or staying in a USB-A port.
- Lists compatibility with Windows, macOS, iOS, Android, Linux, and Chrome OS.
Cons:- Requires a USB-A port or a separate adapter.
- Passkey support depends on the services and accounts being used.
Best for: People with many compatible accounts who want passkeys and OATH-TOTP in a compact USB-A key.
Not ideal for: USB-C-only laptop and phone owners who do not want to carry an adapter.
- Interface:USB 2.0, USB Type-A
- Standards:FIDO and FIDO2
- Authentication:Passkeys, OATH-TOTP, HOTP
- FIDO2 passkey slots:200
- OATH-TOTP slots:50
- Dimensions:0.25 × 0.74 × 0.25 in
- Compatible operating systems:Windows, macOS, iOS, Android, Linux, Chrome OS
Our verdict“Choose the Nano-A if credential capacity and both passkey and TOTP options matter more than having a newer connector.”
TrustKey T110 FIDO2 and U2F USB-A Security Key
The T110 keeps its job clear: FIDO2 and U2F protection with a PIN and a physical touch check. That combination gives buyers a deliberate confirmation step without biometric setup. Compared with the Thetis Nano-A, it has no stated passkey or TOTP slot capacities and does not list OATH-TOTP support, so it is less suited to storing a broader mix of credentials. Its appeal is a simpler authentication role across major browsers and desktop systems. The tradeoff is the USB-A connector and a non-biometric design; buyers seeking USB-C or NFC should look at options such as the TrustKey T120 or YubiKey 5 NFC instead. Smartphone and tablet compatibility is listed, but the connector still shapes which devices are convenient to use.
Pros:- Supports both FIDO2 and U2F authentication.
- PIN and touch provide separate verification steps.
- Works with Chrome, Firefox, Edge, and other major browsers.
- Listed for use with Windows, macOS, and Linux.
Cons:- USB-A connector may require an adapter on newer devices.
- No biometric authentication.
- No OATH-TOTP support is specified.
Best for: Desktop users who want FIDO2 and U2F sign-in with a PIN and touch confirmation, without biometric authentication.
Not ideal for: People who need USB-C or NFC access, or want built-in biometric verification.
- Authentication standards:FIDO2, U2F
- Connector:USB Type-A
- Verification:PIN and touch; non-biometric
- Compatible devices:Personal computers, smartphones, tablets
- Operating systems:Windows, macOS, Linux
- Supported browsers:Chrome, Firefox, Edge, and others
- Color:Black
Our verdict“Pick the T110 for direct PIN-and-touch FIDO2 or U2F use on USB-A computers.”
Thetis FIDO U2F Security Key with Folding Aluminum Cover
This Thetis is the lineup’s focused, old-school option: it adds FIDO U2F to compatible websites and wraps the USB-A connector in a rotating aluminum cover. That cover gives the connector physical protection during carry, while the protocol limitation keeps the choice simple for buyers whose services support U2F. Compared with the Thetis Nano-A, it lacks FIDO2 passkeys and OATH-TOTP, so it cannot serve the same broader mix of sign-in methods. Its compatibility is also narrower: the listed setup calls for the latest Chrome on Windows, macOS, or Linux, and it does not work with common email clients such as Outlook or Apple Mail. Choose it for basic web account protection, but skip it if you need flexible app or email support.
Pros:- Adds U2F authentication for compatible websites.
- Rotating aluminum cover protects the USB connector during carry.
- Compact form is easy to transport.
- Works with the latest Chrome on Windows, macOS, and Linux.
Cons:- Supports U2F only, with no FIDO2 or OTP options.
- Not compatible with Apple Mail, Mozilla Thunderbird, or Microsoft Outlook.
- Listed compatibility is limited to the latest Chrome on specified desktop systems.
Best for: A buyer who needs a compact USB-A U2F key for compatible websites used through Chrome.
Not ideal for: People who need FIDO2 passkeys, OTP methods, email-client support, or broad browser flexibility.
- Connector:USB-A
- Protocol:FIDO U2F only
- Compatibility:Windows, macOS, and Linux with the latest Chrome
- Construction:Aluminum alloy
- Design:360° rotating protective cover
- Email client support:Not compatible with Apple Mail, Mozilla Thunderbird, or Microsoft Outlook
Our verdict“Choose this key for basic U2F website protection if its Chrome and USB-A limits match your setup.”
Thetis Pro FIDO2 Security Key with USB-A, USB-C, and NFC
Three connection options give the Thetis Pro a practical advantage for buyers who move between older USB-A computers, USB-C devices, and NFC-capable mobile devices. It supports FIDO2 authentication and HOTP, and its battery-free design avoids charging or network dependence. Compared with the Thetis Nano-A, it trades the Nano-A’s stated passkey and TOTP slot counts for more connector flexibility, including mobile NFC. The limits are specific: NFC does not work on macOS or Windows, and Windows Hello login requires a compatible Enterprise edition. Its listed dimensions also make it larger than a tiny Nano-style key. I’d choose it for a mixed-device routine, but buyers using only USB-C computers may prefer a dedicated USB-C key without the extra connector choices.
Pros:- Supports USB-A, USB-C, and NFC authentication on compatible mobile devices.
- Works with FIDO2 and HOTP.
- Battery-free operation needs no charging or network connection.
- Rotating metal cover protects the connector.
Cons:- NFC is not supported on macOS or Windows.
- Windows Hello login requires a compatible Windows Enterprise edition.
- Larger than the Nano-A form factor.
Best for: People who switch between USB-A and USB-C computers and want NFC authentication on compatible mobile devices.
Not ideal for: Users who expect NFC to work with Windows or macOS, or need Windows Hello on a non-Enterprise edition.
- Authentication:FIDO2, HOTP
- Connectors:USB-A, USB-C
- NFC:Mobile authentication only; not supported on macOS or Windows
- Compatibility:Windows, macOS, Linux, Chrome OS
- Dimensions:2.9 × 0.72 × 0.5 in
- Design:Rotating metal cover; battery-free
- Read and write speed:480 bytes per second
Our verdict“Choose the Thetis Pro if one key needs to bridge USB-A, USB-C, and compatible NFC phones.”
HyperFIDO Pro Mini U2F/FIDO2/HOTP Security Key
The HyperFIDO Pro Mini combines FIDO2, U2F, and OATH HOTP in a compact design, covering modern sign-in, legacy U2F services, and event-based one-time passwords. That breadth gives it a different role from the Thetis FIDO U2F key, which is limited to U2F, and the TrustKey T110, whose supplied details do not specify HOTP. The product data, however, leaves out its connector, operating-system compatibility, capacity, and physical dimensions. That makes it harder to tell whether it will fit a particular laptop or how easily it can travel. I’d shortlist it for its stated protocol mix, but buyers who need a clear USB-C or NFC fit should compare it with the Thetis Pro before choosing.
Pros:- Supports FIDO2 authentication.
- Includes FIDO U2F for compatible services.
- Adds event-based OATH HOTP support.
- Described as a compact mini key.
Cons:- Connector type is not specified in the supplied product data.
- Operating-system and browser compatibility are not specified.
- No capacity or detailed physical dimensions are provided.
Best for: Buyers seeking a compact key with FIDO2, U2F, and event-based HOTP support across services that accept those standards.
Not ideal for: People who need confirmed connector, operating-system, or NFC compatibility before buying.
- Authentication standards:FIDO2, FIDO U2F
- One-time password support:OATH HOTP (event-based)
- Design:Compact mini
Our verdict“Consider the HyperFIDO Pro Mini for its three stated authentication methods if its unspecified connection and compatibility details suit your setup.”
Thetis Nano-C USB-C FIDO2 Security Key for Business, 2-Pack
Two keys in one pack make this a practical choice for people who want a primary key and a backup for compatible accounts. Its small USB-C design fits newer laptops and phones, while the Manager App adds PIN setup and TOTP/HOTP options that the simpler TrustKey T120 does not list. That extra flexibility comes with a narrower connection choice: there is no NFC, so phone sign-in depends on having an accessible USB-C port. It also lacks the broad connector mix of the Thetis Pro FIDO2 Security Key with USB-A, USB-C, NFC, and PinPlex. I’d choose this set for USB-C users who value a spare and app-based authentication tools, but buyers relying on tap-to-authenticate or Windows Hello should check the stated compatibility limits first.
Pros:- Includes two keys, allowing a separate backup
- Supports FIDO2 passkeys and MFA on compatible services
- Compact form factor suits keychain carry
- Manager App supports PIN setup and TOTP/HOTP
Cons:- No NFC for tap-based phone authentication
- Windows Hello requires compatible Windows Enterprise with Entra ID
- ID Austria is not supported
Best for: USB-C laptop and phone owners who want a spare FIDO2 key and TOTP/HOTP features in the same package.
Not ideal for: People who need NFC sign-in, USB-A support, or Windows Hello outside a compatible Windows Enterprise and Entra ID setup.
- Pack size:2 keys
- Certification:FIDO2 Level 1
- Interface:USB Type-C
- Additional authentication:TOTP/HOTP
- Compatible devices:USB-C PCs, Macs, iPhones, and Android devices
- Dimensions:0.73 x 0.60 x 0.30 inches
- NFC:Not supported
Our verdict“Choose this two-key set if your devices use USB-C and you want a backup plus TOTP/HOTP support; skip it if NFC is essential.”
Thetis Pro FIDO2 Security Key with USB-A, USB-C, NFC, and PinPlex
USB-A, USB-C, and NFC give this key the widest connection range among these five picks, making it easier to use across older computers, newer laptops, and NFC-capable devices. Its support for FIDO2, U2F, PIV, TOTP, and HOTP also covers more authentication workflows than the focused Yubico Security Key C NFC, which does not support one-time passwords. That breadth can matter for users managing both everyday account sign-ins and certificate-based access. The tradeoff is that broader support does not guarantee compatibility with every service, so checking a specific account or platform is still necessary. Windows Hello has a stated Enterprise and Entra ID requirement, and ID Austria is unsupported. I’d pick it for mixed-device households or IT users who need several authentication methods in one key.
Pros:- Connects through USB-A, USB-C, or NFC
- Supports passwordless FIDO2 passkey login
- Adds PIV certificates and TOTP/HOTP options
- PinPlex provides a complex PIN system
Cons:- Windows Hello requires Enterprise edition with Entra ID
- ID Austria is not supported
- Compatibility should be checked for each intended service
Best for: People switching between USB-A and USB-C computers who also need NFC and a mix of passkey, certificate, and OTP methods.
Not ideal for: Buyers who need ID Austria support or want a straightforward key without checking service-specific compatibility.
- Connectors:USB-A and USB-C
- Wireless connectivity:NFC
- Authentication standards:FIDO2, FIDO U2F, WebAuthn, CTAP2
- Additional authentication:PIV certificates, TOTP, HOTP
- PIN protection:PinPlex complex PIN system
- Windows Hello requirement:Enterprise edition with Entra ID
- ID Austria support:Not supported
Our verdict“Pick the Thetis Pro if you need multiple connection types and authentication methods, and can verify your services support them.”
TrustKey T120 FIDO2 and U2F USB-C Security Key
The TrustKey T120 keeps its job clear: it provides FIDO2 and U2F sign-in through USB-C, with a PIN and physical touch required to approve authentication. That makes it a more focused option than the Thetis Pro, which adds NFC, PIV, and OTP methods for buyers with more varied needs. The T120’s support for Windows, macOS, Linux, and major browsers gives it useful platform reach, but the actual connection remains limited to a USB-C port. There is no biometric authentication, and each sign-in requires both PIN entry and touch. I’d choose it for someone who wants a direct hardware-key flow on USB-C computers; people using USB-A machines or expecting tap-based phone use should look at options such as the GoTrust Idem Key A instead.
Pros:- Supports FIDO2 and U2F authentication
- PIN and touch provide an explicit approval step
- Works with Windows, macOS, and Linux
- Compatible with major browsers and online services
Cons:- Requires an available USB-C port
- Every authentication requires both PIN and touch
- Does not offer biometric authentication
Best for: USB-C computer users who want a straightforward FIDO2/U2F key with PIN-and-touch approval across major desktop systems.
Not ideal for: People with USB-A-only computers, those seeking NFC authentication, or buyers who prefer biometric approval.
- Model:T120
- Authentication standards:FIDO2, U2F
- Connection:USB-C
- Authentication method:PIN and touch; non-biometric
- Operating system compatibility:Windows, macOS, Linux
- Browser compatibility:Chrome, Firefox, Edge, and other major browsers
Our verdict“Choose the T120 for uncomplicated USB-C sign-ins on desktop systems; choose an NFC-capable key for phones or USB-A devices.”
Yubico Security Key C NFC, USB-C and NFC, FIDO Certified
USB-C plus NFC makes this Yubico key a compact choice for securing accounts across a laptop and compatible phone: plug it into one device or tap it against the other. Its FIDO2/WebAuthn and U2F support focuses on phishing-resistant sign-in, while the GoTrust Idem Key A offers a wider protocol set that includes OTP and PIV. This model keeps the feature set narrower: it does not support one-time passwords or the Yubico Authenticator app. That makes it a better fit for buyers who want a simple passkey and security-key workflow than for anyone needing a general-purpose authentication token. Its waterproof, crush-resistant construction and lack of battery or internet requirements suit everyday carry, though buyers with USB-A-only computers will need another connector option.
Pros:- Offers both USB-C and NFC authentication
- Supports FIDO2/WebAuthn and FIDO U2F
- Requires no batteries or internet connection
- Waterproof and crush-resistant construction
Cons:- Does not support one-time passwords
- Not compatible with the Yubico Authenticator app
- USB-A computers require an adapter or another key
Best for: People who want one compact FIDO key for USB-C computers and NFC-capable phones, with durable everyday carry.
Not ideal for: Buyers who need OTP codes, the Yubico Authenticator app, or USB-A connectivity.
- Model:100957
- Connectivity:USB-C and NFC
- Authentication standards:FIDO2/WebAuthn and FIDO U2F
- Firmware:5.7
- Weight:0.16 ounces
- Dimensions:0.1 x 1.8 x 0.7 inches
- Waterproof:Yes
- One-time password support:No
Our verdict“Choose this Yubico key for durable USB-C and NFC passkey authentication, but select a broader token if OTP support matters.”
GoTrust Idem Key A USB-A and NFC Security Key
The GoTrust Idem Key A suits buyers whose computers still rely on USB-A but who also want NFC for supported phones. Its listed FIDO2 Level 2 certification and FIPS 140-2 Level 3 secure element set it apart from the TrustKey T120, which uses USB-C and lists FIDO2 and U2F standards. GoTrust also covers OTP, PIV, and smart-card protocols, so it can serve more authentication roles than the focused Yubico Security Key C NFC. The tradeoff is its USB-A connector: newer USB-C-only laptops need an adapter, while phone use depends on NFC compatibility. Its IP68-rated, crush-resistant build and battery-free operation favor people who carry a key in demanding conditions. I’d choose it for rugged USB-A setups that benefit from broader protocol support.
Pros:- Supports USB-A and NFC authentication
- FIDO2 Level 2 certified with a FIPS 140-2 Level 3 secure element
- Supports FIDO2, U2F, OTP, PIV, and smart-card protocols
- IP68-rated, crush-resistant design needs no batteries, software, or drivers
Cons:- USB-A connector may require an adapter for newer computers
- NFC use depends on a compatible device
- Its broader protocol set may be unnecessary for buyers seeking only passkey sign-in
Best for: People using USB-A computers who want NFC phone access, broad protocol support, and a rugged, battery-free key.
Not ideal for: Owners of USB-C-only computers without an adapter, or buyers whose phones lack NFC support.
- Connectivity:USB-A and NFC
- Certifications:FIDO2 Level 2; FIPS 140-2 Level 3 secure element; TAA compliant
- Supported protocols:FIDO2, U2F, OTP, PIV, Mini Driver, smart card
- Ingress protection:IP68 waterproof and dustproof
- Compatibility:Windows, macOS, iPhone, Android, Chromebook
- Browser support:Chrome, Safari, Edge
- Power:No batteries required
Our verdict“Choose the GoTrust for rugged USB-A and NFC use with broad protocol support; skip it if your devices are USB-C-only.”

How We Picked
I ranked these keys by how well their listed authentication methods and connection options serve two-factor sign-ins across common personal and work devices. I gave more weight to FIDO2 and U2F support because these standards enable security-key sign-in flows, then considered USB-A, USB-C, and NFC flexibility, compactness, protective design, and whether a pack includes a spare. OTP models remain relevant for services that use token codes, but their different sign-in flow keeps them below versatile FIDO2 choices for this roundup’s central use case.
The order reflects practical fit rather than a claim that one key works with every account. A key’s value depends on whether the services a buyer uses accept its protocol and whether its connector fits their devices. I placed flexible, broadly useful models ahead of narrower USB-only and specialty designs, while distinguishing paired keys and compact options by the buyers they suit. Product names and listed features alone do not establish compatibility with every service, so I recommend checking account requirements before choosing.
Factors to Consider When Choosing Hardware Security Keys For Two-factor Authentication
Choosing a security key starts with your account recovery and device setup, not the number of features on the package. These broader decisions can prevent a key from becoming an inconvenience or a single point of lockout.
Check the sign-in method each account accepts
Security keys can work through different standards and sign-in flows, and a service may support some without supporting all. Before buying, check the security settings for your most important email, password manager, work, and financial accounts. FIDO2 or U2F support is a strong fit when a service allows a registered key to approve sign-in directly. OTP tokens generate codes, which can serve accounts built around one-time passwords but do not provide the same security-key flow. A common mistake is choosing by the word “hardware” alone without checking the account’s supported method. If one key must cover many services, favor a widely supported standard and verify each account first.
Match connectors to the devices you actually use
List the computers and phones where you expect to sign in, including any older device you still rely on. USB-A, USB-C, and NFC solve different access problems, and a connector that never fits your daily devices adds friction. NFC can be useful for compatible phones, while USB can be the simpler route on laptops and desktops. An adapter may bridge a connector gap, but it adds another small item to carry and can be awkward in a hurry. Buyers often focus on their newest computer and forget a work machine or tablet. Choose around your full device mix, and check phone and operating-system support with the services you use.
Plan for a lost key before you need to recover
A security key can become a point of lockout if it is the only sign-in method registered to an account. A spare key helps only after you add it to the accounts that matter and store it somewhere separate from your everyday key. Some services also offer recovery codes or alternate verification methods; learn those steps while you still have access. Do not assume that buying a two-pack automatically creates a backup. For work accounts, check whether your administrator controls enrollment or recovery. A little setup time up front can make a lost key a manageable inconvenience instead of an account crisis.
Decide whether compactness or protection matters more
Small keys are convenient to leave in a laptop bag or carry on a key ring, but their size can make them easier to misplace. Folding covers and protective designs can help shield a connector in transit, while a Nano-style key can sit close to a device with little protrusion. Neither design removes the need to protect the key from loss, moisture, or rough handling. A permanently inserted Nano key may also be less convenient if you move it among devices. Think about where the key will live most of the time and how often you remove it. The best form is the one you can keep available without accidentally leaving it behind.
Pay for features that change your real sign-in routine
Extra connection types and authentication features can be useful, but only when your devices and services can use them. NFC may be worth prioritizing if you sign in on a compatible phone, while a second USB connector helps when you switch between computer ports. Specialized features such as HOTP or PinPlex may suit a particular workflow, yet they can add complexity for someone who only needs FIDO2 sign-in. Before paying for a more feature-rich design, identify the specific account or device that needs each extra. A simpler key can be easier to manage and less confusing to register. Match added capabilities to an actual use case rather than treating the longest feature list as the best fit.
Separate personal setup from workplace requirements
Work accounts may have enrollment rules, approved models, or recovery processes set by an administrator. A key that works with a personal email account may not satisfy an organization’s policy. Ask whether your employer requires a particular standard, device certification, or managed enrollment before buying for work. If you use one key for both personal and company accounts, check whether that is allowed and how access will be handled when you change roles. Keep personal recovery methods under your control and follow workplace rules for company access. This check can prevent buying a technically capable key that your work system will not accept.
Frequently Asked Questions
Should I choose a FIDO2 key or an OTP token?
Choose based on the sign-in method your accounts support. FIDO2 and U2F keys are designed for direct security-key authentication and can provide phishing-resistant sign-in when the service supports that flow. An OTP token supplies a code for services configured to accept one-time passwords, as with the Symantec VIP model in this lineup. A code-based flow may fit a particular organization or account, but it is not interchangeable with FIDO2. Check the security settings of the accounts you most need to protect before deciding.
Is one security key enough, or should I register a spare?
A spare is a sensible choice if losing access to your email, password manager, or work account would cause serious disruption. Register both keys with each important account while you have the primary key available, then store the spare separately. A second key that has not been enrolled cannot help you sign in. Also save any account recovery codes in a secure place and learn the service’s recovery process. If a service has no workable backup path, consider that limitation before making a key your only sign-in method.
Do I need NFC if my key has USB?
NFC is useful when you want to tap a compatible phone instead of connecting a key by USB. If you mainly sign in on a laptop with a matching port, a USB-only model may suit your routine. Phone compatibility can vary by device, operating system, browser, and service, so check those details rather than assuming NFC will work everywhere. A USB-A and NFC key can be flexible across older computers and supported phones, while USB-C and NFC may fit newer equipment better. Choose NFC for a phone workflow you expect to use, not just as an unused extra.
Can one hardware key protect all of my accounts?
One key can be registered with multiple accounts when those services support its authentication method, but it cannot make an unsupported service accept a security key. Some accounts may use FIDO2, others may rely on OTP codes, and some may offer only app-based or text-based verification. Review each account’s security options and recovery process individually. If you manage work and personal accounts, confirm whether your employer permits using the same key for both. For high-impact accounts, register a spare as well so one lost device does not affect everything at once.
What should I do if none of my devices has the key’s connector?
First check whether the key supports another route, such as NFC on a compatible phone. An adapter may work for some USB connector combinations, but it adds something to carry and does not guarantee that every device or sign-in flow will cooperate. Confirm the adapter and device can support the key’s intended use before relying on that setup. If you sign in across several devices, a key with both USB-A and USB-C or a suitable NFC option can reduce connector hassles. Keep at least one working sign-in and recovery method available while changing your setup.
Conclusion
For the best overall balance in this lineup, I recommend the Yubico YubiKey 5 NFC for buyers who want USB-A, NFC, and a broad set of authentication options. The best value for planned redundancy is the Thetis FIDO2 Security Key USB-A 2-Pack, provided USB-A fits your devices and your accounts accept FIDO2. Beginners who want a direct, familiar setup can start with a straightforward FIDO2 or U2F model after confirming account support; the TrustKey T110 is a USB-A option, while the TrustKey T120 suits USB-C devices. For a premium feature mix, compare the Thetis Pro models and choose PinPlex only if its added capability fits your workflow. If you need an OTP code rather than a FIDO2 sign-in, the Symantec VIP token serves a different need; for phone use, prioritize a compatible NFC key. The right choice is the one your accounts accept, your devices can use, and your recovery plan can support.
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.















