← Back to glossary
🔑

Hardware Security Key

Authentication

Roaming authenticator implementing FIDO2/WebAuthn over USB/NFC/BLE.

Definition

A hardware security key is a roaming authenticator that stores private keys and signs authentication challenges. It often supports user presence (tap) and optional user verification (PIN/biometric).

In plain English Roaming authenticator implementing FIDO2/WebAuthn over USB/NFC/BLE.

Why this matters

Why it matters: It provides strong phishing resistance and mitigates credential stuffing and SIM-swap risks compared to SMS codes.

Example

Example: Register two keys (primary + backup) and keep recovery codes offline.