Hardware security key guides
Plan primary and backup security keys, travel use and loss recovery for phishing-resistant authentication.
How to use this section
Use the Hardware security key guides directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
Hardware keys are most useful when there is a backup key and a documented loss plan. Register keys on the highest-impact accounts first and keep the spare away from the everyday device.
FIDO2 vs U2F Security Keys
Understand modern WebAuthn capabilities, older second-factor use and compatibility decisions.
Open guide →Security Key vs Passkey
Compare hardware-bound credentials, synced passkeys, portability, recovery and high-risk account protection.
Open guide →Security Keys for High-Risk Users
Build a phishing-resistant plan for administrators, journalists, executives and targeted individuals.
Open guide →What to Do If a Security Key Is Lost
Use backup authenticators, remove the missing key and review sessions without panic or unsafe shortcuts.
Open guide →Why You Need a Backup Security Key
Avoid lockout by enrolling a separate protected key and testing account recovery.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.