Skip to content
Personal Security · Authentication Hardware

Best Hardware Security Keys 2026: YubiKey vs Titan vs Feitian vs Solo 2

Six hardware security keys compared on list price, connector, passkey capacity and protocol support, with every price read off the vendor's own store on 18 September 2026.

By ·Apr 11, 2026·Updated Sep 18, 2026·15 min·6 tools compared
Hardware Security KeysFIDO2YubiKeyPasskeysAuthentication

Who should buy what

If you want phishing-resistant login on web accounts and nothing more, buy two Google Titan keys at $30 and $35. If any part of your login involves a certificate, a smart card or an SSH key, buy a YubiKey 5C NFC at $58 instead, because it is the only key here that does FIDO2, PIV, OpenPGP, OATH and Yubico OTP in one device. If PIV is the only extra you need, Feitian's K40+ does it for $57. Buy two of whatever you choose, and register both everywhere.

Three things changed in 2026 and they change the shopping list.

Prices moved. Yubico adjusted its pricing at the start of the year. A YubiKey 5 NFC or 5C NFC now lists at $58 on Yubico's own store, not the $45 to $50 that older comparisons still quote, and the Lightning-capable 5Ci is $85. Yubico's cut-down Security Key Series is $29, which is the cheapest route to the same phishing resistance from the same vendor.

Passkey capacity became the spec that ages. Every passkey you register eats a slot. A YubiKey on firmware 5.0 through 5.6 holds 25, firmware 5.7 and later holds 100, and the Titan holds 250. YubiKey firmware cannot be updated in the field, so that number is fixed the day the key is manufactured.

Lightning stopped being a buying consideration. Apple moved the iPhone to USB-C with the iPhone 15 in 2023, and no current iPhone ships with a Lightning port. Dual-connector Lightning keys still exist, and this page prices them, but they are now a purchase for a phone you already own. For a phone you will buy next, NFC is the connector that keeps working.

If you are deciding between a hardware key and a synced passkey, the split in our 2FA app comparison applies here too: sync the ordinary accounts, keep device-bound hardware credentials on the few that can recover everything else. The password manager comparison covers where synced passkeys live.

Quick Comparison

KeyBest forConnectorsProtocolsPasskeys storedVendor list price (18 Sep 2026)
YubiKey 5 SeriesBroadest protocol and service supportUSB-A, USB-C, NFC, Lightning (5Ci)FIDO2/WebAuthn, U2F, PIV smart card, OpenPGP, Yubico OTP, OATH100 on firmware 5.7 and later; 25 on firmware 5.0-5.6$58 (5 NFC and 5C NFC), $65 (5C), $68 (Nano), $85 (5Ci)
Google Titan Security KeyMost passkey slots per dollarUSB-A + NFC, USB-C + NFCFIDO2/WebAuthn, U2FUp to 250$30 (USB-A + NFC), $35 (USB-C + NFC)
Feitian K-seriesSmart card (PIV) without YubiKey pricingUSB-A, USB-C, NFC, Lightning (K44)FIDO2/WebAuthn, U2F, PIV, OATH, OpenPGP by modelNot published by the vendor$28 (A4B) to $93 (K33 biometric); K40+ USB-C NFC PIV $57
SoloKeys Solo 2Auditable open-source firmwareUSB-A, USB-C, NFC on the + modelsFIDO2/WebAuthn, U2FNot published by the vendor$34-$35 (USB-A or USB-C), $46 (NFC models)
OnlyKey / OnlyKey DUOOne device for FIDO2 plus stored passwords and TOTPUSB-A and USB-C (DUO)FIDO2/WebAuthn, U2F, OATH TOTP, static passwords, PGP/SSHNot published by the vendor$55.99 on sale, $69.99 list
TokenCore wearable ringHands-free tap authenticationBluetooth LE 5.4, NFCFIDO2 Level 1 certifiedNot published by the vendor$279, listed sold out at time of check

YubiKey 5 Series

Best for
Broadest protocol and service support
Connectors
USB-A, USB-C, NFC, Lightning (5Ci)
Protocols
FIDO2/WebAuthn, U2F, PIV smart card, OpenPGP, Yubico OTP, OATH
Passkeys stored
100 on firmware 5.7 and later; 25 on firmware 5.0-5.6
Vendor list price (18 Sep 2026)
$58 (5 NFC and 5C NFC), $65 (5C), $68 (Nano), $85 (5Ci)

Google Titan Security Key

Best for
Most passkey slots per dollar
Connectors
USB-A + NFC, USB-C + NFC
Protocols
FIDO2/WebAuthn, U2F
Passkeys stored
Up to 250
Vendor list price (18 Sep 2026)
$30 (USB-A + NFC), $35 (USB-C + NFC)

Feitian K-series

Best for
Smart card (PIV) without YubiKey pricing
Connectors
USB-A, USB-C, NFC, Lightning (K44)
Protocols
FIDO2/WebAuthn, U2F, PIV, OATH, OpenPGP by model
Passkeys stored
Not published by the vendor
Vendor list price (18 Sep 2026)
$28 (A4B) to $93 (K33 biometric); K40+ USB-C NFC PIV $57

SoloKeys Solo 2

Best for
Auditable open-source firmware
Connectors
USB-A, USB-C, NFC on the + models
Protocols
FIDO2/WebAuthn, U2F
Passkeys stored
Not published by the vendor
Vendor list price (18 Sep 2026)
$34-$35 (USB-A or USB-C), $46 (NFC models)

OnlyKey / OnlyKey DUO

Best for
One device for FIDO2 plus stored passwords and TOTP
Connectors
USB-A and USB-C (DUO)
Protocols
FIDO2/WebAuthn, U2F, OATH TOTP, static passwords, PGP/SSH
Passkeys stored
Not published by the vendor
Vendor list price (18 Sep 2026)
$55.99 on sale, $69.99 list

TokenCore wearable ring

Best for
Hands-free tap authentication
Connectors
Bluetooth LE 5.4, NFC
Protocols
FIDO2 Level 1 certified
Passkeys stored
Not published by the vendor
Vendor list price (18 Sep 2026)
$279, listed sold out at time of check
1

YubiKey 5 Series

Best Overall

Best for: Broadest protocol support and the widest service compatibility

“Still the key to buy if you only buy one. It is the only option here that speaks FIDO2, PIV smart card, OpenPGP, OATH and Yubico OTP from a single device, and firmware 5.7 raised its passkey capacity from 25 to 100. You pay for that breadth: Yubico's own store lists $58 for the 5 NFC and 5C NFC, rising to $85 for the Lightning-capable 5Ci.”

Pros

  • One device covers FIDO2/WebAuthn, U2F, PIV smart card, OpenPGP, Yubico OTP and OATH HOTP/TOTP, so a single key handles Windows smart card login, SSH signing, web passkeys and legacy OTP
  • Firmware 5.7 and later stores up to 100 discoverable credentials, alongside 24 PIV certificates, 64 OATH seeds and 2 OTP slots, which are separate per-application budgets
  • Yubico sells a stripped-down Security Key Series at $29 that is FIDO2 and U2F only, so you can buy a cheap second key from the same vendor and firmware line

Cons

  • Firmware cannot be updated in the field, so a key bought on firmware 5.6 is capped at 25 passkeys forever
  • The Bio series costs $98 and, in the standalone FIDO Edition Yubico sells direct, covers only the FIDO protocols; the Multi-protocol Edition that adds PIV is sold through YubiKey as a Service rather than the public store
Honest Weakness: The non-upgradable firmware is the real cost of ownership. Passkey capacity went from 25 to 100 with firmware 5.7, and the only way to get that capacity is to buy a new key. Yubico frames this as a security decision, and the reasoning holds, but at $58 to $85 per key, and with the standard advice being to own at least two, a capacity bump means a $116 to $170 refresh. Check the firmware version on a key before you buy it from a reseller, because stock on older firmware is still in circulation.

What the $58 actually buys

The YubiKey 5 Series is the only key in this comparison that is a smart card as well as an authenticator. PIV support is what lets it do certificate-based Windows login, macOS login and SSH authentication. OpenPGP support is what lets it sign Git commits and decrypt mail. FIDO2 and U2F cover the modern web. Yubico OTP and OATH HOTP/TOTP cover systems that have not moved on. If you only need the web, that breadth is dead weight and the $29 Security Key Series or a $30 Titan does the same job for the same phishing resistance. If you support a mixed environment, a single YubiKey replaces two or three devices.

Passkey capacity and firmware 5.7

Firmware 5.7 raised the FIDO2 discoverable-credential limit from 25 to 100. Yubico documents the limits as per-application, so a single key can hold up to 100 passkeys, 24 PIV certificates, 64 OATH seeds and 2 OTP seeds at the same time. Firmware 5.8 is the current line. Because firmware is not field-upgradable, the version printed on the key you receive is the version you keep, and older 5.x stock still ships through third-party channels.

Connectors, including the Lightning question

The 5 NFC is USB-A plus NFC. The 5C NFC is USB-C plus NFC. The Nano models sit flush in a port and have no NFC. The 5Ci is the one with a Lightning connector on one end and USB-C on the other, and at $85 it carries a $27 premium over the 5C NFC. Apple moved the iPhone to USB-C with the iPhone 15 in 2023 and no current iPhone ships with a Lightning port, so the 5Ci is now a legacy-device purchase rather than a default one. For a modern iPhone, either a USB-C key plugged straight in or an NFC key tapped to the back of the phone works, and NFC is the more forgiving of the two in daily use.

$58 (YubiKey 5 NFC, 5C NFC), $65 (5C), $68 (5 Nano, 5C Nano), $85 (5Ci). Security Key Series $29. Bio Series FIDO Edition $98. FIPS 140-3 models from $88. Vendor store prices read 18 September 2026.

Visit YubiKey 5 Series
2

Google Titan Security Key

Best Value

Best for: Google Advanced Protection and the highest passkey capacity per dollar

“At $30 for USB-A plus NFC and $35 for USB-C plus NFC, the Titan holds up to 250 passkeys, two and a half times the capacity of a current YubiKey at roughly half the price. It is FIDO2 and U2F only, so it is a web-authentication key and nothing else, but for most buyers that is the entire requirement.”

Pros

  • Up to 250 discoverable credentials, the highest published passkey capacity of any key here, which matters as more services register a passkey per account
  • $30 for the USB-A + NFC model and $35 for the USB-C + NFC model, so a primary-plus-backup pair costs $60 to $70 rather than $116 to $170
  • It is the straightforward route into Google's Advanced Protection Program, which locks a Google account to hardware-key login and tightens account recovery

Cons

  • FIDO2 and U2F only: no PIV smart card, no OpenPGP, no OATH, so it cannot do Windows smart card login or SSH signing
  • Only two SKUs, both with NFC, so there is no flush-mount nano option for a key you leave permanently in a laptop
Honest Weakness: The Titan does one thing. If your list of accounts is Google, Microsoft, GitHub, a password manager and a bank, that one thing is all you need and the YubiKey premium buys you nothing. The moment an employer asks for certificate-based login, or you want to move your SSH key onto hardware, the Titan is a dead end and you are buying a second key anyway. The 250-passkey capacity is also a number most people will never approach; treat it as headroom, not as the reason to buy.

Advanced Protection Program

Advanced Protection is the strongest setting Google offers on a consumer account. It requires hardware-key or passkey login, restricts which third-party apps can reach your Google data, and adds identity checks to account recovery, which is the step attackers usually target. Enrolling needs two keys registered, which is the same rule you should be following anyway. For journalists, campaign staff, activists and anyone who has been targeted rather than merely spammed, this is the highest-value $60 in consumer security.

Why 250 passkeys is the spec that ages best

Passkey capacity is the one hardware-key number that gets tighter over time, because services keep adding passkey support and each registration consumes a slot. A key from the YubiKey 5.0 to 5.6 era tops out at 25. Firmware 5.7 raised that to 100. The Titan's 250 means capacity is unlikely ever to be the reason you replace it. Neither Feitian, SoloKeys, OnlyKey nor TokenCore publish a discoverable-credential limit at all, which is itself a data point when you are trying to plan.

Where it fits against the YubiKey

The honest split is this. Buy the Titan if your authentication lives in a browser. Buy the YubiKey 5 if any part of it does not. Buy the $29 Yubico Security Key Series if you want the Titan's job done by Yubico's firmware and supply chain. All three give you the same protocol-level phishing resistance, because that property comes from WebAuthn origin binding, not from the vendor.

$30 (USB-A + NFC), $35 (USB-C + NFC), Google Store list prices read 18 September 2026

Visit Google Titan Security Key
3

Feitian K-series

Runner Up

Best for: PIV smart card support and unusual connector combinations at a lower price than Yubico

“Feitian is the only vendor here besides Yubico selling PIV smart card support, and it does it for less. The K40+ (USB-C, NFC, PIV) is $57 and the K9+ (USB-A, NFC, PIV) is $57, against $58 for a YubiKey 5C NFC that also adds OpenPGP and OTP. Feitian's real advantage is range, including the K44, a USB-C plus Lightning key at $48.”

Pros

  • PIV smart card support on the plus models (K9+, K40+, K26+, K45+), which is the capability that usually forces buyers to Yubico
  • The widest connector catalogue of any vendor here: USB-A, USB-C, NFC, Bluetooth on the MultiPass line, and a USB-C plus Lightning key (K44) at $48, $37 below the YubiKey 5Ci
  • Biometric models start at $60 for the K45 against $98 for a YubiKey Bio, so fingerprint-on-key is reachable at a mid-range price

Cons

  • Feitian does not publish discoverable-credential (passkey) limits for its keys, so you cannot plan capacity the way you can with Yubico or Google
  • The catalogue is large and the model names (A4B, K9, K9+, K10, K26, K28e, K33, K39, K40, K40+, K41, K44, K45) are hard to tell apart, and the plus suffix is what carries PIV
Honest Weakness: Feitian sells sixteen security keys and makes you work out which one you need from model numbers. Several are listed at steep discounts off a much higher notional list price, which makes it hard to know what the product is actually worth; the K26 biometric shows $86 against a $131 regular price, and the K26+ shows $88 against $154. The K41 MultiPass was sold out at time of check. Service-side compatibility is also thinner than Yubico's: Feitian keys are FIDO-certified and work anywhere WebAuthn does, but there is no Feitian equivalent of Yubico's published integration catalogue, so enterprise attestation and vendor-specific enrolment flows need testing before a bulk order.

The Lightning workaround

If you still carry a Lightning iPhone or an older iPad, the two ways to plug a key in directly are the YubiKey 5Ci at $85 and Feitian's K44 at $48. The K44 also carries PIV. Neither is a purchase to make on the assumption that Lightning has a future: Apple moved to USB-C with the iPhone 15 and no current iPhone has a Lightning port. If you are buying for a household or a fleet with mixed-age iPhones, an NFC key sidesteps the connector question entirely, which is the argument for spending the money on NFC rather than on a dual-connector body.

Where PIV actually matters

PIV is the protocol behind certificate-based login: Windows smart card sign-in, macOS login, SSH authentication backed by a certificate on the key, and the federal PIV standard itself. It is the single most common reason a buyer cannot use a $30 Titan. Feitian's plus models cover it at $57, which is the cheapest credible PIV key in this comparison. Check with whoever administers your certificate authority before ordering, because some enrolment tooling is written against Yubico's management applet specifically.

Biometrics without the Yubico premium

The K45 at $60 and the K26 at $86 put a fingerprint sensor on the key for less than the $98 YubiKey Bio FIDO Edition. The security argument for on-key biometrics is the same across all of them: the template is matched inside the key's secure element and never reaches the host machine. The practical argument is that a fingerprint replaces PIN entry, which is the step users complain about. What you are trading for the lower price is Yubico's documentation and support depth, not the underlying model.

$28 (A4B USB-A) to $93 (K33 AllinPass biometric). K40+ USB-C + NFC + PIV $57. K9+ USB-A + NFC + PIV $57. K44 USB-C + Lightning + PIV $48. K45 biometric $60. Vendor store prices read 18 September 2026.

Visit Feitian K-series
4

SoloKeys Solo 2

Best Open Source

Best for: Buyers who want firmware they can read

“Solo 2 is the open-source FIDO2 key that is still being sold and still being touched: $34 for USB-C, $35 for USB-A, $46 for the NFC models, running the Rust-based Trussed firmware developed with Nitrokey. It is FIDO2 and U2F only, and its history of long quiet periods is the reason to keep it as a second key rather than a first.”

Pros

  • Firmware and hardware are open source, built on the Rust-based Trussed framework, so the code path between a touch and a signature is auditable rather than asserted
  • $34 to $46 puts open-source hardware in the same bracket as the Google Titan rather than at a premium
  • Hacker editions at the same price ship unlocked for developers who want to build and flash their own firmware

Cons

  • FIDO2 and U2F only: no PIV, no OpenPGP, no OATH, and no published passkey capacity
  • Development has gone quiet for long stretches, and the USB-C NFC models were listed sold out at time of check
Honest Weakness: SoloKeys has a real track record of slow development, to the point where the project's own GitHub discussions carry threads asking whether it is dead. The company has been open that its team took outside work because SoloKeys could not be their main focus, and firmware development now runs in partnership with Nitrokey on the shared Trussed codebase. Repository activity and a Terms of Service updated in June 2026 say the project is alive. That is a lower bar than Yubico or Google clear, and it is the right reason to put Solo 2 in the drawer as a backup key rather than on the keyring as the only one.

What open source buys you here

For a hardware authenticator, open firmware means an independent reviewer can check that the private key never leaves the secure element and that the user-presence check is actually enforced, rather than taking the vendor's word. Trussed, the Rust framework Solo 2 runs on, is shared with Nitrokey, which means two vendors and two user bases are reading the same code. That is a meaningfully different trust model from Yubico's or Google's, both of which ship closed firmware and ask you to trust the manufacturing process instead.

Stock and support reality

At time of check the USB-A, USB-C, NFC USB-A and both Hacker lines were in stock, while the USB-C NFC model and the limited-edition USB-C NFC were sold out. Shipping is quoted at $3 in the US, $10 in the EU and $14 elsewhere. A key you cannot reorder in the size you need is a poor fit as an organisation's standard issue. As a personal backup key stored offsite, availability of one specific SKU matters far less.

$34 (Solo 2C USB-C), $35 (Solo 2 USB-A), $46 (Solo 2A+ / 2C+ NFC), $50 (limited edition NFC). Hacker editions same price. Vendor store prices read 18 September 2026.

Visit SoloKeys Solo 2
5

OnlyKey / OnlyKey DUO

Honorable Mention

Best for: One device that is a security key, a small password store and a TOTP generator

“OnlyKey is a FIDO2-certified key that also types stored passwords over USB HID, generates TOTP codes without a phone, and hides a second credential set behind a different PIN. At $55.99 on sale ($69.99 list) it only makes sense if you will use all of that. As a plain FIDO2 key it is beaten on price by every option above it.”

Pros

  • FIDO Alliance certified for FIDO2 while also storing passwords, TOTP seeds and PGP/SSH keys on the same device, with no cloud account anywhere in the design
  • The DUO model carries both USB-C and USB-A in one body, so it works with a phone and an older desktop without an adapter
  • A second hidden profile is unlocked by a different PIN, and its existence cannot be detected from the device, which is a real feature for people who face device seizure

Cons

  • Configuration needs a desktop application and a six-button capacitive interface, which is a long way from plugging in a Titan and touching it
  • Stored-account capacity is small enough that it cannot replace a password manager, and the vendor does not publish a passkey limit
Honest Weakness: OnlyKey is three products in one shell and the interface pays for it. Setting up accounts means a desktop configuration app, and selecting a profile means learning a six-touch-point interface where short and long presses mean different things. The on-device password store holds a couple of dozen entries, which is a rounding error against a real password manager, so in practice it holds the handful of credentials you need when you have no phone and no laptop of your own. Buy it for that specific scenario, or for the hidden-profile feature. Do not buy it because it is also a FIDO2 key.

The offline-everything case

The design assumption behind OnlyKey is that no credential should ever touch a cloud service. Passwords are typed by the device emulating a keyboard, TOTP codes are generated on the device, and PGP and SSH keys live in the same secure element. There is no sync, no account and no recovery service, which means there is also no vendor to breach and no vendor to recover you. That is the trade, stated plainly, and for a small group of people it is the right one.

The hidden profile

Entering a different PIN at startup loads an entirely separate credential set, and the device gives no indication that a second profile exists. This was built for people who may be compelled to unlock a device at a border or in custody. Whether that is your threat model or not, its presence tells you who the product is designed for, and it explains why the interface prioritises local control over convenience.

$55.99 on sale, $69.99 regular list, for both OnlyKey and OnlyKey DUO. International Travel Edition $74.99. Two-key starter pack $99.99 on sale. Vendor store prices read 18 September 2026.

Visit OnlyKey / OnlyKey DUO
6

TokenCore wearable ring

Honorable Mention

Best for: Tap-to-authenticate without taking anything out of a pocket

“The ring formerly sold as Token Ring, now TokenCore, is a FIDO2 Level 1 certified wearable with a fingerprint sensor, Bluetooth LE 5.4 and NFC, at $279. It was listed sold out across sizes at time of check. Include it on a shortlist only if hands-free authentication is worth roughly five YubiKeys to you.”

Pros

  • FIDO2 Level 1 certified and WebAuthn compliant, so it is a real phishing-resistant authenticator rather than a proximity gimmick
  • Authentication is a tap or a proximity check rather than finding and inserting a key, which removes the friction that stops hardware-key rollouts
  • Fingerprint matching happens on the ring, and the ring deactivates when removed, so a lost ring is not a usable credential

Cons

  • $279 against $30 to $85 for a key that does the same protocol job, and it needs charging every five to seven days
  • Ring sizing has to be right for the biometric and proximity checks to work, and returns for sizing are a logistics problem a USB stick does not have
Honest Weakness: Two problems, and the second is worse than the first. The price is roughly nine Google Titans for a device that is FIDO2-only, and unlike every other key here it has a battery, so it has a duty cycle and an end of life. More practically, it was sold out at time of check with a note about limited size availability and an instruction to email the company if your size is unavailable. A security control you cannot buy in your size is not a control. The vendor also rebranded from Token Ring to TokenCore, and store.tokenring.com now redirects to store.tokencore.com, which is worth knowing before you follow an older link.

Why a wearable at all

The thing that kills hardware-key programmes is not cost, it is friction: the key is in the other bag, or on the desk at home, or not on the keyring today. A ring is on your hand. It authenticates over NFC by tapping a phone or over Bluetooth LE to a laptop, and the fingerprint sensor on the ring supplies the user-verification factor. If a rollout has stalled on adoption rather than budget, that is the argument, and it is a real one. It is just an argument that has to survive a $279 per-user price and a battery.

Check before you buy

Confirm three things with the vendor in writing. Current stock in your size. The battery or device replacement policy once the cell degrades. And whether your identity provider accepts a Bluetooth LE authenticator, since some enterprise enrolment flows expect USB or NFC only. None of these are hypothetical risks; they are the ordinary consequences of buying a powered, sized, single-vendor wearable instead of a $58 stick.

$279. Listed sold out across sizes on the vendor store on 18 September 2026.

Visit TokenCore wearable ring

Which One Should You Pick?

Use CaseOur Recommendation
One key, one person, mostly web accounts, lowest sensible spendTwo Google Titans. $30 for the USB-A + NFC model and $35 for the USB-C + NFC model, $65 for the pair, 250 passkey slots each, NFC so they work by tapping a phone. Register both on every account. If you prefer Yubico's supply chain, two Security Key Series at $29 each does the same job with 25 to 100 passkey slots depending on firmware.
You need certificate-based login (Windows smart card, SSH, PIV)YubiKey 5C NFC at $58 if you also want OpenPGP and OATH in the same device, or Feitian K40+ at $57 if PIV plus FIDO2 is the whole requirement. Confirm your certificate tooling supports the vendor's management applet before ordering in volume.
You still carry a Lightning iPhone or iPadFeitian K44 at $48 (USB-C plus Lightning, with PIV) or YubiKey 5Ci at $85 (USB-C plus Lightning, full protocol set). Better answer for most people: buy an NFC key instead and tap it to the back of the phone, because no current iPhone ships with a Lightning port and a dual-connector body is a depreciating purchase.
You want firmware you or a researcher can actually readSoloKeys Solo 2 at $34 to $46, running the Rust-based Trussed firmware shared with Nitrokey. Pair it with a YubiKey or Titan as the primary key, because SoloKeys' development cadence has been uneven and single-SKU stock has run out before.
Enrolling dozens of passkeys across many servicesGoogle Titan, 250 discoverable credentials. A YubiKey on firmware 5.7 or later holds 100 and one on firmware 5.0 to 5.6 holds 25, and firmware cannot be upgraded. Feitian, SoloKeys, OnlyKey and TokenCore do not publish a limit at all.
Hardware-key rollout that stalled on user adoption rather than budgetLook at the TokenCore ring at $279 per user only after confirming stock, sizing and battery replacement terms, and after confirming your identity provider accepts a Bluetooth LE authenticator. In most organisations the cheaper fix is an NFC key plus removing the PIN step with an on-key fingerprint sensor: Feitian K45 at $60 or YubiKey Bio FIDO Edition at $98.

How we evaluated

Every price, connector, protocol and capacity figure on this page was read off the vendor's own store or documentation on 18 September 2026. Nothing here is carried over from another comparison site or inferred from a marketplace listing, because security-key prices on marketplaces drift from list and because several vendors run permanent discounts against inflated notional list prices.

What was checked, and where:

  • Prices: the Yubico store, the Google Store Titan page, FEITIAN's US store, the SoloKeys store, the OnlyKey store and the TokenCore store.
  • Passkey capacity: Yubico's firmware 5.7 technical documentation for the 25-to-100 change and the per-application storage budget. Where a vendor does not publish a discoverable-credential limit, this page says so rather than guessing.
  • Availability: whether each SKU could actually be added to a cart on the vendor's store on the date above. Two could not: the SoloKeys USB-C NFC models and every size of the TokenCore ring.
  • Ownership and naming: store.tokenring.com now issues a permanent redirect to store.tokencore.com, so the product previously sold as Token Ring is listed here under its current name.

What we did not do

No key was tested by hand. This comparison is built on vendor pricing pages, vendor technical documentation, FIDO Alliance certification status and public repository activity, and it says which of those each claim rests on. Where a vendor makes a claim that no third party has verified, the entry says the vendor claims it.

Rankings weigh four things in this order. Whether the key does the protocol job you actually need. What it costs to buy the pair you should be buying. How many passkeys it will hold in three years. And how confident you can be that the vendor will still be shipping it. That last criterion is why SoloKeys sits at four rather than higher despite having the best answer on auditability, and why the TokenCore ring sits last despite being a genuinely interesting product.

What we left out, and why

Thetis was in the previous version of this page. It is dropped here because the vendor's own storefront prices could not be verified on the date above, and this page does not quote a price it has not read from the seller.

Bluetooth-only keys are excluded. Pairing overhead and battery management make them harder to live with than NFC, and the market has largely moved on. The TokenCore ring is the exception, and it is included because a wearable solves a different problem (friction) rather than the same problem more awkwardly.

Phone-based and synced passkeys are not keys and are not ranked here. They are the right default for most accounts and the wrong default for the handful that can recover all the others.

Note

Editorial independence: this is a vendor-neutral comparison with no paid placements, sponsorships or affiliate links. Rankings reflect fit for the stated use cases, not commercial relationships.

Last verified: 18 September 2026. Vendor store prices, passkey capacity documentation, stock status and product availability were all rechecked on this date. Security-key list prices moved in January 2026; if you are reading this well after the date above, confirm the price on the vendor's store before ordering.

Frequently Asked Questions

What are the current list prices for hardware security keys in 2026?
Read off each vendor's own store on 18 September 2026. Cheapest first: Yubico Security Key Series $29, Google Titan $30 (USB-A + NFC) and $35 (USB-C + NFC), SoloKeys Solo 2 $34 to $46. Then Feitian at $28 to $93 depending on model. Then Yubico's main line: YubiKey 5 NFC and 5C NFC $58, 5C $65, Nano $68, 5Ci $85, Bio FIDO Edition $98. OnlyKey is $55.99 on sale against a $69.99 list, and the TokenCore ring is $279. Yubico adjusted its pricing at the start of 2026, so older comparisons quoting $45 to $50 for a YubiKey 5 NFC are out of date.
How many passkeys can each key hold?
Google Titan holds up to 250. A YubiKey on firmware 5.7 or later holds up to 100, and one on firmware 5.0 through 5.6 holds 25. Yubico documents those limits as per-application, so the same key can simultaneously hold its passkey allowance plus 24 PIV certificates, 64 OATH seeds and 2 OTP seeds. Feitian, SoloKeys, OnlyKey and TokenCore do not publish a discoverable-credential limit. Because YubiKey firmware is not field-upgradable, the capacity of a key is fixed on the day it is manufactured, not the day you buy it.
USB-C, NFC or Lightning: which connector should I buy now that iPhones use USB-C?
NFC for most people. Apple moved the iPhone to USB-C with the iPhone 15 in 2023 and no current iPhone ships with a Lightning port, so a Lightning key is now a purchase for a device you already own rather than for the one you will buy next. An NFC key works by tapping the back of an iPhone or Android phone and also plugs into a laptop, which is why the NFC models are the ones most vendors price as the default. Dual-connector Lightning keys still exist if you need one: Feitian's K44 at $48 and the YubiKey 5Ci at $85. Nano models, which sit flush in a port, have no NFC at all and are best as a key that lives permanently in one laptop.
Are hardware keys really phishing-resistant, and does the brand change that?
They are, and the brand does not change it. During FIDO2 authentication the key checks the origin (the domain) of the site requesting the signature, and refuses to sign if the origin does not match the one the credential was registered to. A convincing phishing page on a lookalike domain fails at that step, with no user judgement involved. SMS codes, TOTP codes and push approvals all fail that test because a human can be persuaded to hand them over. That origin binding comes from WebAuthn, so a $29 Yubico Security Key, a $30 Titan and a $98 YubiKey Bio all deliver it equally. What the more expensive keys buy is protocol breadth, capacity, biometrics and build, not more phishing resistance.
Should I put passkeys on a hardware key or let my phone sync them?
It depends on what you are defending against. Passkeys synced through iCloud Keychain, Google Password Manager or a password manager are convenient, recoverable and a large upgrade on passwords, which makes them right for most accounts. A passkey on a hardware key is device-bound: it cannot be synced, copied or extracted remotely, and compromising the sync account does not reach it. The cost of that is that losing the key loses the credential, which is why two registered keys is the standing advice. A practical split is to sync passkeys for ordinary accounts and keep device-bound hardware passkeys for the few accounts that can recover everything else: primary email, the password manager, the domain registrar and financial accounts.
What happens if I lose my key, and how many should I own?
At least two, registered on every account that supports hardware keys, with one carried and one stored somewhere else. If a key is the only authenticator on an account and it is lost, recovery falls back to whatever identity check the service runs, which can take days or fail outright. Print recovery codes where they are offered and store them with the backup key. If you do lose one, remove it from every account immediately rather than waiting, because a found key plus a known username is a meaningfully easier attack than either alone. Buying a pair is also why price matters: two Titans is $65, two YubiKey 5C NFC is $116, and two TokenCore rings would be $558.

About the author

is the founder and creator of LoginRadius, a customer identity platform he built and scaled to over a billion users. He is now the founder of GrackerAI, a GEO platform for B2B SaaS and cybersecurity teams, and has spent more than 15 years building identity and security products.

Related Comparisons