Do You Need a Security Key If You Already Use Passkeys?
Disclosure: This site may contain affiliate links. We may receive a commission from qualifying transactions. Commercial relationships can create conflicts of interest. Learn more.
Short answer: not necessarily. You can use passkeys stored on a compatible device or in a supported password manager without purchasing a separate security key. Consider hardware when you specifically want credentials on a separate physical device, need a supported hardware second factor, or want a separately registered backup for an important account. ASD's ACSC recommends checking account support first and creating a backup passkey on a second FIDO2 key when using hardware.[1]
This guide helps you decide what to buy, if anything. It is based on current official documentation, not hands-on testing or a ranking of key manufacturers. Do not switch off existing sign-in methods until you understand and have checked the replacement and recovery routes.
Passkey and security key describe different things
A passkey is an account sign-in credential. A security key is a physical device that can hold a credential or serve as a second authentication step, depending on the key and service. ACSC describes passkeys stored on devices or physical FIDO2 keys. Google distinguishes a FIDO2 key used to create a passkey from a FIDO1 or FIDO2 key used as the second step after a password.[1][3]
That distinction prevents two buying mistakes: purchasing an older key that cannot create the passkeys you want, or assuming that registering a key automatically removes the account password. Write down whether each account needs password plus hardware verification or sign-in with a passkey before looking at products.
Choose the job before choosing a key
Swipe horizontally to read all columns. Keyboard: focus the table and use arrow keys.
| Your goal | Start here | Purchase gate |
|---|---|---|
| Replace typed passwords on supported personal accounts | Check the passkey features already available on your trusted device or password manager | Buy nothing if that meets your access and recovery needs |
| Keep a credential on a separate physical device | Check the account's support for passkeys on a FIDO2 key | Confirm protocol, connector and backup registration before ordering |
| Add hardware as the second step while retaining a password | Read that account's security-key MFA instructions | Confirm this mode is supported; do not rely on a generic “passkeys supported” badge |
| Protect an Apple Account with Apple's Security Keys feature | Read Apple's requirements for the entire signed-in device set | Budget for at least two compatible FIDO Certified keys and check unsupported devices/accounts |
| Secure an employer-managed account | Ask the administrator for the approved authentication method and devices | Do not buy personal hardware assuming it meets organisational policy |
The device/passkey choices follow ACSC guidance; the Apple requirement is specific to Apple's Security Keys feature, not a universal rule for every online service.[1][2]
Fill in a compatibility sheet before checkout
Make one row per important account. Use the following columns; do not record passwords or recovery codes in the sheet.
- Account and purpose: email, password manager, platform account or another service.
- Required sign-in mode: passkey, password plus security key, or an administrator-specified method.
- Official support page: the provider's instructions for that mode, not a retailer's compatibility claim.
- Devices and browsers: your actual phone and computer models, operating-system versions and normal browsers.
- Connection: USB-C, USB-A or NFC as supported by those devices and that sign-in flow.
- Backup: whether a second key can be enrolled and what other recovery routes remain.
- Checked result: documentation confirmed, personally tried, or unresolved. Never mark an untried combination as tested.
For Google, creating a hardware passkey requires a key that supports FIDO2; its documentation says FIDO1 or FIDO2 keys can instead serve as a second step. Google also lists compatible browsers and warns that a newly added security key may not be usable at sign-in immediately.[3]
For Apple, the supported connector depends on the device: its guidance distinguishes NFC, USB-C, Lightning and USB-A, and notes that NFC keys work with iPhone. “Has NFC” is not evidence that a key will work with every tablet or computer.[2]
Apple Account users: read this before buying one key
Apple requires at least two FIDO Certified security keys compatible with the devices you regularly use. Its listed requirements include iOS 16.3, iPadOS 16.3 or macOS Ventura 13.2 or later on signed-in devices, two-factor authentication and a modern browser. Older devices that cannot be updated are not supported; neither are child accounts or Managed Apple Accounts. Check the full current list before committing.[2]
Apple's Security Keys feature uses your Apple Account password plus a physical security key or another trusted Apple device for the documented sign-in flow. Apple warns that losing all trusted devices and security keys can lock you out permanently. This is not the same decision as using a passkey saved in a password manager to sign in to a separate website.[2]
Decision: if you cannot maintain the required compatible devices and independent spare keys, postpone enabling this feature. Resolve those requirements first rather than assuming support will reverse every lockout.
A spare key must be registered, not just purchased
ACSC recommends creating and storing a backup passkey on a second FIDO2 key in case the first is lost, stolen or damaged. Google's lost-key instructions likewise refer to another key that you have added to your account. A sealed spare in a drawer is not yet a usable account fallback.[1][4]
- Enrol deliberately. Follow each account's official process for the first key and the backup. Do not assume that registering a key with your email service registers it with your password manager too.
- Name the entries. Use recognisable labels such as “daily key” and “home spare” where supported. Google allows key names to be edited.[3]
- Check each route. While retaining a working trusted session, try the intended sign-in mode with each registered key on your actual devices. Respect provider waiting periods; Google notes a possible delay of seven days for a newly added key.[3]
- Separate the spare. As a practical loss-prevention measure, keep it somewhere secure rather than carrying both keys with the same phone and bag.
- Record maintenance tasks. When adding a new important account, remember to enrol the spare there too. Review the inventory after changing devices, account settings or recovery methods.
- If a key is lost, follow the provider's process. Google's instructions are to sign in through another available method, remove the lost key, obtain a replacement and add it. This is not a promise that recovery will always succeed without another method.[4]
Do not confuse phishing resistance with complete protection
ACSC describes passkeys as a way to stop password guessing and password theft through fake login sites. It also advises using trusted devices, avoiding shared devices and avoiding employer-owned devices for personal-account passkeys. A safer sign-in method does not make an untrusted device safe.[1]
Check the other routes into the account. If it still accepts a password or another recovery method, evaluate and secure that route too. ACSC recommends disabling password sign-in after passkey setup; whether and how you can do that depends on the service. Follow its supported process only after checking working access and recovery. Do not remove your only functional fallback to make a checklist look complete.[1]
A key is not a backup of your documents, a device-locking tool or a substitute for an account recovery plan. Likewise, a VPN addresses network traffic rather than satisfying an account's key requirement. ACSC lists VPN use separately from MFA, updates, device locking and backups.[5] Read our personal VPN guide for that separate decision.
The final buying checklist
- I can name the account and authentication problem this purchase solves.
- I checked the account provider's documentation, the exact key's protocol support and my devices' connectors.
- I included the required spare and any needed adapter in the total cost, rather than comparing one-key headline prices.
- I have a plan to register and check the spare, and a secure place to keep it separately.
- I understand what happens if I lose all keys and trusted devices.
- If my existing passkey setup meets the requirement, I am willing to buy nothing.
If the unresolved issue is who can regain access to the vault itself, begin with the recovery criteria in our password manager guide. Hardware should solve a defined problem, not add another object you can lose without a recovery plan.