Physical security key supporting FIDO2, U2F, smart card, and more. Simply insert and touch for two‑factor authentication—immune to phishing. Recommended by Google, Microsoft, and others.
SMS codes and TOTP (like Google Authenticator) can still be intercepted in man‑in‑the‑middle attacks. YubiKey uses FIDO2—it only authenticates on the real website, making phishing sites useless. Google employees all use YubiKey to protect their accounts.
We added a YubiKey to a test Google account. The login flow: after entering the password, insert and touch the YubiKey—authentication completes instantly. Even if an attacker steals your password and SMS code, they can’t log in without the physical key.
Google reports a 99.9% reduction in successful employee account phishing after deploying hardware security keys.
Security tip: Buy at least two YubiKeys—one to carry and one as a backup. Register both to your accounts to avoid being locked out if you lose one.