Rank #2 of 6 in Hardware Security Keys
Access
Install
pipx install pynitrokeyTry itExperimental
See what an agent can do with Nitrokey before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$uvx --from pynitrokey nitropy versionrecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →
Building with and managing the key — CLIs, SDKs, attestation
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Nitrokey stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~5/10
unlocks → Machine-readable spec · Versioning policy · Full data export
Subscribe to events via webhooks
n/an/a
Build against official SDKs
~6/10
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
✓8/10
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
~6/10
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
~6/10
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
~6/10
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
~5/10
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
~4/10
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
✓8/10
Official SDKs let me integrate the key into my own desktop and mobile apps
~5/10
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
—0/10
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
—–
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
~4/10
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
~3/10
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
~3/10
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
~4/10
Tap the key on my phone over NFC to authenticate in mobile browsers and apps
~4/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 5/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably Cli | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 3 | full | 8/10 | Tprobed | |
The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username Fido2 | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 3 | partial | 6/10 | Xcommunity | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | disputed | 3/10 | Dcontradicted | |
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys Provisioning | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 3 | partial | 3/10 | Tprobed | |
The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost Recovery | security engineer | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 3 | none | 0/10 | ||
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email Openpgp | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | full | 8/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | full | 8/10 | Tprobed | |
The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device Source | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | partial | 7/10 | Tprobed | |
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch Ssh | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | partial | 6/10 | Xcommunity | |
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device Piv | it admin | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | partial | 6/10 | Xcommunity | |
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn Otp | power user | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | partial | 6/10 | Cclaimed | |
The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers Fido2 | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | partial | 6/10 | Xcommunity | |
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet Agent audit | ai-native user | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | partial | 5/10 | Tprobed | |
First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts Setup | power user | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 2 | partial | 5/10 | Tprobed | |
Official SDKs let me integrate the key into my own desktop and mobile apps Sdks | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | partial | 5/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 4/10 | Tprobed | |
Tap the key on my phone over NFC to authenticate in mobile browsers and apps Nfc | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | partial | 4/10 | Cclaimed | |
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication Idp | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | partial | 4/10 | Cclaimed | |
The key works across my operating systems and browsers, with a published compatibility catalog of supported services Compatibility | power user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 2 | disputed | 4/10 | Dcontradicted | |
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors Connectors | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | partial | 4/10 | Xcommunity | |
The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices Updates | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | partial | 4/10 | Tprobed | |
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled Attestation | security engineer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | partial | 4/10 | Xcommunity | |
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance) Certifications | it admin | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | partial | 3/10 | Xcommunity | |
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console Agent provisioning | ai-native user | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | none | 0/10 | ||
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate User verification | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | none | 0/10 | ||
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics Delivery | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | none | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
List and delete the passkeys stored on my key and know its credential capacity before it fills up Credential management | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions Agent approval | ai-native user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 1 | none | 0/10 | ||
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 34 stories with headroom
What would move Nitrokey’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
nonemoves PA Scoreimpact 30
No evidence pack item documents a vendor-provided lockout-recovery strategy (e.g., registering a backup Nitrokey, or what OpenPGP/FIDO2/PIV credentials are or are not recoverable if a key is lost).
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
Probes explicitly confirm no llms.txt or agent-oriented docs endpoint exists (404s), and no evidence of AI-native documentation is present anywhere in the pack.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Probes explicitly show no OpenAPI/interactive API reference exists (404s for openapi.json, swagger.json, etc.), and no docs mention runnable examples or an interactive API explorer despite Nitrokey having a CLI (nitropy) and Python SDK.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Nitrokey is a hardware security key vendor; the probe explicitly checked for a machine-readable API spec (openapi.json, swagger.json, etc.) and all candidates returned 404, with no OpenAPI/Swagger spec documented anywhere in the evidence pack.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Nitrokey ships a versioned CLI (nitropy) and Python SDK, but there is no evidence of a documented API deprecation policy, versioned public API, or OpenAPI spec — probes explicitly show 404s for OpenAPI/llms.txt discovery.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
partialq5/10moves agent-readyimpact 22.5
Missing: a documented HTTP/OpenAPI public API, machine-readable API spec, and any AI-agent-specific integration guidance.
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
partialq3/10moves PA Scoreimpact 21
Missing: bulk enrollment/pre-registration tooling, centralized admin console for fleet inventory, lifecycle/revocation tracking at scale, independent case studies of large deployments.
Showing the top 8 of 34 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map9 surfaces · 26 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Nitrokeys docs13 stories
- Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
Hacker News12 stories
- The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
- The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
- Export all of my data in open formats and leave
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
Software docs11 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- Official SDKs let me integrate the key into my own desktop and mobile apps
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Do everything through the API that I can do in the UI
Shop docs8 stories
- Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
- The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
docs.nitrokey.com5 stories
- Drive the product through a documented public API
- Official SDKs let me integrate the key into my own desktop and mobile apps
- The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
GitHub README5 stories
- Build against official SDKs
- The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- Export all of my data in open formats and leave
- Read the product's source under an open license
OpenAPI spec4 stories
Products docs4 stories
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$uvx --from pynitrokey nitropy versionreproduced$ uvx --from pynitro[redacted] nitropy version Command line tool to interact with Nitro[redacted] devices 0.13.0 0.13.0
$curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/Nitrokey/nitrokey-3-firmware/releases/latestreproduced$ curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/Nitro[redacted]/nitro[redacted]-3-firmware/releases/latest
200 https://github.com/Nitro[redacted]/nitro[redacted]-3-firmware/releases/tag/v1.8.3
$curl -s https://pypi.org/pypi/nitrokey/json | python3 -c "...print(name, version)"reproduced$ curl -s https://pypi.org/pypi/nitro[redacted]/json | python3 -c "...print(name, version)" nitro[redacted] 0.4.2
Business model
Hardware purchase (Nitrokey 3A NFC 60 €, Nitrokey Passkey 32 €) with fully open-source Rust firmware; Business Subscription and Fulfillment for organizations.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
