The Nitrokey FIDO2 is a hardware authentication device for passwordless login and two-factor authentication (2FA), utilizing FIDO2, WebAuthn, and FIDO U2F standards to secure access to web services, enterprise systems, and operating systems. It protects against phishing by verifying the service's domain before authenticating and functions natively in common web browsers without needing additional drivers or software. For authorization, the device requires a combination of a user-set PIN and physical touch confirmation to ensure user presence. It supports both discoverable and non-discoverable credentials and maintains backward compatibility with legacy U2F systems.
For remote system administration, the device provides SSH authentication by generating and storing private SSH keys directly on the hardware, ensuring the keys are never exposed. Each SSH login operation requires physical touch confirmation to prevent unauthorized access. All operations involving the device's stored private keys and credentials are authorized and protected by its FIDO2 PIN.