Nitrokey Pro 2 is an open-source, USB-A hardware security device designed to protect emails, files, hard drives, server certificates, and online accounts. It generates and stores cryptographic keys securely on a PIN-protected, tamper-resistant smart card, ensuring the keys never leave the hardware. The device functions independently of operating systems to defend against malware, phishing, and brute-force attacks, and relies entirely on open-source hardware and firmware.
The device supports One Time Passwords (HOTP and TOTP), client certificate authentication, and email or hard disk encryption using OpenPGP and S/MIME standards. It stores up to three cryptographic key pairs with support for RSA (2048 to 4096-bit) and ECC (256 to 521-bit) utilizing NIST P and Brainpool curves. Additionally, it features an encrypted hardware password safe capable of securely storing up to 16 static passwords.