- New
The NEOWAVE Winkeo2J-A FIDO2 is a USB-A hardware security key designed for strong user authentication in online, cloud, and enterprise environments. The device supports FIDO2 (CTAP 2.1) and FIDO U2F standards, enabling both multi-factor authentication and passwordless/Passkey login.
NEOWAVE Winkeo2J-A FIDO2 – FIDO2 L2 USB-A Hardware Security Key
The NEOWAVE Winkeo2J-A FIDO2 is a USB-A hardware security key designed for strong user authentication in online, cloud, and enterprise environments. The device supports FIDO2 (CTAP 2.1) and FIDO U2F standards, enabling both multi-factor authentication and passwordless/Passkey login.
The key uses asymmetric cryptography. The public/private key pair is created during the registration process, while the private key remains securely stored on the device and is not shared with the service where the user is authenticating. This solution reduces the risk of login credentials being compromised and provides high resistance to phishing.
The Winkeo2J-A FIDO2 is FIDO2 Level 2 (L2) certified and uses the Java Card™ component certified according to Common Criteria EAL6+. The product also bears the European Cybersecurity Made in Europe seal.
The key is compatible with Microsoft Entra ID, Windows environments, and identity federation solutions such as Okta, Ping Identity, Evidian, and Ilex. According to the manufacturer, it can also work with over 250 online services that support FIDO mechanisms, including Gmail, PayPal, OVH, WordPress, and Dropbox.
The device does not require any additional software to be installed on the user's computer to utilize FIDO2 functionality. Thanks to the standard USB HID interface, it can be used with supported operating systems and browsers that are WebAuthn/FIDO2 compliant.
FIDO2 / CTAP 2.1 Features
credProtect
hmac-secret
Resident Keys – resident keys / discoverable credentials
Storing resident credentials in the device's persistent memory
Memory consumption: approximately 200–512 bytes per credential, depending on configuration
User PIN support
Support for PIN 1 and PIN 2 protocols
PIN length: from 4 Unicode characters to 63 bytes
Maximum number of failed PIN attempts: 8
Authenticator reset is required after exceeding the number of attempts
No default PIN
PIN policy support
credBlob
largeBlobKey
largeBlobs
noMcGaPermissionsWithClientPin
minPinLength
pinUvAuthToken
Enterprise Attestation
authnrCfg
credMgmt
setMinPINLength
makeCredUvNotRqd
alwaysUv
Software Required for Operation
Basic FIDO2 functionality does not require installing additional software or drivers on the user's computer.
The key works with an operating system, browser, and service or platform that supports the FIDO2/WebAuthn or FIDO U2F standard.
In a corporate environment, the Identity and Access Management (IAM) platform used must be properly configured, for example:
Microsoft Entra ID
Okta
Ping Identity
Evidian
Ilex
For the standard Winkeo2J-A FIDO2 version, the NEOWAVE OTP Manager application is not required. This software applies to models equipped with additional OTP functionality.
Models and Variants
Winkeo2J-A FIDO2
USB-A connector
FIDO2 CTAP 2.1
FIDO U2F
FIDO2 L2 certified
Basic model designed for strong and passwordless authentication
Winkeo2J-C FIDO2
USB-C equivalent
FIDO2 CTAP 2.1
FIDO U2F
FIDO2 L2 certified
Winkeo2J-A FIDO2 + OTP
USB-A connector
FIDO2 CTAP 2.1
FIDO U2F
Additional HOTP/TOTP support
FIDO2 L2 certified
The NEOWAVE OTP Manager application is used for OTP functionality.
Winkeo2J-A FIDO2 + QSCD
USB-A connector
FIDO2 CTAP 2.1
FIDO U2F
PKI infrastructure support
Functionality QSCD – Qualified Electronic Signature Creation Device
FIDO2 L2 certificate
SafeSign Identity Client middleware – CSP/KSP/PKCS#11 required for PKI/QSCD functionality
The NEOWAVE FIDO2 family also offers solutions in other hardware formats:
Badgeo KF FIDO2 – a key fob with a contactless/NFC interface
Badgeo Dual FIDO2 – a smart card with a contactless and NFC interface
Badgeo NFC FIDO2 – a contactless NFC card
Older Winkeo-C FIDO2 and Winkeo2-C FIDO2 models using FIDO2 CTAP 2.0
Personalization
The manufacturer offers optional device personalization services:
logo printing
user photo
name and surname
individual identification number
other graphic identification elements depending on the project
Applications
NEOWAVE Winkeo2J-A FIDO2 can be used for:
securing access to user accounts
FIDO2 authentication
passwordless login
Passkeys
two-factor authentication (2FA)
multi-factor authentication (MFA)
securing Microsoft Entra ID environments
securing Okta environments
securing access to SaaS applications
securing cloud services
protecting administrator and privileged user accounts
protecting against phishing
replacing phishing-prone authentication methods based on passwords or SMS codes
enterprise and government deployments
applications in sectors requiring a higher level of digital identity protection
healthcare applications, including environments using Pro Santé Connect
Manufacturer and Country of Origin
Manufacturer: NEOWAVE
Manufacturer Headquarters: Gardanne, France
Country of Origin/Manufacturing: France
The manufacturer declares for the current FIDO2 family: 100% Made in France
Product Type: Hardware Security Key
Product Family: NEOWAVE FIDO2
Model: Winkeo2J-A FIDO2
Technical Specifications
Interface: USB-A 2.0 HID
Authentication Standard: FIDO2
Protocol: CTAP 2.1
Support: FIDO U2F
Passwordless Authentication Support: Yes
Passkeys Support: Yes
MFA/2FA Multi-Factor Authentication: Yes
Credential Generation: Inside the Secure Device Component
Credential Management: Inside the Device
Private Key Storage: Inside the Device
Architecture Cryptographic: Asymmetric cryptography – public/private key pair
Signature algorithm: ECC P-256 / secp256r1
Secure component: Java Card™ in micro-SIM format
Secure component certification: Common Criteria EAL6+
FIDO certification: FIDO2 Level 2
Marking: Cybersecurity Made in Europe
Product listed by the French Agency for Nuclear Safety – ANS
Compatible with Pro Santé Connect: yes
Physical user presence verification: on-device button
Anti-phishing protection: yes
Password theft protection: yes
Driver installation for basic FIDO2 functionality: not required
Length: 43.8 mm
Width: 18 mm
Height: 9.76 mm
Weight: 6 g
Compatibility
Microsoft Windows 10
Microsoft Windows 11
macOS
Linux
Microsoft Entra ID
Microsoft 365 – in environments using FIDO2/passwordless authentication
Okta
Ping Identity
Evidian
Ilex
Gmail
PayPal
OVH
WordPress
Dropbox
other applications, platforms, and services supporting the FIDO2/FIDO U2F standard
Supported Browsers
Google Chrome
Microsoft Edge
Mozilla Firefox
Apple Safari