- New
Nitrokey is a family of hardware security keys designed to protect user accounts, cryptographic keys, email, files, system access, and PKI infrastructure. Depending on the model selected, Nitrokey devices can be used for features such as two-factor authentication (2FA), passwordless login using FIDO2/WebAuthn and passkeys, OpenPGP key storage, S/MIME and PIV support, OTP one-time password generation, SSH key protection, and secure storage of encrypted data.
Nitrokey – Hardware Security and Authentication Keys
Manufacturer: Nitrokey GmbH, Germany
Nitrokey is a family of hardware security keys designed to protect user accounts, cryptographic keys, email, files, system access, and PKI infrastructure. Depending on the model selected, Nitrokey devices can be used for features such as two-factor authentication (2FA), passwordless login using FIDO2/WebAuthn and passkeys, OpenPGP key storage, S/MIME and PIV support, OTP one-time password generation, SSH key protection, and secure storage of encrypted data.
Cryptographic keys are stored on the hardware device, eliminating the need to save them directly on the user's computer. Select Nitrokey models utilize a Common Criteria EAL6+ certified Secure Element.
A key feature of Nitrokey products is their open architecture. The manufacturer provides the source code for many hardware components, firmware, libraries, and tools, enabling independent analysis and integration with corporate systems. Key Applications
Two-factor authentication (2FA),
Passwordless login,
FIDO2 and WebAuthn,
Passkeys,
FIDO U2F,
Account protection against phishing,
Cryptographic key storage,
Email encryption and signing,
OpenPGP / GnuPG,
S/MIME and X.509,
SSH key protection,
User certificate storage,
PIV – Personal Identity Verification in Nitrokey 3,
HOTP and TOTP one-time password generation in select models,
Hardware password manager in select models,
PKCS#11 and integration with cryptographic applications,
PKI and CA infrastructure key protection using Nitrokey HSM 2,
Hardware-encrypted data storage in Nitrokey Storage 2.
Nitrokey Models and Variants
Nitrokey 3
The most versatile Nitrokey family, combining modern FIDO2/WebAuthn authentication with cryptographic card, OpenPGP, PIV, OTP, and hardware key storage features.
Available variants:
Nitrokey 3A Mini – USB-A, compact form factor,
Nitrokey 3A NFC – USB-A + NFC,
Nitrokey 3C NFC – USB-C + NFC,
Nitrokey 3A – USB-A, non-NFC version,
Nitrokey 3C – USB-C, non-NFC version,
Nitrokey 3A NFC Hacker – variant designed primarily for developers and development work.
Nitrokey Passkey
A compact key designed primarily for protecting online accounts using modern FIDO2/WebAuthn standards. It is a simpler alternative to Nitrokey 3 for users who primarily require secure authentication, rather than OpenPGP, OTP, PIV, or extensive cryptographic key storage.
Nitrokey Pro 2
A hardware cryptographic token designed to protect keys, certificates, email, and generate one-time authentication codes.
Nitrokey Storage 2
Nitrokey Storage 2 combines the functions of a hardware cryptographic token with encrypted storage. This solution is designed for users who, in addition to securing cryptographic keys, need to transfer confidential data in encrypted form.
Nitrokey HSM 2
A hardware security module designed primarily for administrators, enterprises, and PKI/CA infrastructures. It enables hardware protection of keys used by certification authorities, servers, signature systems, and applications using PKCS#11, among others.
Nitrokey Start
A basic cryptographic token designed primarily for OpenPGP applications, email and file encryption, and SSH key protection.
Software Required
The software required depends on the model selected and how the device will be used.
Nitrokey 3
For standard FIDO2/WebAuthn authentication, special Nitrokey software is not required – a compatible operating system, browser, or application that supports FIDO2/WebAuthn is sufficient.
The Nitrokey App 2 is used for device configuration and management.
Alternatively, the nitropy / pynitrokey command-line tool is available.
When using OpenPGP, software such as GnuPG may be required.
For smart card, S/MIME, or PIV applications, appropriate drivers and software compliant with OpenSC/PKCS#11 can be used.
Nitrokey Passkey
For standard FIDO2/WebAuthn login, no additional client software or special driver is required.
A system, browser, or application that supports FIDO2/WebAuthn is required.
Nitrokey App 2 can be used to manage the device.
Nitrokey Pro 2 and Nitrokey Storage 2
Nitrokey App 1 is used to manage the device.
For OpenPGP: GnuPG or compatible software.
For S/MIME/X.509: an application using the appropriate interface, e.g., PKCS#11/OpenSC.
Compatibility with Mozilla Thunderbird, Microsoft Outlook, SSH, and VeraCrypt, among others, is possible, depending on the application.
Nitrokey Start
The basic environment is software that supports OpenPGP, specifically GnuPG.
Depending on the application, OpenSC, PKCS#11, SSH, Thunderbird, or other compatible applications can be used.
Nitrokey HSM 2
Software using the appropriate cryptographic interface is required.
Supported cryptographic interfaces include PKCS#11, OpenSC, CSP MiniDriver, JCE, and API.
The device can work with XCA, EJBCA, and applications using PKCS#11.
System Compatibility
Depending on the model, Nitrokey works with:
Microsoft Windows,
macOS,
Linux,
BSD,
Android – selected models and features,
iOS – selected models and features.
The Nitrokey family utilizes open and widely used cryptographic standards, allowing devices to be integrated with popular internet services as well as corporate authentication infrastructures, PKI, and certificate management systems.
Manufacturer: Nitrokey GmbH, Germany
Nitrokey 3 – Technical Specifications
Authentication standards: WebAuthn, CTAP2/FIDO2, CTAP1/FIDO U2F 1.2,
Passkey support,
2FA support,
Passwordless login support,
HOTP according to RFC 4226,
TOTP according to RFC 6238,
OpenPGP Card,
PIV,
S/MIME and X.509 support,
PKCS#11 and OpenSC support,
RSA 2048–4096 bit key support,
Elliptic curve cryptography support,
Supported, among others NIST P-256, P-384, P-521,
Curve25519 / Ed25519 support,
Brainpool curve support,
AES-128 and AES-256,
SHA-256, SHA-384, and SHA-512,
TRNG hardware random number generator,
Secure Element with Common Criteria EAL6+ certification,
signed firmware updates,
physical touch button,
multicolor LED indicator,
interface: USB-A or USB-C depending on the version,
NFC communication: Nitrokey 3A NFC and Nitrokey 3C NFC,
supported systems: Windows, macOS, Linux, BSD, and, where applicable, Android and iOS.
Nitrokey Passkey – Technical Specifications
WebAuthentication – WebAuthn,
CTAP2 / FIDO2,
CTAP1 / FIDO U2F 1.2,
Passkey support,
Two-factor authentication (2FA),
Passwordless login,
Ability to work with an unlimited number of accounts in FIDO2/U2F modes,
Signed firmware,
Physical touch button,
Four-color LED,
USB-A interface,
USB 2.1,
Dimensions: 17 x 14 x 6 mm,
Weight: approximately 1.5 g,
Operating systems: Windows, macOS, Linux, BSD, Android, iOS,
Compliance: FCC, CE, RoHS, WEEE, OSHwA.
Nitrokey Pro 2 – Technical Specifications
Secure storage of 3 RSA 2048–4096 bit keys or 3 ECC 256–521 bit keys,
AES-128 and AES-256,
NIST P-256, P-384 and P-521,
Brainpool P256, P384 and P512,
SHA-256, SHA-384, SHA-512,
3 × HOTP,
15 × TOTP,
1 × HOTP validation,
Hardware password manager: 16 entries,
Hardware TRNG random number generator,
Tamper-resistant cryptographic card,
OpenPGP Card 3.4,
OpenPGP,
S/MIME,
X.509,
PKCS#11,
USB 2.0 interface Type-A,
Dimensions: 48 × 19 × 7 mm,
Weight: approximately 6 g,
Operating systems: Windows, macOS, Linux, BSD.
Nitrokey Storage 2 – Technical Specifications
Hardware-encrypted storage,
Available capacities depend on the device variant; the manufacturer currently offers, among others: 64 GB version,
memory encryption: AES-256 CBC,
hidden volumes possible,
3 cryptographic key slots,
RSA 2048–4096 bit,
ECC 256–521 bit,
NIST P-256, P-384, P-521,
Brainpool curves,
SHA-256, SHA-384, SHA-512,
3 × HOTP,
15 × TOTP,
password manager: 16 entries,
hardware TRNG random number generator,
OpenPGP,
S/MIME,
X.509,
PKCS#11,
USB 2.0 Type-A interface,
dimensions: 69 × 20 × 8 mm,
weight: approximately 11 g,
systems: Windows, macOS, Linux, BSD.
Nitrokey HSM 2 – Technical Specifications
Algorithms: RSA, ECC, AES,
RSA: 1024–4096 bit,
ECC: 192–521 bit,
AES: 128–256 bit,
RSAES-OAEP support,
RSAES-PKCS1-v1_5 support,
RSASSA-PSS support,
RSASSA-PKCS1-v1_5 support,
ECDH and ECDSA support,
NIST and Brainpool curve support,
SHA-1, SHA-256, SHA-384, SHA-512,
EEPROM memory: 76 KB,
up to 55 RSA-2048 keys,
up to 27 RSA-4096 keys,
up to 55 keys ECC/AES-256 depending on key type,
maximum 65,536 data objects,
encrypted AES-256 backups,
hardware random number generator,
PKCS#11,
X.509,
S/MIME,
CSP MiniDriver for Windows,
Java Cryptography Extension – JCE,
OpenSC,
supports XCA and EJBCA,
USB 1.1 Type-A interface,
dimensions: 48 × 19 × 7 mm,
weight: approximately 6 g,
operating systems: Windows, macOS, Linux, BSD.
Nitrokey Start – Technical Specifications
RSA and ECC algorithms,
RSA 2048 bit,
RSA 4096 bit support with limited performance,
ECC 256 bit,
EdDSA,
ECDSA,
ECDH,
Curve25519 / X25519,
NIST P-256,
secp256k1,
OpenPGP Card,
3 keys: decryption, signature, and authentication,
hardware TRNG random number generator,
OpenPGP,
S/MIME,
X.509,
PKCS#11,
USB 1.1 Type-A,
Dimensions: 48 × 19 × 7 mm,
Weight: approximately 5 g,
Operating systems: Windows, macOS, Linux, BSD.