- New
Thetis Security Key is a family of hardware security keys designed to protect user accounts against phishing, password theft, and unauthorized access. Depending on the model, Thetis devices support FIDO2, WebAuthn, CTAP2, FIDO U2F, multi-factor authentication (2FA/MFA), passwordless login using passkeys, and selected versions also support TOTP/HOTP, NFC, Bluetooth, PIV, and fingerprint biometric authentication.
Thetis Security Key – FIDO2, Passkey, and 2FA Hardware Security Keys
Thetis Security Key is a family of hardware security keys designed to protect user accounts against phishing, password theft, and unauthorized access. Depending on the model, Thetis devices support FIDO2, WebAuthn, CTAP2, FIDO U2F, multi-factor authentication (2FA/MFA), passwordless login using passkeys, and selected versions also support TOTP/HOTP, NFC, Bluetooth, PIV, and fingerprint biometric authentication.
The hardware security key stores authentication data on the device and performs cryptographic operations without the need to transmit the private key to the website. In the case of FIDO2/WebAuthn, the solution provides high resistance to typical phishing attacks, as the authentication is cryptographically linked to the relevant website service.
Thetis offers models equipped with USB-A, USB-C, NFC, and Bluetooth, as well as specialized biometric versions. Compact Nano devices are also available, allowing them to remain permanently connected to a computer.
Thetis key cases are made of metal or incorporate aluminum protective elements, increasing the device's durability during everyday use.
Software Required for Operation
The software required depends on how the device is used.
FIDO2 / Passkey / WebAuthn
For daily logins to services using FIDO2 or WebAuthn, the key works with an operating system and browser that supports these standards.
The manufacturer provides its own tools for initial configuration and advanced management.
Thetis Key Manager – Windows
The official tool for configuring and managing Thetis keys in Windows.
Enables:
viewing device information,
setting a PIN,
changing a PIN,
resetting a PIN,
managing saved FIDO2/Passkey credentials,
managing TOTP,
managing HOTP,
performing basic device administration operations.
For full communication with the key, it is recommended to run the application with administrator privileges.
Thetis Manager – macOS
The official tool for macOS 12 or later. It enables:
reading key information,
managing relying parties,
PIN operations,
TOTP configuration,
HOTP configuration.
The current version of macOS does not support direct management of saved passkey credentials. The manufacturer recommends a tool available in Google Chrome for this purpose.
Google Chrome – Manage Security Keys
Chrome has a tool for managing hardware security keys.
It enables, among other things:
managing FIDO2,
managing passkeys saved on the key,
viewing credentials,
deleting credentials,
managing key settings.
The solution works on PCs and Macs.
Thetis Authenticator – Android and iOS
The manufacturer provides the Thetis Authenticator app for:
Android and
iOS.
The app is intended solely for TOTP support.
It is not intended for:
FIDO2 configuration,
passkey management,
FIDO key configuration,
initial device configuration.
The application reads the stored TOTP secret from the key and generates one-time authentication codes based on it.
Compatibility
Depending on the device model, Thetis devices can be compatible with:
Microsoft Windows,
macOS,
Linux,
Android,
iOS,
Google Chrome,
Microsoft Edge,
other systems, browsers, and applications compatible with FIDO2/WebAuthn or FIDO U2F.
NFC-enabled models can be used with compatible smartphones and tablets without the need to physically connect the key to a USB port.
Certification and Security
Depending on the model, Thetis devices are compliant with or declare compliance with:
FIDO U2F,
FIDO2,
FIDO2 Level 1,
FIDO2 Level 2 – selected models,
CE,
FCC,
RoHS,
WEEE.
The manufacturer also indicates that its key family uses hardware-protected security chips and indicates the security of the integrated circuit certified according to Common Criteria EAL6+.
The exact scope of certification should always be verified for a specific model, as not all devices in the Thetis family have the same certification level and feature set.
Key Applications
Two-factor authentication (2FA),
Multi-factor authentication (MFA),
Passwordless login,
Passkeys,
FIDO2,
WebAuthn,
CTAP2,
FIDO U2F,
Account protection against phishing,
Account takeover protection,
Hardware credential storage,
Google account authentication,
Microsoft account authentication,
GitHub security,
Dropbox security,
Salesforce security,
Interoperability with compatible password managers,
TOTP and HOTP on models that support them,
PIV on select versions,
Fingerprint authentication on BioFP models,
NFC mobile authentication on select versions,
Bluetooth connectivity on BLE models.
Producer: Razzo Tech Corporation DBA Thetis.io, USA
Thetis Models and Variants
Thetis FIDO2 Security Key – USB-A
The basic Thetis hardware security key supporting FIDO2, passkeys, and FIDO U2F.
Connection: USB-A,
FIDO2,
WebAuthn,
CTAP2,
passkeys,
FIDO U2F,
2FA,
MFA,
TOTP/HOTP via app,
passwordless login,
no NFC,
Suitable for: desktop computers and laptops,
Also available in sets of 2,
Variant with USB-C adapter available.
Thetis Nano-A FIDO2 Security Key
Ultra-compact FIDO2 key designed for USB-A devices. The Nano design allows the key to be left in the computer's USB port. Connector: USB-A,
FIDO2,
WebAuthn,
CTAP2,
passkeys,
2FA/MFA,
FIDO U2F,
Number of passkey slots: up to 200,
Number of OATH slots: up to 50,
OATH-TOTP support,
No NFC,
Algorithms: SHA-256, AES, HMAC, ECDH, ECDSA,
Certification: FIDO2 Level 1,
Compliance: CE,
Compliance: FCC,
Compliance: RoHS,
Compliance: WEEE,
Aluminum casing,
Dimensions: approximately 18.5 × 15.2 × 7.6 mm,
Windows compatible,
macOS compatible,
Linux compatible,
Thetis Nano-C FIDO2 Security Key
Nano version designed for computers and devices equipped with USB-C.
Connector: USB-C,
FIDO2,
WebAuthn,
CTAP2,
passkeys,
2FA/MFA,
FIDO U2F,
up to 200 passkeys,
up to 50 OATH locations,
OATH-TOTP support,
no NFC,
SHA-256,
AES,
HMAC,
ECDH,
ECDSA,
FIDO2 Level 1,
CE,
FCC,
RoHS,
WEEE,
aluminum casing,
dimensions: approximately 18.5 × 15.2 × 7.6 mm,
Thetis PRO
The Thetis PRO series is designed for users who require greater connection versatility. Depending on the version, the PRO models offer USB-A, USB-C, and NFC.
Thetis PRO FIDO2 Security Key – USB-A + USB-C + NFC
The most versatile standard Thetis model, featuring USB-A, USB-C, and NFC. USB-A connector,
USB-C connector,
NFC,
FIDO2,
WebAuthn,
CTAP2,
FIDO U2F,
passkeys,
passwordless login,
2FA,
MFA,
TOTP,
HOTP,
up to 200 passkeys,
up to 50 OATH locations,
SHA-256,
AES,
HMAC,
ECDH,
ECDSA algorithms,
FIDO2 Level 1 certification,
CE,
FCC,
RoHS,
WEEE,
foldable design,
rotating metal/aluminum cover,
supports computers via USB,
supports compatible mobile devices via NFC,
no batteries required,
no network connection required for authentication,
Thetis PRO-A FIDO2 Security Key
Connector: USB-A,
NFC: Yes,
FIDO2,
WebAuthn,
CTAP2,
FIDO U2F,
passkeys,
2FA/MFA,
TOTP/HOTP,
up to 200 passkeys,
up to 50 locations OATH,
SHA-256,
AES,
HMAC,
ECDH,
ECDSA,
FIDO2 Level 1,
foldable design with aluminum cover,
Thetis PRO-C FIDO2 Security Key
Connector: USB-C,
NFC: Yes,
FIDO2,
WebAuthn,
CTAP2,
FIDO U2F,
passkeys,
2FA/MFA,
TOTP/HOTP,
up to 200 passkeys,
up to 50 locations OATH,
SHA-256,
AES,
HMAC,
ECDH,
ECDSA,
FIDO2 Level 1,
foldable design with aluminum cover cover,
Thetis PRO FIDO2 Level 2
Thetis also offers models targeted at more demanding business deployments, where FIDO2 Level 2 certification is essential.
Available models include:
Thetis PRO FIDO2 L2 – USB-A + USB-C + NFC,
Thetis PRO-C Plus FIDO2 L2 – USB-C + NFC.
Depending on the model:
FIDO2,
WebAuthn,
CTAP2,
passkeys,
FIDO U2F,
2FA/MFA,
TOTP/HOTP,
USB-A and USB-C or USB-C,
NFC,
up to 200 passkeys,
up to 50 OATH locations,
designed with an aluminum cover,
intended for both individual and business use.
Thetis PRO with PinPlex
An extended version of the PRO series, also designed for applications requiring PIV functionality. USB-A,
USB-C,
NFC,
FIDO2,
WebAuthn,
CTAP2,
passkeys,
FIDO U2F,
TOTP,
HOTP,
PIV,
2FA/MFA,
PinPlex feature for enhanced PIN protection,
Performance of PIV certificates,
Usability for compatible system login and certificate infrastructure,
Intended for individual and corporate applications.
Thetis FIDO2 BioFP Security Key
Biometric model equipped with a fingerprint reader. Biometrics replaces PIN entry during FIDO2 operations.
Connector: USB-A,
Fingerprint reader,
FIDO2,
WebAuthn,
passkeys,
FIDO U2F,
2FA,
MFA,
Passwordless login,
TOTP/HOTP,
Local biometric verification,
Physical user identity confirmation with a fingerprint.
Thetis FIDO2 BioFP Plus Security Key
A newer biometric variant equipped with USB-C.
Connector: USB-C,
Fingerprint reader,
FIDO 2.1,
Passkeys,
Passwordless login,
FIDO U2F,
2FA/MFA,
TOTP/HOTP,
Fingerprint authentication,
Option to replace the PIN with a fingerprint during supported operations,
Intended for computers and devices with USB-C.
Thetis BLE FIDO2 Security Key
Variant offering three communication methods: USB-A, NFC, and Bluetooth. USB-A,
NFC,
Bluetooth,
FIDO2,
passkeys,
FIDO U2F,
2FA/MFA,
TOTP/HOTP,
passwordless login,
computer authentication via USB,
mobile device authentication via NFC,
Bluetooth designed for compatible Windows computers,
Bluetooth requires a built-in or external Bluetooth adapter,
the manufacturer recommends using NFC instead of Bluetooth on mobile devices.
Thetis FIDO U2F Security Key
The basic model of the previous generation, designed exclusively for FIDO U2F authentication.
Connector: USB-A,
FIDO U2F,
2FA,
MFA,
physical login confirmation,
compact design,
no FIDO2,
no passkey support,
no passwordless login in the FIDO2 standard.
This model is primarily intended for users of services that still use FIDO U2F as a second factor authentication.
Thetis BLE FIDO U2F Security Key
A version of the older U2F key, additionally equipped with Bluetooth communication.
USB-A,
Bluetooth,
FIDO U2F,
2FA,
MFA,
Ability to switch between USB and Bluetooth,
No FIDO2,
No passkeys,
No modern passwordless FIDO2 login.