YubiKey 5C NFC
The default hardware security key for anyone with a USB-C laptop and a modern phone.
TL;DR verdict
Boringly reliable. The 5C NFC covers the widest range of real-world logins of any single key we've tested, and it will still be working long after whatever laptop you plug it into has been retired. Buy two.
What we like
- Rock-solid FIDO2 and WebAuthn with NFC for mobile
- Works with almost every major site and most password managers
- No battery, no firmware update anxiety, essentially indestructible
- Sweden-based vendor with a long, unblemished security record
Where it falls short
- You'll lose it eventually — get two and register both up front
- NFC on iPhone requires the phone awake and near the top of the device
- Once shipped, firmware can't be updated, by design
The YubiKey 5C NFC is the key we hand to people who ask which one to buy. It works with the widest range of laptops and phones, it supports every current authentication protocol worth caring about, and Yubico has been shipping these things without a serious incident for long enough that the question of trust is essentially answered.
What it does well
The 5C NFC is the workhorse of the range. USB-C for the laptop, NFC for the phone, and support for FIDO2, WebAuthn, U2F, smart card, OpenPGP, and OATH-TOTP all on the same piece of plastic. In practice you will use maybe two of those protocols. The point is that whichever of your important services picks a horse, this key is already on it.
There is no battery, no screen, no companion app that has to keep running. You touch the gold disc when the browser asks you to. That's the whole interaction. This is why hardware keys tend to still be working ten years in, when everything else you bought the same week has been landfilled.
Support is now genuinely broad. Every major identity provider, every password manager we recommend, most banks that have caught up, and the platform accounts from Apple, Google, and Microsoft all accept it. Passkey storage on the key itself is limited to 25 discoverable credentials, which is enough for the accounts that actually matter and not enough to become a full replacement for a vault.
Where it disappoints
Firmware on shipped keys can't be updated. This is deliberate; a key that can be reflashed can be reflashed by an attacker. It also means that if a new attack ever landed against the current firmware, you'd need to buy new hardware. There is no free lunch here.
NFC on iPhone is the other small friction. It works, but you have to hold the key against the top third of the phone with the screen on, and the tap window is short. Android is more forgiving.
Who it's for
Anyone using a password manager should already own two of these. Journalists working with sensitive accounts should treat them as non-negotiable. Travellers get real value from the fact that a physical key in your pocket is not phishable, however convincing the fake login page in the hotel wifi captive portal looks. Parents setting up a family's shared accounts will find that a pair of these on the main accounts prevents the majority of the "someone got into mum's Amazon" incidents that make up most of the household security we get asked about.
Buy two, register both, and forget about them for a decade.
Frequently asked
Do I need a YubiKey if I already use a password manager?
A password manager protects your accounts. A YubiKey protects your password manager. If someone gets past your vault's master password, a hardware key is what stops them going any further.
Should I buy one YubiKey or two?
Two. Register both against every important account and store the second one somewhere you don't carry daily. When you lose the first one, and you will, the second is the difference between an inconvenience and a bad week.
Will it work with my iPhone?
Yes, over NFC or by plugging into the USB-C port on newer models. The NFC handshake is fussier than on Android, but it works.