What Nitrokey actually does
Nitrokey (Nitrokey GmbH, Berlin) manufactures open-source hardware security keys: small USB-A or USB-C devices, some with NFC, that store cryptographic keys and perform cryptographic operations physically on the device rather than in software on the host computer. That physical separation means a compromised computer generally cannot extract the private keys stored on the token, which is a fundamentally different security model from a software password manager or browser-based 2FA.
The core product
The lineup spans several purpose-built models. The Nitrokey Start focuses on email encryption (GnuPG, OpenPGP, S/MIME) and disk/file protection. The Nitrokey Passkey is a dedicated FIDO2 passwordless-login key. The Nitrokey 3 series (available in USB-A and USB-C, with or without NFC) combines FIDO2, one-time-password generation, and OpenPGP smart-card functions in one device. Further up, the Pro 2 and HSM 2 target smart-card and server/PKI use cases, and the Storage 2 adds 64GB of hardware-encrypted storage with hidden-volume support for concealing sensitive data even if the device itself is seized.
What's new or notable
Nitrokey continues to publish its firmware as open source, letting independent researchers audit the actual code running on the device rather than relying on the manufacturer's word — a meaningfully stronger transparency claim than most software-based privacy products in this list can make. This puts Nitrokey in direct contrast to closed-firmware hardware keys from larger competitors, where the community has to trust the vendor's own security claims without being able to inspect the code that actually runs on the chip.
Nitrokey also targets business and IT-administrator use cases alongside individual consumers — the HSM 2 in particular is built for server-side certificate authority and public-key-infrastructure work rather than personal login security, which means the product range spans from a casual user wanting FIDO2 passkeys all the way to an organization managing its own certificate infrastructure, all from one small independent manufacturer.
Who should use Nitrokey
Great fit if…
- You want hardware-backed 2FA or encryption — private keys never leave the physical device.
- You're tired of subscriptions — this is a genuine one-time purchase with nothing to renew.
- You value inspectable, open-source firmware — Nitrokey's code can be independently reviewed rather than trusted blindly.
Skip it if…
- You want a plug-and-play consumer product — configuring OpenPGP or SSH key storage takes real technical effort.
- You need 24/7 live support — Nitrokey's support is email and community-forum based.
- You just want the cheapest possible FIDO2 key — Nitrokey's pricing reflects open-source, EU-manufactured hardware rather than mass-market commodity pricing.
Pricing in detail
Every Nitrokey is a one-time hardware purchase with no subscription attached. Prices below are per unit, current on the official Nitrokey shop.
| Plan | Price | What's included |
|---|---|---|
| Nitrokey Start | 28,80€ (one-time) | Email encryption, OpenPGP, disk/file protection |
| Nitrokey Passkey | 32,00€ (one-time) | FIDO2 passwordless login |
| Nitrokey 3A/3C (No NFC) | 48,00€–52,00€ (one-time) | FIDO2, OTP, OpenPGP combined |
| Nitrokey 3 NFC variants | 60,00€–79,00€ (one-time) | Adds NFC contactless use |
| Nitrokey Pro 2 / HSM 2 | 109,00€ (one-time) | Smart-card / server PKI use cases |
| Nitrokey Storage 2 (64GB) | 199,00€ (one-time) | Hardware-encrypted storage with hidden volumes |
Where it falls short
- Not beginner-friendly — advanced features assume familiarity with GPG, SSH keys or smart-card concepts.
- You can lose it — like any hardware key, losing the device without a backup key configured can lock you out of accounts.
- No mobile-first experience — while NFC models work with Android, iOS support for hardware security keys is generally more restricted at the OS level than on desktop or Android.
Privacy & data
Nitrokey GmbH is based in Berlin and operates under German and EU law. Because the product is hardware you own outright with open-source firmware, there's no ongoing data relationship with the company after purchase — no account, no telemetry subscription, no cloud sync of your keys. That one-time transaction model is itself a privacy feature: unlike a VPN or cloud subscription that requires an ongoing account relationship (and therefore ongoing billing data, login history and potential profiling), a Nitrokey purchase can be entirely anonymous after checkout, since the device doesn't phone home or require registration to function. The only ongoing data footprint is whatever the shipping and payment process itself requires, which is a far smaller and shorter-lived exposure than any recurring subscription generates over years of billing cycles.
How we checked this
Pricing verified directly on shop.nitrokey.com on 2026-09-05, cross-checking the entry-level Nitrokey Start price against the individual product page.
What you get, what you give up
What you get
- One-time purchase — no subscription, no renewal, no recurring fee ever
- Open-source firmware that can be independently inspected, rather than a closed black box
What you give up
- Setup for advanced use (OpenPGP email encryption, SSH key storage) requires real technical comfort, not a one-tap install
- Support is community forum and email based, no 24/7 live chat