Nitrokey Affordable

Security & Privacy · USB-A/USB-C hardware security key, used with Windows, macOS, Linux, BSD and Android (NFC models) · switch in Ships as physical hardware; register FIDO2/OpenPGP credentials in minutes once it arrives, no account or subscription to ever cancel

Best for: Best for people who'd rather buy one physical key outright than pay another monthly fee to secure logins, email and disk encryption

The verdict

Reviewed by Matthis Duarte · checked 2026-09-05 · how we check

Nitrokey is a Berlin-based, independent manufacturer of open-source hardware security keys — small USB devices that store cryptographic keys physically, outside the reach of malware on the host computer. Unlike every other entry in this category, Nitrokey isn't a subscription: you buy a specific model once and own it, with no recurring fee and nothing to cancel later. The lineup ranges from the entry-level Nitrokey Start (email encryption and OpenPGP smart-card functions) and Nitrokey Passkey (pure FIDO2 passwordless login) up through the Nitrokey 3 series that combines FIDO2, one-time passwords and OpenPGP in a single key, and specialist models like the Pro 2, HSM 2 (server/PKI use) and the Storage 2, which adds 64GB of hardware-encrypted storage with hidden-volume support. Nitrokey publishes its firmware as open source, which lets outside researchers actually inspect what the device does rather than trusting a closed black box — a meaningfully different privacy posture than a VPN or cloud app asking you to trust a no-logs policy. The trade-off is friction: setting up OpenPGP email encryption or SSH key storage is not a one-tap process the way installing a VPN app is, and support is community- and email-based rather than 24/7 live chat. This is a tool for people who already know they want hardware-backed 2FA or encryption, not a mass-market privacy app.

Based inGermany
This costs€28.80once
Score73/100

How we scored it

Price15/20
Ease of use12/20
Security & privacy19/20
Feature completeness15/20
Support & reliability12/20

73 out of 100. Each of the five criteria is judged on its own, 0 to 20, and the five add up — never measured against another product. How we score.

What Nitrokey actually does

Nitrokey (Nitrokey GmbH, Berlin) manufactures open-source hardware security keys: small USB-A or USB-C devices, some with NFC, that store cryptographic keys and perform cryptographic operations physically on the device rather than in software on the host computer. That physical separation means a compromised computer generally cannot extract the private keys stored on the token, which is a fundamentally different security model from a software password manager or browser-based 2FA.

The core product

The lineup spans several purpose-built models. The Nitrokey Start focuses on email encryption (GnuPG, OpenPGP, S/MIME) and disk/file protection. The Nitrokey Passkey is a dedicated FIDO2 passwordless-login key. The Nitrokey 3 series (available in USB-A and USB-C, with or without NFC) combines FIDO2, one-time-password generation, and OpenPGP smart-card functions in one device. Further up, the Pro 2 and HSM 2 target smart-card and server/PKI use cases, and the Storage 2 adds 64GB of hardware-encrypted storage with hidden-volume support for concealing sensitive data even if the device itself is seized.

What's new or notable

Nitrokey continues to publish its firmware as open source, letting independent researchers audit the actual code running on the device rather than relying on the manufacturer's word — a meaningfully stronger transparency claim than most software-based privacy products in this list can make. This puts Nitrokey in direct contrast to closed-firmware hardware keys from larger competitors, where the community has to trust the vendor's own security claims without being able to inspect the code that actually runs on the chip.

Nitrokey also targets business and IT-administrator use cases alongside individual consumers — the HSM 2 in particular is built for server-side certificate authority and public-key-infrastructure work rather than personal login security, which means the product range spans from a casual user wanting FIDO2 passkeys all the way to an organization managing its own certificate infrastructure, all from one small independent manufacturer.

Who should use Nitrokey

Great fit if…

  • You want hardware-backed 2FA or encryption — private keys never leave the physical device.
  • You're tired of subscriptions — this is a genuine one-time purchase with nothing to renew.
  • You value inspectable, open-source firmware — Nitrokey's code can be independently reviewed rather than trusted blindly.

Skip it if…

  • You want a plug-and-play consumer product — configuring OpenPGP or SSH key storage takes real technical effort.
  • You need 24/7 live support — Nitrokey's support is email and community-forum based.
  • You just want the cheapest possible FIDO2 key — Nitrokey's pricing reflects open-source, EU-manufactured hardware rather than mass-market commodity pricing.

Pricing in detail

Every Nitrokey is a one-time hardware purchase with no subscription attached. Prices below are per unit, current on the official Nitrokey shop.

PlanPriceWhat's included
Nitrokey Start28,80€ (one-time)Email encryption, OpenPGP, disk/file protection
Nitrokey Passkey32,00€ (one-time)FIDO2 passwordless login
Nitrokey 3A/3C (No NFC)48,00€–52,00€ (one-time)FIDO2, OTP, OpenPGP combined
Nitrokey 3 NFC variants60,00€–79,00€ (one-time)Adds NFC contactless use
Nitrokey Pro 2 / HSM 2109,00€ (one-time)Smart-card / server PKI use cases
Nitrokey Storage 2 (64GB)199,00€ (one-time)Hardware-encrypted storage with hidden volumes

Where it falls short

  • Not beginner-friendly — advanced features assume familiarity with GPG, SSH keys or smart-card concepts.
  • You can lose it — like any hardware key, losing the device without a backup key configured can lock you out of accounts.
  • No mobile-first experience — while NFC models work with Android, iOS support for hardware security keys is generally more restricted at the OS level than on desktop or Android.

Privacy & data

Nitrokey GmbH is based in Berlin and operates under German and EU law. Because the product is hardware you own outright with open-source firmware, there's no ongoing data relationship with the company after purchase — no account, no telemetry subscription, no cloud sync of your keys. That one-time transaction model is itself a privacy feature: unlike a VPN or cloud subscription that requires an ongoing account relationship (and therefore ongoing billing data, login history and potential profiling), a Nitrokey purchase can be entirely anonymous after checkout, since the device doesn't phone home or require registration to function. The only ongoing data footprint is whatever the shipping and payment process itself requires, which is a far smaller and shorter-lived exposure than any recurring subscription generates over years of billing cycles.

How we checked this

Pricing verified directly on shop.nitrokey.com on 2026-09-05, cross-checking the entry-level Nitrokey Start price against the individual product page.

What you get, what you give up

What you get

  • One-time purchase — no subscription, no renewal, no recurring fee ever
  • Open-source firmware that can be independently inspected, rather than a closed black box

What you give up

  • Setup for advanced use (OpenPGP email encryption, SSH key storage) requires real technical comfort, not a one-tap install
  • Support is community forum and email based, no 24/7 live chat

What we check on every tool

Five things get checked on every tool, free or paid, and the answers are printed on the page with the date they were checked. Nothing is hidden because it looks unflattering — a tool with a short trial is listed exactly like any other, and labelled so you know what you are signing up for.

Legal options only. No cracks, no key resellers, no stream-ripping. Read the policy →

  • 1Card up front? Whether you have to hand over card details before you can use it at all.
  • 2Does it expire? Whether the free version stops working after a set number of days.
  • 3Where's the wall? Whether the free tier's real limit — an advert, a quota, or a feature held back for the paid plan — is named, not left vague.
  • 4Easy to cancel? How many steps it takes to stop paying, and whether it auto-renews quietly.
  • 5Still maintained? Whether the project has shipped anything in the last twelve months.