Decision point
The practical question on this page is not simply “is what to do if a security key is lost secure?” It is which account, device or recovery path changes after the decision.
For What to Do If a Security Key Is Lost, this is a hardware-authentication decision page. Its goal is to plan enrollment, backup keys and loss response. Register at least two keys where the service permits and store them separately.
Why this topic matters
Loss is manageable when a backup key, recovery code or trusted device was prepared in advance.
- Core decisions
- Practical checklist
- Common mistakes
- Frequently asked questions
Primary and backup keys
Enroll at least two keys when the service permits it, and store the backup separately.
Device and travel use
Practical checklist
- Confirm the service supports the exact key protocol and connector you need.
- Enroll the primary and backup keys from a trusted device.
- Label keys without writing the account name or password on them.
- Test both keys and any recovery code.
- Review the account device and session list.
- Document replacement steps without storing the key PIN or recovery code in the document.
Common mistakes
- Owning only one enrolled key.
- Leaving the backup key in the same bag as the primary.
- Approving an unexpected sign-in because a key is present.
- Using a shared computer and leaving the session active.
- Assuming the key protects account recovery automatically.
How to document the decision
For each account, note ownership, recovery dependencies and when the decision will be revisited. Separate these governance notes from all live authentication material.
Frequently asked questions
Do security keys stop every phishing attack?
Do I need two keys?
A separate enrolled backup greatly reduces lockout risk.
Can a phone replace a hardware key?
Some services support phone-based passkeys or cross-device sign-in, but availability and recovery differ.
What happens if a key is stolen?
Can I share one key with a team?
Individual authentication and auditable roles are usually safer than a shared physical authenticator.
Technical reference points
Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.
Apply What to Do If a Security Key Is Lost to a real account
For What to Do If a Security Key Is Lost, write down the account owner, recovery email, trusted devices and the action that would cause the greatest damage. Then use the guidance above to reduce that specific risk. A generic “secure” status is less useful than knowing who can recover the account and how unauthorized access would be detected.
Verification before you finish
- Confirm the change from a trusted device.
- Test the new sign-in or recovery method.
- Check that an old session or fallback has not been left active unintentionally.
- Store recovery information away from the primary device.
- Record the next review owner if the account is shared or business-critical.