Nitrokey 3 review: open-source security key from Berlin
Our review of the Nitrokey 3: open-source Rust firmware, FIDO2 passkeys, OpenPGP and PIV, NFC and USB-C, plus prices and who should choose it.
ReviewsPublished
Provider
Nitrokey
Origin: Germany
Visit website
The Nitrokey 3 is one of the most complete open-source security keys you can buy in Europe. It handles FIDO2 passkeys and U2F for phishing-resistant logins, stores OpenPGP and PIV keys for email encryption and certificates, and can generate one-time passwords. Nitrokey says it develops and produces its devices in Germany, mainly in Berlin. This review is an editorial assessment based on the manufacturer’s documentation, published release notes and prices, not a laboratory test.
What the Nitrokey 3 offers
The Nitrokey 3 family comes in several variants. At the time of writing (October 2026), the Nitrokey shop lists the Nitrokey 3 from about 54 EUR, with the Nitrokey 3A NFC at 60 EUR and the Nitrokey 3C NFC at 65 EUR. A 3A Mini is the smallest USB-A variant. Availability varies, and some models have been listed as available on request.
| Feature | Nitrokey 3 |
|---|---|
| FIDO2 / U2F | Yes, passkeys and second factor |
| Passkey slots | Limited number of discoverable credentials (a few dozen on NFC models, up to 100 on the 3A Mini); non-discoverable credentials not limited the same way |
| Connections | USB-A or USB-C, NFC on the NFC models |
| OpenPGP | OpenPGP smart card, three key pairs |
| PIV | Up to 24 key pairs, usable for certificates and S/MIME |
| One-time passwords | TOTP and HOTP |
| Secure element | SE050, Common Criteria EAL 6+ certified according to Nitrokey |
| Firmware | Open source, written in Rust, updatable |
| Origin | Germany, mainly Berlin |
Nitrokey also sells a cheaper product called the Nitrokey Passkey, aimed at people who only need FIDO2 passkeys without OpenPGP and PIV.
Openness and security design
The strongest argument for the Nitrokey 3 is transparency. Hardware design and firmware are public, and the firmware is written in Rust, a language that avoids a whole class of memory errors. A secure element (SE050) handles sensitive operations, and since firmware version 1.7.0 it is activated by default for OpenPGP functions. The main processor is an ARM chip with TrustZone support.
Openness is not a security guarantee, but it changes who can find problems: anyone can read the code, and Nitrokey publishes release notes for each firmware version. Firmware updates are installed through the Nitrokey App 2 or the command-line tool nitropy, which means that bugs can be fixed after you have bought the key. Many competing keys cannot be updated at all.
On certification, Nitrokey reports that the Nitrokey 3A Mini has received FIDO2 level 1 certification and that work towards level 2 is under way with support from the NLnet Foundation. We do not rate a key on promises, so we treat level 2 as a plan, not a feature. If your employer or a regulated service requires a certified key, check the current FIDO Alliance certification listings and Nitrokey’s announcements before you buy.
Daily use
For logins you register the key like any other FIDO2 device. Sign in with a password, open the security settings of the service, choose “security key” or “passkey”, insert the key, enter the PIN and touch it. Because the browser checks the website address during the exchange, a fake page cannot use your key, which is the main benefit described in our guide to hardware security keys and in the explanation of phishing-resistant multi-factor authentication.
The extras are where the Nitrokey 3 differs from simpler keys. If you sign emails with GnuPG, use a smart card for SSH, or need S/MIME certificates, one device can cover all of that. Nitrokey’s own documentation notes some limits: the key is for cryptographic secrets, not for storing ordinary files, and it requires a recent firmware version for GnuPG compatibility. Desktop systems are better supported than phones for OpenPGP and PIV.
Limits and trade-offs
- Passkey capacity. The number of discoverable credentials is smaller than on some competitors. Nitrokey’s documentation and release notes have named figures from 25 to 35 for the NFC models and 100 for the Mini, so treat the number as “a few dozen”. For a handful of important accounts this is plenty. If you want to keep a hundred passkeys on the key itself, look at other models in our overview of hardware security keys.
- Convenience. Setup is a little more technical than with a mainstream key, particularly for OpenPGP and PIV. For pure FIDO2 use the difference is small.
- Price. At 54 to 65 EUR it costs about as much as a YubiKey and clearly more than a Token2 key.
- Availability. Production is small-scale, so stock can run short.
Who should buy it
Choose the Nitrokey 3 if you want open firmware, German production and support for OpenPGP and PIV in one key. It is a good fit for people who already use GnuPG, for journalists and activists who want verifiable components, and for anyone who prefers a European supplier. If you simply want passkeys with the widest software support and a long track record, the YubiKey 5 remains the more common choice, and our direct YubiKey vs Nitrokey comparison goes through the differences.
Whichever you buy, get two. Register both keys with every account and keep one at home in a safe place. Our guide to FIDO2 and WebAuthn explains why a key cannot be copied, and that is exactly why a spare matters.
How we assessed it
This page is built from Nitrokey’s documentation, release notes and shop listings, plus public statements about certification. We did not run lab tests, measure speeds or try to attack the hardware, and we do not give star ratings. Where sources disagree, for example on the exact passkey capacity, we say so instead of picking one number. Prices and availability were checked in October 2026 and can change at any time.
Setting it up sensibly
Before you register the key anywhere, update its firmware with the Nitrokey App 2 and set a PIN that you can remember but others cannot guess. Add the key to your most important accounts first: your email account, your password manager and your banking or payment logins. Keep recovery methods such as backup codes in place while you test, and remove weaker methods such as SMS only once both of your keys work. Our guide to account recovery explains how to do this without locking yourself out.
Verdict
The Nitrokey 3 is among the most open and flexible security keys in this category. Its weak points are a small passkey capacity compared with some rivals, a higher price than budget keys and a slightly technical setup. For people who care about openness, European production and OpenPGP, it is an easy recommendation. For everyone else it is a good, but not the only sensible, choice.
Frequently asked questions
Is the Nitrokey 3 really open source?
Nitrokey describes the Nitrokey 3 as open source and open hardware, and its firmware is written in the Rust programming language on the Trussed framework. That lets outside experts inspect and build the code. It does not by itself prove the device is secure, but it removes the need to trust a closed black box.
How many passkeys can a Nitrokey 3 hold?
The documentation names a limited number of discoverable credentials, in the range of a few dozen on the NFC models and up to 100 on the Nitrokey 3A Mini, and the exact figures have changed between firmware versions. Non-discoverable credentials are not limited in the same way. Check the current Nitrokey documentation before you buy.
Is the Nitrokey 3 FIDO certified?
Nitrokey reports that the Nitrokey 3A Mini received FIDO2 certification at level 1, and it is working with funding from the NLnet Foundation towards level 2. Certification status can change, so check the current Nitrokey announcements.
Can I update the firmware?
Yes. Updates are installed with the Nitrokey App 2 or the command-line tool nitropy. This is a difference to many other keys, whose firmware cannot be changed after production.
Does it work with iPhone and Android?
The NFC models work wirelessly with phones for FIDO2 logins, and Nitrokey lists Android and iOS support alongside Windows, macOS and Linux. Support for individual functions such as OpenPGP is better on desktop systems than on phones.
More in Reviews
1Password review 2026: security, features and price
1Password reviewed: Secret Key security, passkeys, EU account region, recovery rules, export and 2026 prices in euros. Who it suits and the alternatives.
2FAS Authenticator review: open source, no account
Review of 2FAS Auth, the free open-source authenticator from Poland: encrypted backup, export, browser extension, Apple Watch support, limits and who it suits.
Aegis Authenticator review: open-source 2FA for Android
Review of Aegis Authenticator: free GPL v3 2FA app for Android with an encrypted vault, automatic backups, export, audit log, limits and who should use it.
Best authenticator apps in 2026: 2FAS, Aegis, Ente Auth
The best authenticator apps for 2FA codes compared: 2FAS, Aegis and Ente Auth, with encrypted backup, export, open source, platforms and what to avoid.
Best free password managers in 2026: what you really get
Bitwarden, Proton Pass and KeePassXC offer genuinely usable free password managers, while Dashlane and 1Password no longer do. Limits and trade-offs explained.
Best password managers 2026: compared for European users
Seven password managers compared on encryption, audits, passkeys, EU data options, recovery, export and price, with advice on which one fits whom.