What is Security Keys?
A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key. With WebAuthn, it creates a key pair scoped to a relying party and signs a fresh challenge after user presence or user verification. This verifier binding makes WebAuthn phishing-resistant. A key proves control of a credential. It does not by itself authenticate the general-purpose device or authorize access.
Why it matters
A security key can resist credential phishing because its WebAuthn credential is bound to the relying party. The private key also stays in the authenticator instead of being sent to the service.
How it works
- During registration, the authenticator creates a key pair for the relying party and returns the public credential data.
- During authentication, the relying party sends a fresh challenge and the authenticator requires user presence or user verification.
- The authenticator signs the challenge, and the relying party verifies the signature and ceremony data.
Example
An administrator touches a USB security key to satisfy a WebAuthn device requirement before Pomerium allows access to an operations route.
Pomerium boundary
Pomerium can use WebAuthn for clientless device identity checks on protected routes. The browser and authenticator perform the WebAuthn ceremony, and Pomerium policy decides whether the registered device context is sufficient for access.
Limits and non-claims
- A security key does not by itself prove full device posture or authorize an application action.
- Organizations need enrollment, loss, recovery, replacement, and revocation procedures.
- Roaming keys, platform authenticators, and synchronized passkeys have different custody and recovery properties.
Evaluation checklist
- Does the verifier validate challenge, origin, relying-party identifier, signature, and user-verification state?
- How are keys enrolled, recovered, replaced, revoked, and protected from unauthorized registration?
- Do roaming, platform, or synchronized credentials match the required custody and recovery model?
