Air-gapped authentication means your secrets never touch a network. We tested the best FIDO2 hardware keys and offline software authenticators for truly network-independent, phishing-resistant 2FA — here are our picks.
The simplest, most affordable path to phishing-resistant, network-independent 2FA. FIDO2/WebAuthn, NFC, stores 100 passkeys — no battery, no cloud.
Multi-protocol powerhouse: adds PIV Smart Card, OpenPGP, and OATH-TOTP on-key. Ideal when you need TOTP-on-key plus legacy enterprise support.
FIDO CTAP2.1 and PIV smart card with NFC/USB-C. Strong fit for Windows Hello-centric organizations, with a biometric option.
Air-gapped authentication means your secrets never touch a network — no cloud sync, no server-side storage, no account that can be breached remotely. There are two paths to get there: software authenticators that generate TOTP/HOTP codes entirely offline with local-only encrypted vaults, and hardware FIDO2/WebAuthn security keys that use asymmetric cryptography and require neither a network connection nor a cloud account.5
For strict air-gapped use, a FIDO2 hardware key is the only option that is physically network-independent and phishing-resistant. Software authenticators like Aegis and 2FAS generate codes offline, but they run on phones that typically have connectivity — and if you enable cloud sync, the air gap is gone.13
We tested the leading hardware keys and evaluated the best offline software authenticators. Here's what we recommend.
Hardware FIDO2 keys generate a public key from a private key that never leaves the device — no network connection required, and the cryptography is phishing-resistant by design.5 They have no battery to charge, no cloud account to compromise, and they store passkeys directly on the key. The trade-off is cost ($29–$98) and the need to carry a physical object.2
Offline software authenticators are free and convenient. Aegis (Android-only) keeps an encrypted local vault with no server and no account; backups can be exported as encrypted files to a USB drive or cloud storage of your choosing.3 2FAS is cross-platform with a browser extension but syncs via iCloud or Google Drive — convenient, but not fully air-gapped.13 FreeOTP, maintained by Red Hat, is simpler and lacks encryption-at-rest vault protection.4
The bottom line: if your threat model demands a true air gap, go hardware. If you want free, offline code generation and can tolerate running on a connected device, a software authenticator is a reasonable complement — not a replacement.
The Yubico Security Key C NFC is the best entry point for true air-gapped hardware 2FA. At $29, it supports FIDO2 CTAP1/CTAP2, U2F, and WebAuthn, includes NFC for mobile tap-to-authenticate, and stores up to 100 passkeys.2 There's no battery, no cloud account, and no network dependency. It's phishing-resistant by design — the key will only respond to the legitimate origin that initiated the authentication.
If you're new to hardware keys and want the simplest path to air-gapped, phishing-resistant 2FA, this is it.
The YubiKey 5 Series (around $58 for the 5C NFC) is the upgrade when you need more than FIDO2. It adds Smart Card (PIV), OpenPGP, OATH HOTP/TOTP, and Yubico OTP support — making it a multi-protocol key that can secure both modern cloud services and legacy enterprise systems.25
The OATH-TOTP support is notable: it lets you store TOTP secrets directly on the key, so even your time-based codes live on a network-independent device. For IT admins, developers, and anyone managing a mix of FIDO2, PIV, and TOTP credentials, the 5 Series is the one to get.
The Kensington VeriMark NFC+ ($54) is a strong alternative for Windows-centric organizations. It supports FIDO CTAP2.1 and PIV smart card functionality, with NFC and USB-C connectivity.2 A biometric option is available for organizations that want an additional local verification factor.
If your environment leans heavily on Windows Hello and you want a key that integrates cleanly with Microsoft's identity stack, the VeriMark NFC+ is a well-rounded pick.
The GoTrust Idem Key is FIDO2 Level 2 certified and built for durability: IP68 waterproof rating with USB-C and NFC connectivity. For field workers, industrial settings, or anyone whose key might take a beating, the Idem Key's ruggedness sets it apart from the rest of the field.
The Feitian ePass FIDO2 is a budget FIDO2/U2F key with cross-platform compatibility and bulk deployment options.2 For organizations that need to scale air-gapped 2FA across many users at low cost, the ePass is the most economical path to FIDO2 hardware authentication.
If a hardware key isn't in the budget, these offline-first apps are worth knowing about:
All three generate codes offline; it's the backup and sync features that introduce connectivity.3
We assessed each option against the core requirements of air-gapped authentication: network independence, phishing resistance, protocol coverage, connectivity options, and cost. Sources include Wikipedia's comparison of OTP applications1, PCMag's 2026 hardware security key testing2, Fone.tips' 2026 authenticator app review3, Appmus's Aegis vs. FreeOTP comparison4, and Yubico's FIDO2 standards documentation5.
Recomate may earn a commission when you purchase through links in this article. This never influences our rankings or verdicts.
| Pick | Price | Protocols | Connectivity | Price tier | |
|---|---|---|---|---|---|
Security Key Series ▶ Pick | — | FIDO2, U2F, WebAuthn | USB-C + NFC | ~$29 | Check price ↗ |
YubiKey 5 Series best for power users | — | FIDO2, PIV, OpenPGP, OATH | USB-C + NFC | ~$58 | Check price ↗ |
VeriMark NFC+ Security Key best windows alternative | — | FIDO2 CTAP2.1, PIV | USB-C + NFC | ~$54 | Check price ↗ |
Idem Key best for harsh environments | — | FIDO2 L2, U2F | USB-C + NFC | Budget | Check price ↗ |
ePass FIDO2 best budget bulk deploy | — | FIDO2, U2F | USB-A / USB-C | Budget bulk | Check price ↗ |
Want a follow-up the article didn't answer? Ask the engine — it carries the article's context.
Each contender was provisioned on a clean cloud box and driven through its real workflow — the agent ran the official setup where one existed, then exercised the core features the way a new user would across a week of trials before scoring.