Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

PayPal Announces Security Key: What the 2007 Token Was—and What Replaced It

PayPal’s 2007 Security Key was a physical two-factor token, not the same as today’s passkeys. Here’s how the device worked, what PayPal’s passkeys do, and what current support remains unconfirmed.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On June 15, 2007, eBay and PayPal announced the PayPal Security Key, a small physical token that generated a new one-time code about every 30 seconds. Customers entered that code along with a username and password when signing in to PayPal or eBay. It was an early form of two-factor authentication and was associated with the VeriSign Identity Protection (VIP) Network.

That announcement describes a historical token, not proof that PayPal still sells it or that it is supported today. PayPal’s newer passkeys are a separate, device-based sign-in method.

What PayPal announced in 2007

The June 15, 2007 announcement came jointly from eBay and PayPal. The Security Key was a physical device that displayed a fresh numerical code roughly every 30 seconds. During login, the customer supplied three pieces of information: a username, a password and the current code shown on the token.

Because the rotating code was required in addition to the password, PayPal described the product as two-factor authentication. The release identified the device as part of the VeriSign Identity Protection (VIP) Network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

“While PayPal.com remains a trusted and secure environment, the PayPal Security Key allows customers to take their privacy and security into their own hands to help protect their eBay and PayPal accounts against unauthorized access.”

— Michael Barrett, PayPal chief information security officer, June 15, 2007 announcement

Rank #2
ATLKey USB-C Security Key for Passkey & 2FA, FIDO2/U2F Certified with 3-Side Touch & Multi-Color LED, Stores 100 Passkeys, Phishing-Resistant Login for Google, Microsoft, Apple & More, IP68 Waterproof
  • PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
  • 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
  • MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
  • IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
  • UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.

How the legacy Security Key worked

  1. Open PayPal or eBay and enter the account username.
  2. Enter the account password.
  3. Read the current code on the physical Security Key.
  4. Submit the rotating code before it changes.

The token did not replace the password. Its purpose was to add a time-changing factor that an attacker would not normally know from stealing or guessing a password alone.

Security Key versus a modern PayPal passkey

Passkeys should not be described as a renamed version of the 2007 token. They use a different credential model: a cryptographic key pair stored and used by a supported device. PayPal announced passkeys for eligible Apple-device users on PayPal.com in October 2022, then described a rollout to eligible U.S. Android users running Android 9 or later through Chrome mobile web in March 2023. Those announcements were rollout snapshots, not a complete current list of countries, devices or browsers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Feature 2007 PayPal Security Key PayPal passkey
Credential form Physical token displaying a changing code Device-held cryptographic credential
Sign-in action Username and password plus the current token code Unlock the device with its biometric, PIN or device password
Biometric handling Not applicable to the token PayPal says biometric data is not shared with PayPal
Recovery if the device or factor is unavailable Not established by the 2007 announcement PayPal says password or one-time-passcode login remains available if a device is lost or stolen; additional authentication may still be required
Current availability evidence Present-day sale or support is not established Eligibility depends on the account and supported device/browser setup

How to log in to PayPal with a passkey

If PayPal offers passkey enrollment for your account and device, the sign-in flow uses the device-unlock method already configured on that device. Depending on the platform, that can be a fingerprint, face recognition, PIN or device password. The exact availability and prompts can vary by account, operating system, browser and region.

  1. Open PayPal in a supported browser or app and choose the normal sign-in option.
  2. When PayPal presents a passkey prompt, select the passkey for that device.
  3. Approve the request with the device’s biometric, PIN or password.
  4. If the passkey is unavailable, use the password or one-time-passcode option PayPal provides, then complete any additional verification requested.

PayPal’s help material says the biometric check happens on the device; the biometric data itself is not sent to PayPal.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Has PayPal removed support for security keys?

The 2007 announcement does not establish that the physical token remains available, and the reviewed current PayPal material does not confirm present-day retail support for that legacy device. It also does not establish that a generic external FIDO hardware key works with PayPal’s current passkey implementation. Do not buy a token based solely on the 2007 announcement. Check the security or login settings in your PayPal account and PayPal’s current help pages for the options offered to you.

What PayPal says about passkey results

In a January 23, 2025 PayPal article, Rakan Khalid, senior director of Identity Product at PayPal and a FIDO Alliance board member, said the company planned to accelerate passkey availability in 2025. He also reported a “10%+ increase in login success rate with Passkeys compared with traditional password methods.” That is a PayPal-reported company statistic, not independent research and not a guarantee for every user.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical guidance for account holders

  • Do not confuse a 2007 rotating-code token with a current passkey.
  • Use passkeys only when PayPal offers them for your account and supported device/browser combination.
  • Keep a recovery method available, since PayPal documents password or one-time-passcode sign-in when a device is lost or stolen.
  • Review PayPal’s live security settings before purchasing any external security key; compatibility with the legacy token or a third-party hardware key is not established by the cited announcements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.