On June 15, 2007, eBay and PayPal announced the PayPal Security Key, a small physical token that generated a new one-time code about every 30 seconds. Customers entered that code along with a username and password when signing in to PayPal or eBay. It was an early form of two-factor authentication and was associated with the VeriSign Identity Protection (VIP) Network.
That announcement describes a historical token, not proof that PayPal still sells it or that it is supported today. PayPal’s newer passkeys are a separate, device-based sign-in method.
What PayPal announced in 2007
The June 15, 2007 announcement came jointly from eBay and PayPal. The Security Key was a physical device that displayed a fresh numerical code roughly every 30 seconds. During login, the customer supplied three pieces of information: a username, a password and the current code shown on the token.
Because the rotating code was required in addition to the password, PayPal described the product as two-factor authentication. The release identified the device as part of the VeriSign Identity Protection (VIP) Network.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
“While PayPal.com remains a trusted and secure environment, the PayPal Security Key allows customers to take their privacy and security into their own hands to help protect their eBay and PayPal accounts against unauthorized access.”
— Michael Barrett, PayPal chief information security officer, June 15, 2007 announcement
Rank #2
ATLKey USB-C Security Key for Passkey & 2FA, FIDO2/U2F Certified with 3-Side Touch & Multi-Color LED, Stores 100 Passkeys, Phishing-Resistant Login for Google, Microsoft, Apple & More, IP68 Waterproof
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
How the legacy Security Key worked
- Open PayPal or eBay and enter the account username.
- Enter the account password.
- Read the current code on the physical Security Key.
- Submit the rotating code before it changes.
The token did not replace the password. Its purpose was to add a time-changing factor that an attacker would not normally know from stealing or guessing a password alone.
Security Key versus a modern PayPal passkey
Passkeys should not be described as a renamed version of the 2007 token. They use a different credential model: a cryptographic key pair stored and used by a supported device. PayPal announced passkeys for eligible Apple-device users on PayPal.com in October 2022, then described a rollout to eligible U.S. Android users running Android 9 or later through Chrome mobile web in March 2023. Those announcements were rollout snapshots, not a complete current list of countries, devices or browsers.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
| Feature | 2007 PayPal Security Key | PayPal passkey |
|---|---|---|
| Credential form | Physical token displaying a changing code | Device-held cryptographic credential |
| Sign-in action | Username and password plus the current token code | Unlock the device with its biometric, PIN or device password |
| Biometric handling | Not applicable to the token | PayPal says biometric data is not shared with PayPal |
| Recovery if the device or factor is unavailable | Not established by the 2007 announcement | PayPal says password or one-time-passcode login remains available if a device is lost or stolen; additional authentication may still be required |
| Current availability evidence | Present-day sale or support is not established | Eligibility depends on the account and supported device/browser setup |
How to log in to PayPal with a passkey
If PayPal offers passkey enrollment for your account and device, the sign-in flow uses the device-unlock method already configured on that device. Depending on the platform, that can be a fingerprint, face recognition, PIN or device password. The exact availability and prompts can vary by account, operating system, browser and region.
- Open PayPal in a supported browser or app and choose the normal sign-in option.
- When PayPal presents a passkey prompt, select the passkey for that device.
- Approve the request with the device’s biometric, PIN or password.
- If the passkey is unavailable, use the password or one-time-passcode option PayPal provides, then complete any additional verification requested.
PayPal’s help material says the biometric check happens on the device; the biometric data itself is not sent to PayPal.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Has PayPal removed support for security keys?
The 2007 announcement does not establish that the physical token remains available, and the reviewed current PayPal material does not confirm present-day retail support for that legacy device. It also does not establish that a generic external FIDO hardware key works with PayPal’s current passkey implementation. Do not buy a token based solely on the 2007 announcement. Check the security or login settings in your PayPal account and PayPal’s current help pages for the options offered to you.
What PayPal says about passkey results
In a January 23, 2025 PayPal article, Rakan Khalid, senior director of Identity Product at PayPal and a FIDO Alliance board member, said the company planned to accelerate passkey availability in 2025. He also reported a “10%+ increase in login success rate with Passkeys compared with traditional password methods.” That is a PayPal-reported company statistic, not independent research and not a guarantee for every user.
Quick Recap
Practical guidance for account holders
- Do not confuse a 2007 rotating-code token with a current passkey.
- Use passkeys only when PayPal offers them for your account and supported device/browser combination.
- Keep a recovery method available, since PayPal documents password or one-time-passcode sign-in when a device is lost or stolen.
- Review PayPal’s live security settings before purchasing any external security key; compatibility with the legacy token or a third-party hardware key is not established by the cited announcements.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




