Your laptop doesn't have a port for your security key because many thin laptops dropped USB-A and kept two USB-C ports. The 13-inch MacBook Air M4 has two Thunderbolt 4 ports plus MagSafe. The Dell XPS 13 9350 has two Thunderbolt 4 ports and nothing else, and one of them charges the machine.
So a USB-A key needs an adapter, and even a USB-C key competes with your charger, your monitor and your dock. You have four ways out: buy a USB-C key, tap an NFC key against your phone, move to passkeys stored in software, or unlock your password manager with something that doesn't need a port at all. Each one solves a different part of the problem. Here's which part.
Where the ports went
This isn't a feeling. It's on the spec sheets.
| Laptop | Ports, per the manufacturer | Left for a security key |
|---|---|---|
| MacBook Air 13-inch, M4 (2025) | 2 × Thunderbolt 4 (USB-C), MagSafe 3, headphone jack | Two USB-C, if you charge over MagSafe |
| Dell XPS 13 9350 | 2 × Thunderbolt 4 (USB-C) with Power Delivery | One USB-C, once the charger is in |
Dell's own manual tells you to connect the power adapter to only one of the two ports. Headphones and displays go through adapters. That leaves one port for everything else you plug in, and a security key is one more thing.
Why this hurts security keys more than other accessories
A mouse can go Bluetooth. A monitor can go through a dock. A security key has to be there every time you sign in, and it has to be close enough to touch.
Yubico sells nano keys, like the YubiKey 5C Nano, that are meant to stay in the port permanently. That fixes the fumbling. It also means one of your two ports is gone for good.
And the key you already own might be the wrong shape. The YubiKey 5 series comes in USB-A, USB-C, NFC and Lightning variants. If you bought a USB-A YubiKey 5 NFC a few years ago, it doesn't fit a current MacBook Air without an adapter.
Your options, side by side
| Option | Needs a port? | Works on your phone? | Phishing-resistant? | What it costs you |
|---|---|---|---|---|
| USB-C security key | Yes, one USB-C | Yes, over USB-C, or NFC if the model has it | Yes (FIDO2) | A key, plus a spare |
| USB-A key with an adapter | Yes, plus the adapter | Depends on the model | Yes (FIDO2) | An adapter you'll lose |
| NFC security key, tapped on the phone | Not on the phone | Yes | Yes (FIDO2) | Only helps where there's an NFC reader |
| Passkeys in a software authenticator | No | Yes | Yes, for sites that support passkeys | Trusting the device or app that stores them |
| Password manager unlocked with a card | Not with phone NFC; a desk reader is USB | Yes, with phone NFC | No. It's a keycard, not a FIDO2 key | A card, and knowing its limits |
USB-C security key
The boring answer, and often the right one. A YubiKey 5C NFC plugs into USB-C and also taps against a phone. Register two, keep one somewhere safe. If your laptop lives on a desk with a dock, put the key in the dock and stop thinking about it.
NFC key on the phone
Fine for phones. On the laptop it only helps if the laptop has an NFC reader. Check yours before you count on it.
Passkeys
A passkey is a login stored in software (on your phone, in your browser, or in a password manager) instead of on a separate key. No port, nothing to carry. Sites have to support them, and plenty still don't. When a site does, signing in is a fingerprint or a PIN on your own device, and there's no password for anyone to steal.
SecureGate Card works as a software passkey authenticator in the Chrome extension and on Android 14 and later. iOS isn't available yet.
A card that unlocks your password manager
This is what we built, so here's the honest version.
With SecureGate Card, your vault opens three ways: tap a card on a reader, tap an NFC tag on your Android phone, or sign in with email and your master password. 2FA codes live in the same vault. Once it's open, the extension fills your logins.
A desk reader is a USB device too. The difference is that a reader stays on the desk, in the dock or the monitor, and the phone route needs no port at all. How unlocking with an NFC card works covers the setup.
What a card changes, and what it doesn't
A FIDO2 key does cryptography. When you sign in, the site sends a challenge, the key signs it, and the signature only works for that site. That's why a fake login page can't reuse it.
Our card doesn't do that. The reader reads the card's ID, and the ID opens your vault. It's the same idea as the keycard for your office building. Quick, convenient, and only as safe as your habit of not losing it.
So the card replaces typing your master password ten times a day. It doesn't replace a FIDO2 key on the accounts where a phishing attack would really hurt: your email admin, your domain registrar, your bank.
Used together, they don't compete. The card opens the vault. Inside the vault you can hold passkeys, which are phishing-resistant, for the sites that support them.
Which one to pick
- You sign in at a desk with a dock. A USB-C key in the dock. Done.
- You work from the laptop alone, on the move. Passkeys for the sites that support them, and a USB-C key on your keyring for the ones that don't.
- Your problem is typing the master password all day, not 2FA. That's what a card is for.
- You run IT for a small team and nobody will carry a key. A card they tap is easier to get people to use than a key they have to find. Just be clear with them about what it protects and what it doesn't.
- You need phishing-resistant sign-in for compliance. A FIDO2 key, or passkeys. Not a card.
When SecureGate Card fits, and when it doesn't
It fits if what bothers you is the friction of getting into your password manager, and you like the idea of a tap instead of a password. It fits a small team that wants shared vaults without handing everyone a USB key they'll leave at home. Personal is free. Team is €4 per user a month and Business €8, with a 14-day trial, all on the pricing page.
It doesn't fit if you want a hardware key that proves who you are with cryptography. Buy a USB-C YubiKey for that, and a spare. It also doesn't fit if you want a vault the provider can't read at all. SecureGate Card encrypts your vault with AES-256-GCM on our servers, using a key we hold. That isn't the same as Bitwarden or 1Password, which both encrypt on your device before anything leaves it. If that matters to you, they're the better choice, and you should know that before you sign up rather than after.