Cryptnox SA

Cryptnox FIDO2 White PVC — Customizable Hardware Security Key for 2FA, MFA & Passwordless

The Cryptnox FIDO2 White PVC card is the customizable variant of our basic FIDO2 security card — a single-application FIDO2 NFC smart card on a blank PVC face ready for in-house printing. FIDO Alliance Certified (FIDO2 v2.1 + CTAP Level 1) for hardware 2FA / MFA on every major FIDO2 / WebAuthn service. For corporate IT, MSPs, and resellers needing branded employee credentials.

ORDERS TO THE EU SHIP DIRECTLY FROM THE EU – NO IMPORT DUTIES

 39.00

Tax included. Shipping calculated at checkout.

Description

The Cryptnox FIDO2 White PVC card is the customizable variant of our basic FIDO2 security card — a single-application FIDO2 NFC smart card on a blank PVC face ready for in-house printing. FIDO Alliance Certified (FIDO2 v2.1 and CTAP Level 1), it’s used as a hardware 2FA / MFA second factor on every major FIDO2 / WebAuthn service. Passwordless sign-in is supported on the subset of services that have explicitly enabled FIDO2-only login (Microsoft Entra ID, Google Workspace, login.gov, AGOV, etc.).

Designed for branded enterprise rollouts

The blank White PVC face accepts standard ID card printers (dye-sublimation or thermal transfer) — Zebra, Evolis, Fargo, Magicard, Matica. Print employee photo, name, department, company logo, or any combination on each card. Inside, every card carries the same Swiss-engineered FIDO2 chip as our Cryptnox-branded variant. Typical buyers:

  • Corporate IT rolling out 2FA / MFA company-wide with branded employee credentials
  • MSPs and resellers applying client branding for white-label deployments
  • Compliance projects requiring documented FIDO2 hardware with visible card identifiers

Tap to authenticate — on phone or computer

The card supports both NFC and contact (ISO 7816) interfaces. Tap on any NFC-capable phone for FIDO2 sign-in; on a desktop or laptop, use a contactless smart card reader or a contact reader. For Windows desktop users on the contact interface, the Cryptnox dual-slot Smartcard Reader features a dedicated “tap” button that electronically simulates card extraction and reinsertion (Windows only). See the click-to-tap tutorial for the full workflow.

How this card differs from the rest of our FIDO2 lineup

  • This card (FIDO2 White PVC): single card, blank printable face, FIDO2 only.
  • FIDO2 (Cryptnox-branded): same FIDO2 capabilities with our standard Cryptnox branding (no in-house printing).
  • FIDO2 White PVC 25-pack: bulk pack of these same cards for enterprise IT rollouts.
  • FIDO2 + MIFARE White PVC: the same printable PVC face but with an additional MIFARE DESFire EV2 applet for physical access control on the same chip — choose this if you want one credential for both web auth and building doors.

What does FIDO2 mean?

FIDO2 is the modern open authentication standard (WebAuthn + CTAP2) for phishing-resistant strong authentication. Most services use FIDO2 cards as a hardware second factor — sign in with your password, then tap the card. A growing set of services (Microsoft Entra ID, Google Workspace, login.gov, AGOV) also support FIDO2-based passwordless sign-in. Backed by the FIDO Alliance — a consortium including Google, Microsoft, Apple, Amazon, and major banks — FIDO2 is the foundation of modern hardware-backed authentication on the web.

Features

Customize the card face for branded employee credentials

The blank White PVC surface is dimensioned to standard CR80 ID card printer specs. You can print:

  • Employee photo, name, department
  • Company logo and color branding
  • QR codes, NFC redirection tags, visible serial numbers
  • Optional laminate overlay for added durability

Most local ID badge services or corporate print departments can run a small batch if you don’t have an in-house printer.

Compatible services

  • Personal accounts: Google, Microsoft, Apple ID, Facebook, X, Dropbox, Bitwarden, 1Password
  • Developer & cloud: GitHub, GitLab, AWS, Cloudflare, Vercel, Fastly
  • Enterprise SSO: Okta, Auth0, Microsoft Entra ID, Google Workspace, Duo, Ping Identity
  • Government identity: login.gov (US), AGOV (Switzerland), SwissID
  • Compliance: required for OMB M-22-09; accepted under NIS2, DORA, NIST SP 800-63B AAL3, PCI DSS v4

Why hardware authentication matters

Software passkeys sync through cloud accounts (iCloud Keychain, Google Password Manager) — convenient, but a compromise of the cloud account compromises every passkey. The Cryptnox FIDO2 White PVC card stores keys inside a tamper-resistant secure-element chip that never touches any cloud. A phished attacker cannot remotely clone it — they’d need physical possession of the card and your PIN.

Easy to use, easy to deploy

  • Tap to authenticate on any NFC-capable phone (iOS for full FIDO2; Android for CTAP1 / U2F second-factor)
  • Contact mode for desktop: insert into any USB CCID-class smart card reader; for Windows, the Cryptnox dual-slot Smartcard Reader tap button streamlines the flow
  • No drivers required on Windows / macOS / Linux with any standard USB CCID smart card reader
  • No charging — passive NFC, no battery
  • No app required for daily use — register once on each service through the standard browser flow. The Cryptnox FIDO2 app is for advanced management only (PIN changes, factory reset, resident-key credentials).

Scaling beyond a single card

For deployments across an organization, see the FIDO2 White PVC 25-pack. For 500+ or pre-printed batches, get in touch via our contact form.

For setup walkthroughs, integration guides, and service-specific tutorials (Google, Microsoft, Apple, GitHub, Bank of America, login.gov, AGOV, SwissID), browse our FIDO2 tutorials hub.

Specifications

Technical specifications

  • Form factor: ISO/IEC 7810 ID-1 (CR80, credit-card size)
  • Card face: blank White PVC, ready for ID card printers
  • Interface: NFC (ISO/IEC 14443 Type A) + contact (ISO 7816)
  • Certification: FIDO Alliance Certified — FIDO2 v2.1 and CTAP Level 1
  • Standards supported: WebAuthn, CTAP2, FIDO U2F (legacy)
  • Secure element: EAL6+ certified chip
  • Power: passive — no battery, energy harvested from the NFC reader’s RF field
  • Operating systems: iOS (full FIDO2), Android (CTAP1 / U2F), Windows 10/11, macOS 11+, Linux (with Cryptnox FIDO2 HID bridge)

Compliance

  • FIDO Alliance Certified (FIDO2 v2.1 + CTAP Level 1)
  • ISO/IEC 7810 (card form factor)
  • ISO/IEC 7816 (contact interface)
  • ISO/IEC 14443 (NFC interface)

Frequently Asked Questions

Who is the FIDO2 White PVC security key designed for?

This is a blank-surface version of our FIDO2 smart card, intended for organizations that want to customize or brand their hardware:

  • Corporate IT rolling out 2FA company-wide — print each employee’s photo and name before handing the card over
  • Resellers and MSPs — apply your own branding on a FIDO Certified FIDO2 key for white-label deployment
  • Industry events — produce conference-branded FIDO2 keys as functional giveaways
  • Compliance-driven projects — tie a visible card identifier to a documented FIDO2 hardware inventory for audit

The white face is PVC, compatible with standard ID card printers that handle dye-sublimation or thermal transfer printing. The FIDO2 chip and antenna sit inside fixed zones, so printing in the designated card face area doesn’t affect electrical performance.

How do I customize or print the white PVC face?

The card is standard CR80 credit-card dimensions and works with any PVC ID card printer supporting dye-sublimation or direct-to-card thermal transfer. You can design in any card-printing software (CardFive, CardExchange, Badge Designer, or your printer’s native tool), then print text, logo, or employee photo on the printable area — keep clear of the chip module zone. A thin laminate overlay is optional but extends card life.

For small volumes, a single-card-input desktop ID printer is sufficient. For larger batches, dual-side auto-feed printers save time. If your organization doesn’t own card-printing equipment, most local ID badge services or promotional-merchandise vendors can run a batch for a per-unit fee.

Can I pre-enroll these FIDO2 cards for employees before distribution?

Yes — IT can register each card to the target user’s accounts before handing it over. Typical onboarding-at-scale workflow:

  1. Admin opens the target identity provider (Google Workspace, Microsoft Entra ID, Okta, Duo, etc.) in delegated-admin mode
  2. Sets a temporary PIN on the card and registers it to the user’s account by tapping it on an NFC reader
  3. Labels the card with the user’s name on the printable white face or a removable sleeve
  4. Hands the card to the employee along with the temporary PIN

The employee changes the PIN to their own on first use — either from Windows (Settings → Accounts → Sign-in options → Security Key → Manage) or via the Cryptnox FIDO2 app on a mobile device. The Cryptnox FIDO2 app is for advanced management only (PIN changes, factory reset, resident-key credentials) and is not required for day-to-day sign-in. After PIN setup, only the employee can use the card. Each card stores its FIDO2 keys on-chip, so enrollment is a one-time cryptographic binding and the employee doesn’t need to be present during the initial registration step. For enterprise-scale rollouts, some IdPs (Entra ID, Okta) support bulk passkey registration via API — useful for hundreds or thousands of cards.

OS and browser compatibility: iOS supports FIDO2 over NFC natively (any iPhone 7+). Android currently supports only CTAP1 / U2F (FIDO1) for external NFC keys — not FIDO2 / CTAP2. Most major services maintain CTAP1 backward compatibility, so the card works as a U2F second-factor authenticator on Android, but the feature set is reduced and CTAP1 implementations vary. macOS FIDO2-over-NFC support varies by version and browser. Linux browsers expect FIDO2 authenticators on a HID interface — use the Cryptnox FIDO2 HID bridge to present the card to the browser as an HID-FIDO device. Windows 10/11 has full FIDO2 support across all major browsers. Always test with your specific OS + browser + service before rolling out to employees.

FIDO2 hardware security key vs passkey — which do we actually need?

Passkeys and FIDO2 hardware security keys use the same underlying cryptographic protocol (WebAuthn), but they differ in where the private key lives:

  • Passkeys (software) sync through a cloud account — Apple iCloud Keychain, Google Password Manager, Microsoft account. Convenient, but if that cloud account is compromised, every passkey it holds is exposed.
  • FIDO2 hardware security key (this card) stores the private key inside a tamper-resistant secure-element chip that never touches any cloud. A phished attacker cannot clone it remotely — they’d need physical possession of the card and your PIN.

For consumer use (shopping, social media), passkeys are fine. For accounts that absolutely cannot be compromised — admin accounts, crypto exchanges, banking, government portals (login.gov, AGOV, SwissID), NIS2- and DORA-regulated logins — a hardware key is the industry-recommended approach. Many organizations deploy both: passkeys for low-risk logins, this FIDO2 card for privileged accounts.

Does this work for Windows Hello for Business workforce deployments?

Yes — the card is supported by Windows Hello for Business as a passwordless FIDO2 security key since Windows 10 version 1903 (fully in Windows 11), via Microsoft Entra ID (formerly Azure AD).

Standard enterprise deployment:

  1. IT enables the FIDO2 security key policy in Entra ID (Admin center → Protection → Authentication methods → FIDO2 security key)
  2. Optionally allow-lists the card’s AAGUID, or permits all FIDO2 keys
  3. Employees register the card via the Microsoft My Account portal, or IT pre-enrolls on their behalf
  4. At the Windows login screen, employees pick “Sign-in options → Security Key” and tap the card on an NFC reader (or place it on a contactless reader)

This delivers passwordless sign-in for Windows desktops, Microsoft 365, and every Entra ID-federated application. For shift-based and shared-workstation environments (call centers, healthcare, retail), passwordless FIDO2 cuts sign-in to a few seconds per shift change.

Select your currency
0
    0
    Shopping cart
    Your cart is emptyReturn to Shop