A
security key is a physical device used to prove a sign-in, commonly through FIDO2/WebAuthn. In that flow, the browser and key bind the response to the site's real domain, so a copied login page cannot simply relay the same proof to a different domain. Some keys also offer other modes; not every use of a hardware token has this protection.
A useful example
You reach a fake webmail login and enter your password. The impostor asks for your security key. A FIDO sign-in should reject the wrong site origin instead of completing the genuine account login. The password may still be exposed, so change it on the real site.
Before you rely on one
Check which key protocols your services support, register a backup method and store it safely. Losing your only registered key without recovery can lock you out. NIST explains
phishing-resistant authentication; our
authenticator migration guide covers the broader recovery planning.
Practical distinction
A FIDO/WebAuthn sign-in is bound to the website origin. A one-time code displayed by a hardware token can still be typed into a fake site, so check which mode the service uses.