A person using a contactless payment method with a mobile phone and a red card in a card holder on a white surface, with a partially visible keyboard in the background.

ATKey.Card NFC User Guide

ATKey.Card NFC is the first fingerprint authenticated FIDO2 hardware key in Smart Card format. It supports FIDO and PKI identities to blend physical and digital access seamlessly.

Each ATKey.Card NFC has an 8-digit code on the card front under the FIDO2 logo. That is the ATKey serial number, a unique identifier for your ATKey.
You may need your serial number later for support, warranty, or enterprise registration.

In this guide you will find:

If you are looking to set up your Tapni digital business card on your ATKey.Card NFC, check this guide.

ATKey.Card NFC Compatibility

Feature Windows PC Mac iPhone Android
ATKey setting Via Device Account Setting Via SecurityKey Desktop APP Via SecurityKey NFC APP Via SecurityKey NFC APP
Major browser availability for NFC FIDO2 authentication Chrome, Edge Safari Chrome, Safari Chrome (U2F only)
Smart Card configuration Via SecurityKey Desktop APP Via SecurityKey Desktop APP - -
Smart Card authentication with fingerprint Via SecurityKey Desktop APP (AtPivToken) ATKey Smart Card Minidriver Via SecurityKey NFC APP -
PKCS#11 Library for fingerprint authentication Support via request Support via request - -

We provide the PKCS#11 library to integrate the fingerprint smart card verification with applications. Contact us for more information!

Anatomy of ATKey.Card NFC

Serial numbers are a unique 8 digits, hexadecimal codes that are not only printed on the key but also embedded in the firmware. They can be used to map users to their key in the lifecycle management software.

Serial numbers are also used to track which services each card supports, you can check yours here.

How to Enroll Your Fingerprint in Your ATKey.Card NFC for FIDO2

Fingerprint enrollment is easy and fast; it adds an extra layer of security and can be performed from any operating system.

Windows 11

  1. Connect your card to the PC with a card reader.

  2. On your computer go to Settings → Accounts → Sign-in options → Security Key → Manage.

  3. When prompted by the pop up select “Security Key PIN” and create a PIN for your card. This is a requirement in the FIDO2 system.

  4. Once you have set the PIN proceed to click “Security Key Fingerprint” from the same prompt menu. Follow the on-screen instructions. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. For best results, touch at different angles to ensure your fingerprint is fully captured and easily recognized in future authentications.

  5. You can register a maximum of 2 fingerprints.

MacOS

  1. To enroll your fingerprint from your Mac system you first need to download and install SecurityKey Desktop

  2. Launch the SecurityKey Desktop APP

  3. Connect your card to the PC with a card reader.

  4. In the tab “FIDO2”, follow the on-screen instructions to create a Security Key PIN. This is a requirement in the FIDO2 system.

  5. Follow the on-screen instructions to enroll your fingerprint. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. For best results, touch at different angles to ensure your fingerprint is fully captured and easily recognized in future authentications.

  6. You can register a maximum of 2 fingerprints.

iOS

  1. To enroll your fingerprint from your iOs device you first need to download and install SecurityKey NFC APP.

  2. Launch SecurityKey NFC APP.

  3. Click “Manage” and tap your card to the NFC area to scan.

  4. Click “PIN Code” and follow the on-screen instructions to create a Security Key PIN — required by FIDO2 and used for fingerprint management once enrollment is complete.

  5. Click “Fingerprint” and follow the on-screen instructions to enroll your fingerprint. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. For best results, touch at different angles to ensure your fingerprint is fully captured and easily recognized in future authentications.

  6. You can register a maximum of 2 fingerprints.

Android

  1. To enroll your fingerprint from your Android device you first need to download and install SecurityKey NFC APP.

  2. Launch SecurityKey NFC APP.

  3. Click “Manage” and tap your card to the NFC area to scan. The NFC reading area is located differently on different devices. Check your device specifications to know the best area to tap your card.

  4. Click “PIN Code” and follow the on-screen instructions to create a Security Key PIN — required by FIDO2 and used for fingerprint management once enrollment is complete.

  5. Click “Fingerprint” and follow the on-screen instructions to tap your card and enroll your fingerprint. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. Fingerprint enrollment on ATKey.Card NFC requires 4 successful touches on the sensor. For best results, touch at different angles to ensure your fingerprint is fully captured and easily recognized in future authentications.

  6. You can register a maximum of 2 fingerprints.

A person holding a red and white FIDO security card above a smartphone with a fingerprint scan screen. The phone displays instructions to keep the security key still on the sensor for four times.

Enable Fingerprint Authentication for PIV Login

Before you begin make sure to have completed the fingerprint enrollment on your ATKey.Card NFC.

The default values of PIV PINs:

  • PIN: 123456

  • PUK: 12345678

  • Management Key: 010203040506070801020304050607080102030405060708

Enable Fingerprint Protection

Windows PC

  1. You first need to download and install SecurityKey Desktop.

  2. Launch SecurityKey Desktop (run as administrator).

  3. Connect your card to the PC with a card reader.

  4. In the tab “PIV”, update the PIV PINs from the default values.

  5. Enable “Biometric protection” & “Protect management key with PIN/Biometric”.

MacOS

  1. You first need to download and install SecurityKey Desktop.

  2. Launch SecurityKey Desktop.

  3. Connect your card to the PC with a card reader.

  4. In the tab “PIV”, update the PIV PINs from the default values.

  5. Enable “Biometric protection” & “Protect management key with PIN/Biometric”.

Install Minidriver to Enable Fingerprint Authentication for PIV

Windows PC

  1. Download the ATKey Smart Card Mini driver.

    1. Supporting OS: Win11 x64, Win10 x64, x86, arm.

  2. Search and launch the Device Manager from the Windows search box.

  3. Expand the Smart Card section to view the current driver used.

  4. To update the driver to ATKey Smart Card Mini driver, right-click and select Update driver > Browse my computer for drivers > Set the location to the downloaded file in the first step > Next.

  5. A line of text, “Enter PIN or leave it empty to verify Fingerprint.” on the smart card verification dialogue. Touch the fingerprint sensor and click enter with the PIN field empty for fingerprint verification.

Windows PC

  1. The AtPivToken is included in the SecurityKey Desktop APP

  2. When the token driver is activated, a “Verify with your fingerprint notification” will show together with the “Smartcard verification pop-up” asking for the PIN

  3. Touch the fingerprint sensor and click enter with the PIN field empty to verify the fingerprint (hold until the loading is complete).

  4. In case the “Verify with your fingerprint notification” doesn’t show, read here how to enable the AT token driver manually.

    • Go to “System setting > General > SmartCards > SmartCard Drivers” to check all the smart card driver installed on the system.

    • In terminal, enter below command to enable only token driver “AtPivToken” by disabling the others
# ex: sudo defaults write /Library/Preferences/com.apple.security.smartcard DisabledTokens -array com.apple.CryptoTokenKit.pivtoken com.twocanoes.Smart-Card-Utility.pivtoken

    • Refresh system setting, and go to “System setting > General > SmartCards > SmartCard Drivers”, the token driver will be marked ” disabled” after disabling.

iOS

  1. Launch the SecurityKey NFC APP.

  2. Click “Manage” and NFC scan the card.

  3. In the side menu, go to “Certificates”.

  4. Click “+” to add the certificate public key to the device from the card. Certificates on devices are ready to be used for smart card authentication.

Register your accounts to enable FIDO2 passwordless login.

Limitations and Protections

ATKey.Card NFC is limited to 15 failed fingerprint verification before requiring PIN insertion to be unlocked. This is a soft lock. After a successful PIN verification ATKey.Card NFC can be used with fingerprint verification again. If the PIN is inserted wrong for 8 times ATKey.Card NFC is locked, requiring a complete reset to be used again. Resetting the card will erase all the credentials on the card.

NB. Fingerprint verification does not have a cool down period, if the card is kept on the reader with the sensor occupied it can go through multiple fingerprint verification in sequence. To avoid users to accidentally soft lock their card a limit of 3 verification per power cycle is in place. 5 power cycles can be performed before the card is soft locked.

For MacOS and iOS users, if their are using the card through Safari, continuous fingerprint failure will prompt the browser to ask for the PIN code. For cards with firmware before 5.0.6 due to forced fingerprint verification there is no PIN fallback. The user should restart the verification process to attempt fingerprint verification once more.

For ATKey.Card NFC with firmware 5.0.6 and above, PIN fallback is supported but is switched off by default. It can be activated through SecurityKey Desktop settings.

Frequently Asked Questions

How do I enable the Smart Card PIV function on my ATKey.Card NFC? 

Firstly you need to make sure that your card model supports Smart Card PIV. You can use the serial number printed on the card under the FIDO2 logo and this table to find out. 


Alternatively you can connect your card to the SecurityKey Desktop app and check if the PIV section is active. 

Once confirmed that your ATKey.Card NFC supports Smart Card PIV functions: 

  • Launch SecurityKey Desktop as Administrator

  • Connect your ATKey.Card NFC with your computer 

  • Go to the "Setting" tab 

  • Click "Manage" 

If PIV is supported, there will be a toggle next to the PIV section.    

Will my card reader be compatible with ATKey.Card NFC? 

ATKey.Card NFC is compatible with any NFC Contactless or 7816 smart Card Contact Reader that supports short and extended APDU commands.

This is necessary to run FIDO2 functions.

Compatibility can also be influenced by the OS or the browser you are employing. 
Here you can find a list of reader that we tested and found to be compatible.     

How many credentials can I stored in the ATKey.Card NFC? 

Each ATKey.Card NFC can contain up to: 2 fingerprints, 38 FIDO2 credentials, 11 KB of PIV certificates, and 1 URL for Tapni digital business card. 

I'm having trouble to authenticate with my fingerprint 

Make sure you are using one of the fingers you enrolled on the ATKey.Card NFC. 

Check if the card reader or your finger is dirty, dusty, oily, or have any sort of physical impediment to the correct functioning. 

If you have performed multiple attempts already remember: on cards with firmware 5.0.4 only 3 attempts can be performed before requiring the card to be moved away and replaced on the reader. If 5 blocks of 3 attempts are performed unsuccessfully the fingerprint function is blocked and is required to insert the PIN in order to unlock it. 

Can you recover the credentials in the ATKey.Card NFC if I forgot which fingerprint I registered? 

No.

ATKey.Card NFC provides its users with the highest level of security possible. All data are stored locally, and we do not provide any kind of backdoor for admin access. 

If you forgot which fingerprint you have enrolled with your ATKey.Card NFC, you can try to connect with SecurityKey Desktop using your PIN to access the fingerprint management.

If also this fails, the only possibility is to wipe the card, start from zero, and perform recovery access for any account you had credential stored on your ATKey.Card NFC. 

If your ATKey.Card NFC has been issued you by your employer and is part of a managed system, you may want to contact your IT team and verify with them what is the correct procedure.

Can I use ATKey.Card NFC on iPhone? 

Yes, ATKey.Card NFC works with the iPhone integrated NFC reader. It can be used for FIDO2 and PIV authentication as well as digital business card. 

Can I use ATKey.Card NFC on iPad? 

Yes, ATKey.Card NFC works with the iPad integrated NFC reader. It can be used for FIDO2 and PIV authentication as well as digital business card. 

Can I use ATKey.Card NFC on Android? 

Yes, ATKey.Card NFC works with any Android device with integrated NFC reader. FIDO U2F, PIV authentication, as well as digital business card. 

Need Help? Meet Your ATKey Setup Assistant

IIf you’re new to ATKey or setting up multiple devices, our Setup Assistant can walk you through the entire process.

Woman with black hair and glasses working on a laptop at a wooden desk in a modern office with a brick wall. The desk has a potted plant, open notebook, smartphone, and a blue mug. In the background, shelves with books, a camera, and office supplies, as well as various decorative items, are visible.
A man with a headset sitting at a desk in an office, smiling at his computer. There is a window with a plant and a gray wall with text behind him.