ArkWarden is the first and only iPhone vault that supports a YubiKey. Your pattern derives the encryption key. A YubiKey adds a second factor stored on separate hardware, not on the phone. Tap the key against your iPhone over NFC. The vault opens only after both checks pass.
Both Face ID and PIN are stored on the phone. A YubiKey is separate hardware. Someone who takes your phone does not also have the key.
Your pattern derives the key that decrypts your files. A second factor is checked after the pattern succeeds, before the vault is shown. Many second factors are stored or verified on the phone. A YubiKey is different because it is separate hardware.
Because the key is physical and separate, it helps in these situations:
ArkWarden communicates with the YubiKey using FIDO2 and WebAuthn. When you register a key, the YubiKey creates a public and private key pair internally and gives ArkWarden only the public key. The private key never leaves the YubiKey. At unlock time, ArkWarden sends the key a new random challenge, the key signs it, and ArkWarden verifies the signature. No reusable YubiKey secret is stored on the phone.
A YubiKey is a small physical security key made by Yubico. Yubico co-authored the FIDO2 and WebAuthn standards that hardware keys use. YubiKeys are used by governments, banks, and large technology companies to protect accounts where password theft is a serious risk.
ArkWarden chose YubiKey because it provides a physical second factor, keeps the private key on the hardware key, and works with iPhone over NFC. ArkWarden does not create its own hardware-key system. It uses FIDO2 and WebAuthn through the YubiKey's signing hardware.
Setup happens once over NFC. You confirm with your pattern, hold the key to the top of your iPhone, and ArkWarden registers it. The screenshots below show the actual screens.
In Settings, open two-factor authentication. ArkWarden lists three methods, one of which pairs with your pattern: Biometrics, PIN Code, and YubiKey. Choose YubiKey.
Before changing a security setting, ArkWarden asks you to draw your pattern. This makes sure the person adding a hardware key is the same person who already unlocks the vault.
On the Register YubiKey screen, tap Scan to Register. ArkWarden also recommends registering a second key as a backup during setup.
The system NFC sheet appears and asks you to scan your YubiKey. Hold the key against the top of your iPhone. ArkWarden communicates with the key, and once registration is complete the screen confirms the key is registered. This process does not need a network connection.
Choose YubiKey in two-factor authentication.
Draw your pattern to confirm it is you.
Register YubiKey 1. Tap Scan to Register.
The system NFC sheet: scan your YubiKey.
Communicating with the key over NFC.
Registered. The key is now a second factor.
You can register up to two YubiKeys per vault. Either key can unlock it. The second key is your backup if the first key is lost, left at home, or unavailable.
From the YubiKey management screen, you can add a second key and remove either key. By default, the keys are named YubiKey 1 and YubiKey 2. You can rename them to make them easier to tell apart, for example by naming the key you carry and the key you keep at home. Neither key is primary. Registering two just gives the vault a second key it will accept.
The practical advice is simple. Register two keys during setup and keep them in different places. This reduces the risk of losing access because one hardware key is lost.
Up to two keys. Add, remove, or rename. Either key unlocks your vault.
After a key is registered, unlocking the vault adds one NFC scan. Draw your pattern, hold the key to your iPhone, and the vault opens after the YubiKey check succeeds.
The order is always the same. You draw your pattern first, which derives the encryption key and decrypts the vault key. Then, because a second factor is enabled, ArkWarden asks for the YubiKey before showing the vault. You hold the key to the top of the phone, ArkWarden verifies the signature over NFC, and the vault opens. If you cancel, the vault stays closed.
After your pattern, scan the key.
Vault unlocked. Both checks passed.
Hardware keys are often used for signing in to websites, so it is important to be clear about what YubiKey does in ArkWarden. ArkWarden does not store login codes for other services, does not generate one-time passwords, and is not a replacement for an authenticator app.
The YubiKey in ArkWarden protects one thing: your vault. It is a second factor checked after your pattern, before your own files are shown. It does not change your accounts on other sites, and using it here does not register the key with anyone except ArkWarden. The same physical key still works independently with your other services.
There are two recovery paths, depending on how you set up YubiKey:
The recovery phrase is always the final recovery method, regardless of which second factor you use. It is generated on your device, written down by you, and never stored anywhere ArkWarden can access. A second registered key is easier for normal use because it lets you recover without using the recovery phrase.
Most vault apps stop at a passcode. ArkWarden lets you add a hardware key, the same kind banks and governments rely on, to protect the files that matter most. Set it up in a minute.
Back to two-factor authentication