Librem Key

Librem Key

Keep your secret encryption keys in your pocket and out of the hands of hackers.

A USB security token to make encryption, key management, and tamper detection convenient and secure. The Librem Key is proudly made in the USA

Portable Protection

The Librem Key is designed with portability in mind. It’s the same size as your average thumb drive and has a durable, full-size USB plug and a sealed case. Add it to your key ring or just put it in your pocket or purse and know your keys are always with you. Librem Key
  • Up to 4096-bit RSA Keys
  • Up to 512-bit ECC Keys
  • Average > 20 Years of Storage Time
  • Life Expectancy > 100,000 PIN Entries

You Hold the Keys

Using encryption across multiple devices just got easier.

  • Tamper-resistant OpenPGP smart card
  • Store up to 4096-bit RSA keys and up to 512-bit ECC keys
  • Securely generate keys on any device
  • Encryption and decryption happens on the key itself!

The Key to Convenient Security

Typing in your passphrase each time you boot can be a hassle. Let’s fix that. Librem Key With a Librem Key linked to your encrypted drive, you can boot your system, insert your key, and enter your PIN when prompted. You can always fall back to your passphrase if your Librem Key isn’t at hand.
Just remove your Librem Key and your desktop will lock automatically, protecting your system from snooping while you are gone.

Tamper Detection

  • Detect BIOS or kernel tampering
  • Key LED blinks green – all systems are go
  • Key LED blinks red – detected tampering

Password Settings

  • Manager: 16 entries
  • Storage: 3x HOTP (RFC 4226)
  • Storage: 15 x TOTP (RFC 6238)

Hardware Specifications

Key Slots

Three key slots supporting RSA 2048-4096 bit and ECC 256-512 bit

Supported Elliptic Curves

NIST P-256, P-384, P-521 (secp256r1/prime256v1, secp384r1/ prime384v1, secp521r1/prime521v1), brainpoolP256r1, brainpoolP384r1, brainpoolP512r1


CSP, OpenPGP, S/MIME, X.509, PKCS#11

Password Storage

3x HOTP (RFC 4226), 15 x TOTP (RFC 6238)

Password Manager

16 Entries

Random Number Generator

40 kbit/s true random number generator
Tamper-resistant smart card

Life Expectancy

> 100,000 PIN entries

Storage Time

> 20 years


USB 2.0, Type A









6 g

Safety Compliance