Buy two keys. If you take one thing from this store, take that.
The reasoning is short. A security key is deliberately impossible to copy. That property is the entire point, and it is also the reason a single key is dangerous. Lose it, break it, leave it in a hotel room, and the credential is gone with no way to reconstruct it. What you fall back on at that moment is account recovery, which is the weakest and most attacked part of any sign-in system.
A second key turns an emergency into an inconvenience.
Why account recovery is the wrong safety net
Think about what happens when your only key disappears.
On a personal account, you are into recovery codes if you saved them, or into an automated recovery flow if you did not. Those flows are designed to help people who genuinely cannot get in, which means they are also the path an attacker takes when they want in.
On a work account, you are into a call to the service desk. That call is the step attackers have targeted repeatedly against large organisations, because persuading a busy human is cheaper and more reliable than defeating cryptography. Every time your recovery process runs for a real reason, it also runs for a reason someone could fake.
You bought a phishing-resistant credential to close that door. Losing your only key opens it again.
Picking the pair
The two keys do different jobs, so they do not need to be the same model.
The first key travels. It goes on your keyring or in your bag, and it does the daily work. An NFC model suits this, because the travelling key is the one that ends up tapping against a phone. That is the 5C NFC for a modern laptop, or the 5 NFC if your machines are USB-A.
The second key stays put. It never leaves a building, so it does not need to be comfortable to carry. The 5C Nano is built for this. It sits nearly flush in a port and lives in a desktop or a docked machine you can always reach.
If you would rather the backup sat in a safe than in a computer, buy a second NFC model instead. A key in a drawer is easier to hand to a colleague during an emergency than a key wedged in someone's desktop.
Where the second key should live
Pick a location you can get to on a bad day, and be specific about it.
For an individual, a home desktop or a drawer at home works. For a business, the answer is usually a locked cabinet or a safe that more than one person can open, with a register of which key belongs to whom.
The failure to avoid is storing the backup somewhere that shares a fate with the first. Both keys in the same laptop bag is one bag away from having no keys. A backup in the office when the office is what you cannot get into is not a backup.
Register both at the same time
This is the part people skip, and it is the part that makes the second key worthless.
A backup key protects nothing until it has been registered to the accounts it is meant to protect. Registering it later, after you have lost the first one, is exactly the scenario the backup was supposed to prevent.
So do it in one sitting. For each account that matters, add both keys before you move on. It takes a few minutes per account and it is much easier while you are holding both keys and are already in the security settings.
Then test the backup at least once. Sign in with it. A key you have never used is a key you are trusting on faith.
How many for a business
Two per person is the floor, not a target.
Beyond that, hold a small pool of spares with whoever runs IT, so a lost key is a replacement handed over the same day rather than a procurement exercise. And register a dedicated pair to your break-glass accounts, stored separately from everything else, tested on a schedule.
If you want the arithmetic for a specific headcount and a specific set of privileged roles, that is something our team works through as part of a Conditional Access review.