Ten minutes now saves a bad afternoon later. Work through this in order.
1. Check you have two
If you bought one key, order the second now, before you set anything up.
A key cannot be copied. With only one, losing it drops you into account recovery, which is the weakest part of any sign-in system and the thing you bought the key to avoid. Everything below assumes two.
2. Set a PIN
Most accounts that matter will ask for a PIN as well as the key itself. Set it deliberately rather than letting a website prompt you mid-registration.
Choose something you will remember without writing it down near the key. One thing is worth knowing in advance: too many wrong attempts locks the key, and unlocking it means a reset that erases the credentials stored on it.
3. Decide which accounts get it
Do not start with the easiest account. Start with the one that would hurt most.
For most people that is the email account everything else resets through. Whoever controls your email controls your other accounts, so it is the first thing to protect, not the fifth.
Then work outward. Password manager. Banking and finance. Work accounts. Anything holding money or customer data.
4. Register both keys to each account, one account at a time
This is the step people get wrong, and getting it wrong is what makes the second key worthless.
For each account, register the first key and then register the second key before moving on. Registering the backup later, after you have lost the first, is exactly the situation the backup exists to prevent.
It takes an extra minute per account while you are already in the security settings. It takes considerably longer once something has gone wrong. Registering the backup properly covers the naming, the PIN question and how to check your coverage afterwards.
5. Save the recovery codes
Most services offer recovery codes when you enable a security key. Take them. Store them somewhere separate from both keys, in a password manager or on paper somewhere secure.
They are the third line, behind two keys. You will probably never use them. The time you do, you will be glad they exist.
6. Test the backup
Sign in once with the second key.
A backup you have never tested is a backup you are trusting on faith. Ten seconds now confirms it works and that you registered it to the account you thought you did.
7. Put the second key somewhere sensible
Not in the same bag as the first. Not in the same room, ideally.
A desk drawer at home, a safe at the office, or permanently in a desktop if you bought a Nano. The test is whether you could get to it on a day when the first key is gone.
That is it
The keys need no charging, no battery, no app and no maintenance. From here they simply work.