Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
Video

Adding the AmbiSecure card as a FIDO security key in Google 2-Step Verification

Pair the AmbiSecure card with a Google account. Walkthrough of 2-step verification → security key registration on a desktop browser.

DURATION · 1:21 RESOLUTION · 1920x1080 FIDO setup · Consumer
Adding the AmbiSecure card as a FIDO security key in Google 2-Step Verification

Hosted on YouTube. Open in YouTube →

Registering the card on a Google account (desktop)

On a desktop browser the AmbiSecure card registers over USB as a FIDO2 / U2F security key on your Google Account. The whole flow lives inside Google's 2-Step Verification settings.

  1. Sign in at your Google Account and open Security.
  2. Under How you sign in to Google, open 2-Step Verification (enable it first if it is off).
  3. Choose Add security key (listed under passkeys and security keys) and select USB / external security key.
  4. Insert the AmbiSecure card into a USB reader when prompted and touch it to confirm presence.
  5. Name the key so you can recognise it later, then save.

Before you start

Google will not offer the security-key option until the account is already using 2-Step Verification, so the order of operations matters:

  • Turn on 2-Step Verification first. Google requires an existing second factor — usually a phone number or the Google prompt — before it will let you enrol a key.
  • Keep that first factor enrolled. Google blocks removing your last remaining second factor, and you will want a fallback while you are still testing the card.
  • Use a USB smart-card reader for the desktop flow. The card presents as a FIDO2 / U2F authenticator over the reader; NFC is the phone flow, covered in the mobile walkthrough.
  • Any current desktop browser works — Chrome, Edge, Firefox, and Safari on macOS all speak WebAuthn. Chrome tends to give the clearest prompts for external keys.

What is specific to Google accounts

Google folds passkeys and hardware security keys into a single list in the account UI, which is the most common source of confusion here. The AmbiSecure card enrols as a device-bound security key — the private key is generated inside the card's secure element and never leaves it. That is a different object from a synced passkey stored in a Google account or password manager, even though both appear under the same heading.

Two Google-specific behaviours worth knowing before you roll this out:

  • Advanced Protection Program. If the account enrols in Google APP, Google requires two registered security keys, not one. Two AmbiSecure cards satisfy this — register the second before enrolling, since APP enrolment checks at sign-up time.
  • Workspace policy. Google Workspace administrators can require security keys for an organisational unit from the admin console. The card's AAGUID is what identifies the authenticator model in Workspace reporting and in any allow-list policy, so record it during your pilot — the AAGUID lookup tool resolves it.

If the registration does not complete

  • “Couldn't verify it's you” almost always means the card left the field before the ceremony finished. Leave it seated in the reader until the browser confirms.
  • Google only offers “use your phone” — choose Try another way and pick the USB security-key option explicitly; Google preferentially suggests phone-as-passkey.
  • The reader is not detected — confirm the card enumerates at the OS level before blaming the browser. Our ATR parser is a quick way to confirm the reader sees the card at all.

Need a pilot, datasheet, or technical conversation?

Tell us the form factor, target deployment, and certification needs. Our engineering team will follow up directly.

Talk to engineering

Frequently asked questions

Do I need 2-Step Verification enabled before adding the AmbiSecure card to Google?

Yes. Google only exposes the security-key option on accounts that already have 2-Step Verification switched on, so enrol a phone or Google prompt as your first second factor, then add the card.

Is the AmbiSecure card a passkey or a security key on a Google account?

It enrols as a device-bound security key. The private key is generated inside the card's secure element and cannot be exported or synced, which is what distinguishes it from a passkey synced through a Google account or password manager.

How many security keys does Google's Advanced Protection Program require?

Two. Advanced Protection checks for two registered keys at enrolment, so register a second AmbiSecure card before enrolling the account in the programme.

Can the same AmbiSecure card protect Google and other accounts at once?

Yes. The card stores multiple resident credentials, so one card can be registered to a Google account, a Facebook account, and other FIDO2 relying parties simultaneously.

What happens if I lose an AmbiSecure card registered to my Google account?

Sign in with another enrolled second factor or a saved backup code, then remove the lost key from the 2-Step Verification settings. This is why Google will not let you delete your last remaining second factor, and why a second registered key is worth having before you need it.