iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Fernet can keep someone who obtains a copy of a credential file from reading or altering its contents—provided that person cannot also access the Fernet key. The key must be stored separately and protected; Fernet does not make credentials unconditionally safe, and it cannot protect plaintext after your application decrypts it.
What Fernet encryption does
Fernet is a Python library recipe for symmetric authenticated encryption. Symmetric means the same secret key is used to encrypt and decrypt data. Authenticated means a recipient with the key can detect attempts to alter a token. The pyca/cryptography documentation says, “Fernet guarantees that a message encrypted using it cannot be manipulated or read without the key.” Read the Fernet documentation.
A Fernet key is a URL-safe base64-encoded 32-byte value. Anyone who obtains it can decrypt tokens made with it and create valid tokens of their own. Fernet’s documented construction uses AES-CBC, PKCS7 padding, HMAC-SHA256, and randomly generated initialization vectors. Tokens also contain a timestamp, so encryption does not conceal all metadata: token age can be observable. The documentation describes the token format and construction.
Fernet is intended for data that fits in memory because the complete message must be available for decryption. That makes it a reasonable fit for small credential records, not a general solution for large files.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What disk encryption protects—and what it does not
If a file containing an API token or database password is copied, Fernet can prevent the thief from reading the credential when the Fernet key is not available to them. Authentication also makes undetected alteration of the token harder. Neither property helps if an attacker can access both the encrypted file and its key, control the application that reads the key, or capture the credential after decryption. Nor does encryption undo damage if a stolen credential is used to access the account or service it protects.
Encryption can be applied at different layers. OWASP describes application, database, filesystem, and hardware-level data-at-rest encryption; the appropriate layer depends on the threat model. Filesystem or hardware encryption can help if a device is physically lost or stolen, but hardware-level encryption does not protect a server from a remote attacker who compromises it while running. These protections complement rather than replace sound application key management. OWASP’s Cryptographic Storage Cheat Sheet discusses these layers and their limits.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Where to keep the Fernet key
Key custody is the central design decision. Do not save the Fernet key beside the encrypted file, hard-code it in the application, or commit it to a source-code repository. A key bundled in source code or a build artifact may be exposed along with the ciphertext. OWASP recommends separating keys from the data they encrypt and using operating-system, framework, or cloud secure storage mechanisms where available. It also cautions that a fully compromised application may expose keys the application itself can access. See OWASP’s Key Management Cheat Sheet.
Free tools Windows power users keep installed
One-click scans. No signup required.
Python’s keyring library provides an interface to system keyring services and describes its use for safe password storage. Whether a particular backend is suitable depends on the operating system, deployment mode, and threat model; there is no single configuration established as right for every application. Consult the keyring documentation.
Rank #3
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
If a password must be used to derive the Fernet key, use a key derivation function rather than treating the password as the key. The cryptography project currently recommends Argon2id for this purpose. Its example uses a salt that must remain available to derive the same key again; the salt is not a secret key and does not replace the password. See the project’s password-derived key guidance.
Choose protection for the kind of secret you have
“Credential” can mean a service secret the application must recover, or a user password it only needs to verify. Those require different handling. The options below address different threats and are not interchangeable:
Rank #4
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
| Approach | Useful for | Key limitation |
|---|---|---|
| Application-level Fernet | Encrypting selected fields in a file or database when the application needs to recover the original secret. | Requires separate, carefully managed key storage; best suited to small messages. |
| Operating-system keyring or secure store | Keeping a key or retrievable secret under a system-managed storage service. | Suitability depends on the platform, deployment, and backend. |
| Filesystem or full-disk encryption | Reducing exposure if a device is physically lost or stolen. | Does not by itself prevent a remote attacker from accessing a compromised running system. |
| Password hashing | Storing a user password when the application only needs to check whether a supplied password is correct. | One-way: it cannot return the original password for use with another service. |
OWASP recommends password-storage algorithms such as Argon2id, bcrypt, or PBKDF2 for passwords that only need verification, rather than reversible encryption. Fernet is more appropriate for a service credential that the application must later retrieve and send. See OWASP’s Password Storage Cheat Sheet.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rotate Fernet keys without losing access
Fernet’s MultiFernet supports migration between keys. It encrypts new tokens with the first key in its list and tries keys in sequence when decrypting. Its rotate() method re-encrypts tokens under the primary key. The Fernet documentation explains MultiFernet and rotation.
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
- Introduce the new key as the primary key while retaining old keys that are still needed to decrypt existing tokens.
- Re-encrypt existing tokens with the new primary key, using
MultiFernet.rotate()or an equivalent migration that preserves access to the original data. - Verify that required credentials remain readable with the new key configuration.
- Retire old keys only after no required tokens depend on them. Losing every key that can decrypt a token makes its credential unrecoverable.
Plan recovery as well as rotation: keep access to required keys protected and separate from the encrypted data, rather than making an exposed copy beside the tokens.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

