OpenSSH 8.2 added the ecdsa-sk and ed25519-sk key types. The -sk suffix identifies security-key-backed credentials. A key generated with a supported FIDO authenticator uses the hardware device during signing, and the release notes describe user presence—typically a physical touch—as the default authorization behavior.
ssh-keygen -t ed25519-sk
# or, depending on authenticator support:
ssh-keygen -t ecdsa-sk
The operational value is different from simply encrypting a private-key file with a passphrase. A copied local key file is not enough to authenticate if the signing operation still depends on the physical authenticator. That can reduce the value of workstation file theft, but it does not eliminate endpoint compromise, session theft, malicious forwarding, weak server authorization, or account-recovery risks.
Resident keys
FIDO2-capable tokens can support resident credentials. OpenSSH 8.2 documented resident-key generation and retrieval so a credential can be made portable without carrying the usual key-handle file between machines. That convenience changes the threat model: if more of the credential state can be recovered from the token, loss of the token matters more. Protect authenticators with an appropriate PIN/user-verification policy and maintain a deliberate recovery process.
User presence should be a policy decision
OpenSSH supports options that relax the default touch requirement for some security-key credentials. Do not disable user presence merely because automation becomes easier. If a workload needs non-interactive credentials, design that identity separately and constrain it with service-account scope, network boundaries, command restrictions, short lifetimes, or workload identity mechanisms rather than weakening a human administrator credential by default.