Skip to content

YubiKey vs Feitian FIDO Keys

hardware-purchase · enterprise-subscription

·

hardware-purchase

YubiKey wins · 217 (10 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    YubiKeynone0/10

    Direct probes confirm no llms.txt or agent-oriented docs exist on any Yubico domain (404s across docs.yubico.com, developers.yubico.com, www.yubico.com), and no MCP endpoint resolves; documentation is human-oriented HTML only.

    • [probe] PROBE llms.txt: HTTP 404 at https://docs.yubico.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://docs.yubico.com/.md
    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
    Feitian FIDO Keysnone0/10

    Feitian is a hardware FIDO key vendor with no evidence of an llms.txt or agent-oriented documentation; probes explicitly show 404s for llms.txt, markdown docs, and OpenAPI endpoints.

    • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
    • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to YubiKey
    YubiKeypartialprobed4/10

    Yubico ships scriptable tooling (ykman CLI, python-fido2 SDK) that can configure/query keys programmatically in scripts or CI pipelines, and a fleet REST API for enterprise management — but the core authentication function inherently requires physical touch/user presence, which cannot be automated headlessly. Missing for 10: any documented way to perform actual FIDO2/PIV/OATH authentication or signing operations without a human touch event, explicit CI/automation guidance, and evidence of true headless operation for the security-critical path (only configuration/management is scriptable).

    • [claimed-docs] Configure your YubiKey via the command line.
    • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
    Feitian FIDO Keysnone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

    • ai-native userUse an official CLI

      weight 2 · round to YubiKey
      YubiKeypartialprobed6/10

      YubiKey ships an official CLI (ykman/yubikey-manager) for device configuration, verified installable via pip/uvx and Homebrew with scriptable device management, but this is a hardware-configuration tool, not an AI-agentic CLI designed for LLM/agent workflows — there's no evidence of AI-native features like structured output for agents, agent-oriented docs, or MCP integration. missing for 10: evidence of AI-agent-oriented usage patterns, structured/machine-readable output tailored for agentic consumption, and any llms.txt/MCP support (explicitly absent per probes).

      • [claimed-docs] Configure your YubiKey via the command line.
      • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
      • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
      Feitian FIDO Keysnone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      • ai-native userDrive the product through a documented public API

        weight 3 · round to YubiKey
        YubiKeypartialprobed5/10

        YubiKey exposes genuine programmatic interfaces — the ykman CLI, python-fido2 SDK, PKCS#11/PIV/OpenPGP libraries, and platform SDKs (Android/iOS/.NET) — that let a developer or automated agent drive the device (yubikey-docs-4, yubikey-probe-rt-1, yubikey-probe-rt-3, yubikey-docs-8, yubikey-docs-19). There is also a separate REST API for YubiEnterprise fleet management (yubikey-probe-rt-2). However, there is no unified public REST/OpenAPI spec for the core device (probe-3 confirms 404s), and no AI-agent-oriented discovery layer like llms.txt or MCP (yubikey-probe-1, yubikey-probe-rt-4). Missing for 10: a documented OpenAPI/REST spec for core device operations, and any llms.txt/MCP support for AI-agent consumption.

        • [claimed-docs] Configure your YubiKey via the command line.
        • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
        • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
        • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
        • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
        • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
        • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
        • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
        Feitian FIDO Keysnone0/10

        Feitian FIDO Keys are hardware authentication devices with no documented public API for programmatic/agentic control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404, and no evidence describes any API surface for AI agents to drive.

        • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
        • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
        • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…
      • ai-native userBuild against official SDKs

        weight 2 · round to YubiKey
        YubiKeyfullprobed8/10

        Yubico publishes and maintains a broad set of official SDKs (python-fido2, java-webauthn-server, .NET SDK, YubiKit Android/iOS, ykman CLI) with dedicated docs, and runtime probes confirm these packages are live and installable from public registries (PyPI, Homebrew) rather than just claimed in docs. This gives developers, including AI-native builders, real programmatic building blocks for passkeys/FIDO2/PIV integration. Missing for 10: no AI-agent-specific SDK examples or agent-oriented tooling, and no independent (non-Yubico) hands-on validation of SDK developer experience.

        • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
        • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
        • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
        • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
        • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
        • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
        • [claimed-docs] Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…
        Feitian FIDO Keysnone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Api quality

        1. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

          weight 2 · round drawn
          YubiKeynone0/10

          Explicit probes for OpenAPI/Swagger specs at docs.yubico.com and developers.yubico.com all returned 404s, and no llms.txt or machine-readable API spec was found anywhere in Yubico's domains. While a YubiEnterprise REST API console exists, there is no evidence it is exposed as a downloadable OpenAPI/machine-readable spec.

          • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
          • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
          • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
          Feitian FIDO Keysnone0/10

          Feitian's FIDO key documentation covers WebAuthn/FIDO2 standards and setup guides but no OpenAPI/Swagger spec is published; explicit probes for llms.txt, docs-md, and openapi.json all returned 404.

          • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
          • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
          • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

        Automation depth — how much of the product can run unattendedAutomation depth

        How much of the product can run unattended

        1. ai-native userPerform bulk operations across many items at once

          weight 2 · round to YubiKey
          YubiKeypartialprobed4/10

          Yubico exposes a scriptable CLI (ykman) and a YubiEnterprise fleet-management REST API that could be used to configure or manage many keys programmatically, hinting at bulk-capable automation, but no docs explicitly describe a bulk/batch operation (e.g., configuring N keys or revoking many credentials in one call). Missing for 10: explicit bulk-operation API/CLI documentation, batch examples, and independent confirmation that many items can be processed in one automated action.

          • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
          • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
          • [claimed-docs] Configure your YubiKey via the command line.
          Feitian FIDO Keysnone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido

          What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

          Openpgp

          1. developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email

            weight 2 · round to YubiKey
            YubiKeyfullcommunity7/10

            Yubico's own docs describe OpenPGP support with RSA/ECC sign/encrypt operations using a private key stored on the YubiKey smartcard (yubikey-docs-9, yubikey-docs-26), and independent community testimony confirms real-world use of YubiKey's GPG smartcard functionality (contrasted with competitors lacking it) (yubikey-comm-14, yubikey-comm-15). This covers the underlying capability for git commit signing (via GPG) and encrypted email (via OpenPGP), though neither specific workflow (git config, email client integration) is explicitly documented in the pack. Missing for 10: explicit git commit-signing walkthrough/documentation, explicit encrypted-email (e.g., Enigmail/Thunderbird) setup guide, and more first-party depth beyond the general OpenPGP overview.

            • [claimed-docs] OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…
            • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as YubiKeys), through common interfaces like P…
            • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
            • [community] Unfortunately SoloKey doesn't work as an OpenPGP smart card, which means it's not a real substitute for a Yubikey.
            Feitian FIDO Keysnone0/10

            Evidence covers FIDO/U2F, PIV, OTP, and OpenSSH use cases, but there is no mention of OpenPGP key storage, git commit signing, or encrypted email support anywhere in the pack.

            Otp

            1. power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

              weight 2 · round to YubiKey
              YubiKeyfullcommunity8/10

              YubiKey natively supports OATH TOTP/HOTP slots (with secrets stored in the secure element) and Yubico OTP/challenge-response via the OTP application, documented and manageable via ykman/Yubico Authenticator, covering legacy services without WebAuthn. Community evidence corroborates real-world use of these legacy modes alongside FIDO2. Missing for 10: independent hands-on walkthrough of setting up HOTP/TOTP slots or challenge-response specifically, and more detail on slot capacity/limits.

              • [claimed-docs] the shared secrets are stored and processed in the YubiKey's secure element
              • [claimed-docs] No client software needed. The OTP is just a string. If you can send a password, you can send an OTP.
              • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
              • [claimed-docs] Configure your YubiKey via the command line.
              • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
              Feitian FIDO Keyspartialclaimed6/10

              Feitian documents HOTP functionality that emulates HID keyboard to auto-type OTP values, plus an OTP Tool to switch protocols and an SK Manager to manage OTP/PIV/FIDO functions, confirming legacy OTP slot support beyond WebAuthn. However, there's no detail on TOTP support, challenge-response mode, or number of OTP slots available. Missing for 10: TOTP-specific documentation, challenge-response mode details, slot capacity/configuration specifics, and independent hands-on verification.

              • [claimed-docs] The HOTP function of FEITIAN FIDO Security Key emulates HID Keyboard protocol to enable automatically type the value in.
              • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.
              • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.

            Piv

            1. it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

              weight 2 · round to YubiKey
              YubiKeyfullcommunity7/10

              Docs confirm PIV smart-card functionality (PKCS#11 sign/encrypt with on-device RSA/ECC keys, non-exportable, with attestation to prove device-generated keys), and community independently corroborates real-world PIV smart-card use (yubikey-comm-16, yubikey-comm-14). This covers certificate-based login and code-signing capability, though the workstation-login and VPN integration flows themselves aren't explicitly documented in this pack. Missing for 10: explicit docs/screenshots of Windows/macOS smart-card workstation sign-in setup, VPN client PIV integration guides, and a dedicated code-signing walkthrough.

              • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
              • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
              • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
              • [community] Also, yubikey works as a PIV smartcard.
              • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
              Feitian FIDO Keyspartialclaimed6/10

              Feitian documents PIV smart card functionality via the SK Manager tool, including macOS PIV smart card logon configuration and general PIV/FIDO/OTP management, supporting workstation sign-in use cases. However, evidence does not explicitly confirm VPN certificate-based authentication or code signing use cases with PIV, nor detail Windows/Active Directory PIV smart card logon specifically. Missing for 10: explicit VPN certificate-auth documentation, code-signing workflow evidence, Windows PIV smart card logon docs, and independent/third-party validation of PIV compliance.

              • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
              • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.

            Ssh

            1. developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

              weight 2 · round to YubiKey
              YubiKeyfullcommunity9/10

              Yubico documents all three hardware-backed SSH paths: FIDO2 sk-ssh keys generated on-device with OpenSSH (private key never leaves hardware, touch required per operation), PIV smartcard usage via PKCS#11 for sign/encrypt with SSH, and OpenPGP smartcard keys for SSH auth. Community corroboration confirms FIDO2/PIV/OpenPGP smartcard functionality and touch-to-sign is genuinely enforced (not remotely bypassable). Missing for 10: no independent hands-on benchmark of ed25519 sk-ssh key generation end-to-end, and some community friction noted around PIN/touch UX onboarding.

              • [claimed-docs] FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.
              • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
              • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
              • [claimed-docs] OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…
              • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
              • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
              • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
              • [community] Also, yubikey works as a PIV smartcard.
              • [community] The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.
              Feitian FIDO Keyspartialclaimed6/10

              Feitian docs explicitly cover FIDO2 sk-ssh usage for OpenSSH/GitHub/Linux server login (feitian-docs-6) and PIV smart-card functionality including macOS PIV logon via SK Manager (feitian-docs-9, feitian-docs-10), supporting hardware-backed SSH auth with physical touch. However, no OpenPGP-based SSH key support is documented anywhere in the pack. Missing for 10: explicit OpenPGP applet/SSH support, independent/hands-on verification of sk-ssh workflow, and unified documentation tying all three methods together.

              • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
              • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
              • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.

            Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling

            Building with and managing the key — CLIs, SDKs, attestation

            Agent audit

            1. ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

              weight 2 · round to YubiKey
              YubiKeyfullprobed8/10

              Yubico's official ykman CLI (and underlying python-fido2/yubikey-manager libraries) exposes exactly this data programmatically: serial number, firmware version, enabled applications, PIN/PIV/OATH/OTP slot state, all scriptable without a client GUI — confirmed both in docs (docs-4, docs-15/25) and a keyless runtime probe showing full scriptable device management (probe-rt-1) plus SDK availability on PyPI (probe-rt-3). An agent can shell out to ykman on each key to build a fleet audit, though Yubico provides no built-in cross-fleet aggregation/reporting endpoint (the YubiEnterprise API in probe-rt-2 covers shipping/inventory, not live security-posture state). Missing for 10: a native fleet-wide audit/reporting API or dashboard aggregating multiple keys' state, and independent hands-on confirmation of scripting this across many devices at scale.

              • [claimed-docs] Configure your YubiKey via the command line.
              • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
              • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
              • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
              • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
              • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
              • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
              Feitian FIDO Keysnone0/10

              There is a SK Manager GUI tool for managing FIDO/PIV/OTP functions, but no evidence of any programmatic API, CLI output, or SDK exposing serial, firmware version, enabled applications, or credential state for automated fleet auditing by an agent; probes for API/docs endpoints all returned 404.

              • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
              • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
              • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
              • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

            Attestation

            1. security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled

              weight 2 · round to YubiKey
              YubiKeyfullprobed8/10

              YubiKey documents PIV attestation explicitly: certificates prove a key was generated on-device (not imported), and python-fido2 provides library support for 'verifying attestation and assertion signatures,' enabling backend registration flows to reject non-genuine or imported keys. This directly supports enforcing genuine device enrollment at registration time. Missing for 10: no independent/hands-on validation of attestation-based enrollment enforcement in production, and no explicit vendor-model allowlisting guide beyond the raw attestation cert mechanism.

              • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
              • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
              • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
              • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
              Feitian FIDO Keysnone0/10

              No evidence in the pack discusses FIDO attestation, AAGUID verification, metadata service (MDS) support, or any mechanism for security engineers to validate genuine Feitian key models at registration; the docs cover general FIDO compatibility, interfaces, and setup guides only.

              Cli

              1. developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

                weight 3 · round to YubiKey
                YubiKeyfullprobed9/10

                ykman is Yubico's official CLI for configuring YubiKeys — enabling/disabling applications, setting PINs, managing PIV/OATH/OTP slots, and reading device/firmware state — and is documented and verified installable/scriptable via pip/Homebrew/uvx in runtime probes. Independent community mentions corroborate real-world use of ykman-adjacent workflows (e.g., PIN enrollment via CLI/GUI tools). Missing for 10: no independent hands-on developer review specifically praising ykman's scripting ergonomics beyond install verification.

                • [claimed-docs] Configure your YubiKey via the command line.
                • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
                • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
                Feitian FIDO Keyspartialclaimed4/10

                Feitian offers GUI tools (SK Manager, iePassManager, OTP Tool) for managing FIDO/PIV/OTP functions, PINs, and slots, but these are graphical utilities, not documented as scriptable CLIs. No evidence of a command-line interface, scripting API, or automation-friendly tooling for enabling apps, setting PINs, or reading device state. missing for 10: dedicated CLI tool, scripting/automation documentation, examples of headless/scriptable configuration workflows.

                • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.

              Sdks

              1. developerOfficial SDKs let me integrate the key into my own desktop and mobile apps

                weight 2 · round to YubiKey
                YubiKeyfullprobed8/10

                Yubico provides official desktop SDK (.NET SDK, yubikey-manager), Android (YubiKit) and iOS (yubikit-ios) mobile SDKs, plus python-fido2 and java-webauthn-server libraries, all documented and confirmed live on package registries. missing for 10: independent third-party developer testimonials on ease of SDK integration, and no official cross-platform (e.g. Flutter/React Native) SDK is mentioned.

                • [claimed-docs] Yubico has developed a range of mobile SDKs, such as for iOS and Android, and also desktop SDKs to enable developers to rapidly integrate ha…
                • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
                • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
                • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
                • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
                • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
                Feitian FIDO Keysnone0/10

                Evidence covers WebAuthn/FIDO2 standard support, OS integrations (Windows Hello, Azure AD, OpenSSH), and firmware provisioning via Google's OpenSK repo, but nothing indicates Feitian ships its own official SDK for developers to embed key support into custom desktop/mobile apps. Probe results also confirm no API/docs discoverability artifacts. This is an applicable axis for a hardware key vendor (SDKs are common in this space) but no evidence of one existing.

                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

              Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat

              Where the key works — platforms, browsers, service compatibility catalogs

              Agent approval

              1. ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

                weight 1 · round to Feitian FIDO Keys
                YubiKeypartialprobed4/10

                YubiKey's FIDO2/WebAuthn and SSH implementations require a physical touch for every cryptographic operation, and SDKs like python-fido2, PKCS#11, and yubikey-manager expose this as a programmable building block that could be wired into an agent approval flow, but there is no evidence of any actual AI-agent or automation-approval integration built on this. missing for 10: any documented agent-framework integration, a sample workflow gating an AI or agent action behind YubiKey touch, or a third-party report of this pattern in use.

                • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
                • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
                • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
                • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
                • [community] The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.
                Feitian FIDO Keyspartialclaimed5/10

                Feitian keys are standard FIDO2/WebAuthn/U2F hardware tokens that inherently require a physical touch to complete authentication (feitian-docs-1, feitian-docs-4, feitian-docs-18), which is the underlying mechanism that could be wired into an agent's approval flow via WebAuthn. However, there is no evidence of any AI-agent-specific integration, SDK, or documented workflow showing the key used as a human-approval gate for agent-initiated actions. Missing for 10: explicit AI-agent/automation integration examples, documentation of using the key as an approval gate in agentic pipelines, and any third-party corroboration of this use case.

                • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.
                • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…

              Compatibility

              1. power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services

                weight 2 · round drawn

                Docs show broad standards-based compatibility (FIDO2/WebAuthn, PIV, OpenPGP, OTP, SSH) and SDKs for iOS, Android, .NET, and desktop, implying cross-OS/browser support, and community posts confirm real-world use across GPG/PIV/SSH/WebAuthn workflows. However, there is no evidence of a published, browsable compatibility catalog listing specific supported services/websites or a browser support matrix as the story requests. Missing for 10: an explicit 'works with' directory of supported services/sites, and a documented OS/browser compatibility matrix beyond protocol-level claims.

                • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                • [claimed-docs] this guide will provide all the necessary technical knowledge required to adopt passkeys into your application
                • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
                • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
                • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
                • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
                • [community] Also, yubikey works as a PIV smartcard.
                Feitian FIDO Keyspartialclaimed5/10

                Feitian documents cross-platform compatibility (Windows, macOS, Linux, Android/iOS) and integration guides for specific platforms (Windows Hello, Azure AD, GitHub/OpenSSH, Google Advanced Protection, PIV/macOS), and multi-interface support (USB/NFC/BLE) which implies broad OS/browser reach. However there is no published, centralized compatibility catalog or matrix listing supported browsers/services, and no independent verification of claims. Missing for 10: a formal published compatibility catalog/matrix of supported services and browsers, independent/hands-on verification of cross-platform claims.

                • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).
                • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                • [claimed-docs] MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.
                • [claimed-docs] Recognized as a HID device, no driver is needed for MultiPass FIDO® Security Key to work on Microsoft Windows, macOS and Linux via USB.
                • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.

              Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery

              Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

              Recovery

              1. security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

                weight 3 · round to Feitian FIDO Keys
                YubiKeynone0/10

                The evidence pack contains no vendor documentation describing a lockout-recovery strategy (e.g., backup key enrollment guidance, what's recoverable vs. not). Community threads instead highlight the opposite experience — users must manually track and re-register every account per lost key with no central mechanism (yubikey-comm-7), and lost/compromised keys require full manual replacement across all enrolled services (yubikey-comm-2, yubikey-comm-6) — indicating this is an unaddressed gap rather than a documented workflow.

                • [community] I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …
                • [community] I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…
                • [community] They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…
                Feitian FIDO Keyspartialclaimed5/10

                FAQ entries state that a lost key can be worked around by logging in with a backup security key or another method, then disabling the lost key and provisioning a new one, which is a real but minimal statement of a lockout-recovery strategy (feitian-docs-14, feitian-docs-24). However, there is no dedicated recovery guide explaining what is and isn't recoverable (e.g., per-relying-party re-registration necessity, loss of resident/discoverable credentials, biometric enrollment data) beyond this brief FAQ mention. Missing for 10: a structured recovery/lockout doc, explicit treatment of what is NOT recoverable (credentials tied to lost key), and guidance on enrolling multiple backup keys per service rather than just a generic FAQ answer.

                • [claimed-docs] The dedicated users can still logon to the account by using back-up security key or other method.
                • [claimed-docs] The dedicated users can still logon to the account by using back-up security key or other method. Then user can disable the lost security ke…

              Setup

              1. power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

                weight 2 · round to Feitian FIDO Keys

                Yubico ships an official 'Yubico Authenticator' app described as an 'intuitive and easy-to-use GUI interface' and provides technical guides for SSH/PGP/PIV/FIDO setup, but these are protocol-specific developer docs, not an end-to-end enrollment wizard for registering a key with personal accounts. A hands-on community report (yubikey-comm-13) describes exactly the opposite of guided onboarding: a new user enrolled keys without setting a PIN because the right guidance wasn't surfaced, then had to unenroll everywhere, set a PIN, and re-enroll — a concrete documented setup failure for a power user. Missing for 10: a dedicated first-run setup app/wizard walking users through registering with common accounts (Google, GitHub, etc.), and independent corroboration that such guidance works smoothly in practice.

                • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
                • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
                • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
                Feitian FIDO Keyspartialclaimed7/10

                Feitian provides first-party guided documentation for pairing keys (BLE setup guide), registering with specific platforms (Windows, Azure AD, Microsoft, GitHub/Linux via OpenSSH), and a dedicated SK Manager desktop app for configuring FIDO/PIV/OTP functions, which together resemble a guided enrollment flow for a power user. However, missing for 10: independent/hands-on user reports confirming the setup experience is clear in practice, and no single unified 'wizard' walkthrough spanning consumer-account registration (e.g., Google/Microsoft account UI) rather than platform/OS-level docs.

                • [claimed-docs] Learn how to pair your FEITIAN Bluetooth FIDO2 security key to your device.
                • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your personal Windows.
                • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.

              Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness

              What runs on the device — open-source firmware, update policy, vulnerability response

              Source

              1. security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

                weight 2 · round to Feitian FIDO Keys
                YubiKeynone0/10

                Yubico documentation and community evidence describe YubiKey firmware as closed and non-upgradable ('proprietary smartcard', 'not being able to flash firmware is a feature'), with no mention of open-sourcing or third-party firmware audits anywhere in the evidence pack; no vendor claim or independent report of open/audited firmware exists to evaluate.

                • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
                • [community] Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…
                • [community] Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…
                • [community] A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…
                Feitian FIDO Keyspartialclaimed5/10

                Feitian offers a specific OpenSK hardware variant where users can build firmware from Google's open-source OpenSK repo and flash it themselves, directly addressing the transparency concern for that model. However, the flagship BioPass and MultiPass FIDO keys firmware is not documented as open source or independently audited, and no third-party security audit reports are cited anywhere in the pack. missing for 10: independent firmware audit reports for mainstream product lines, confirmation that BioPass and MultiPass firmware not just the niche OpenSK SKU is open or audited, and hands-on verification that shipped OpenSK devices match the public source

                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…

              Updates

              1. security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

                weight 2 · round to YubiKey

                Docs show only a firmware-version lookup tool (ykman/Authenticator) with no official advisory page, CVE list, or affected-model lookup in the evidence pack, and community reports confirm YubiKey firmware is not field-upgradable — vulnerability response instead relies on ad-hoc device replacement (comm-3, comm-5, comm-8) which posters describe as inconsistent and manual (comm-2, comm-4, comm-6), directly undercutting any 'clear fix pipeline' claim. missing for 10: published security-advisory index, affected-model/serial lookup tool, documented recall/replacement SLA, and any firmware-update delivery mechanism.

                • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
                • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
                • [community] Previously when their Yubikey 4's were found to be susceptible to the ROCA vulnerability, they issued replacements for any customers who had…
                • [community] Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…
                • [community] I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…
                • [community] Don't have high hopes for this but I just requested a replacement device through their support system as the offered mitigations are not som…
                • [community] They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…
                Feitian FIDO Keysnone0/10

                No evidence of security advisories, CVE tracking, affected-model lookup tools, or a documented firmware update delivery mechanism; only general product/setup docs and an OpenSK build guide are present, none of which address vulnerability response or patch distribution.

                Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management

                Keys at organization scale — bulk provisioning, delivery services, IdP policies

                Agent provisioning

                1. ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

                  weight 2 · round to YubiKey
                  YubiKeypartialprobed5/10

                  Yubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and publicly live (console.yubico.com/apidocs/), providing a programmatic surface for fleet delivery, inventory, and shipment management that an agent could call instead of a human-only console. However, the evidence pack gives no detail on specific endpoints for ordering, assignment, or pre-registration workflows, no sample agent integration, and no independent confirmation of end-to-end automation success. Missing for 10: detailed API endpoint documentation for order/assign/pre-register flows, evidence of actual agent-driven automation, and independent corroboration of the API's completeness.

                  • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                  Feitian FIDO Keysnone0/10

                  No evidence of any enterprise API for provisioning, ordering, or assignment of keys — all documentation is consumer/end-user setup guides, and probes for API/docs endpoints returned 404s.

                  • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                  • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                  • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                Delivery

                1. it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

                  weight 2 · round to YubiKey
                  YubiKeypartialprobed6/10

                  Yubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and live at console.yubico.com/apidocs/, described as the programmatic surface for fleet delivery, inventory, and shipment management — directly matching the API/console-driven distribution story. However, this rests on a single probe citation with no deeper documentation of the shipping workflow itself, no case studies, and no independent corroboration that enterprises use it this way in practice. Missing for 10: detailed docs on shipment/delivery mechanics, customer/independent confirmation of the service in use, and console UI evidence beyond the API doc existing.

                  • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                  Feitian FIDO Keysnone0/10

                  No evidence of any API, console, or enterprise fulfillment/logistics/shipping-management capability; probes confirm no API/docs exist for this. Evidence covers only device features (FIDO2, biometrics, NFC/BLE/USB) and setup guides, nothing about distributed shipping orchestration.

                  • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                  • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                  • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                Idp

                1. it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

                  weight 2 · round to Feitian FIDO Keys
                  YubiKeynone0/10

                  The evidence pack covers YubiKey's general FIDO2/WebAuthn/passkey protocol support and a fleet-management API (YubiEnterprise) for shipment/inventory, but contains no mention of specific IdP integrations (Okta, Entra ID, Google Workspace) or of admin-configurable policies enforcing hardware-key-only authentication. Since IdP integration and policy enforcement are a fair and expected axis for an enterprise MFA hardware vendor, absence of evidence means 'none' rather than 'na'. Missing for 10: documented Okta/Entra ID/Google Workspace integration guides, admin policy/enforcement console features, and any independent confirmation these integrations work in practice.

                  • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                  • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                  • [claimed-docs] YubiKey — strongest hardware-backed passkey
                  Feitian FIDO Keyspartialclaimed6/10

                  Feitian keys are documented as fully W3C WebAuthn/FIDO2-compliant HID devices with explicit setup guides for Azure AD-joined Windows, Microsoft applications, and Google Advanced Protection, which implies interoperability with major identity providers. However, there is no explicit documentation or guide for Okta or Google Workspace integration, nor any mention of admin-side policy enforcement (e.g., requiring hardware-key-only auth) within these IdPs. Missing for 10: Okta-specific integration guide, Google Workspace-specific setup docs, and evidence of IdP admin policy controls enforcing hardware-key requirements.

                  • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.
                  • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.
                  • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).

                Provisioning

                1. it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

                  weight 3 · round to YubiKey
                  YubiKeypartialprobed6/10

                  Yubico documents ykman for scriptable bulk device configuration (PIN/PIV/OATH/OTP setup) and a live YubiEnterprise 'YubiKey as a Service' REST API covering fleet delivery, inventory, and shipment management, plus PIV attestation to verify keys were hardware-generated — together these map to pre-registration, bulk config, and some lifecycle tracking. Missing for 10: detailed enterprise lifecycle-tracking dashboard docs, independent/customer case studies of at-scale deployment, and clearer documentation tying pre-registration workflows directly to the API rather than inferring from an apidocs page title.

                  • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                  • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                  • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
                  • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
                  • [claimed-docs] Configure your YubiKey via the command line.
                  Feitian FIDO Keysnone0/10

                  Evidence only shows per-device configuration tools (SK Manager, iePassManager) for individual FIDO/PIV/OTP settings, not organization-wide bulk provisioning, pre-registration workflows, or lifecycle/inventory tracking across a fleet of keys. No admin console, CSV/bulk import, or enterprise deployment tooling is documented.

                  • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                  • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                  • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                  • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.

                Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors

                The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

                Certifications

                1. it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

                  weight 2 · round drawn
                  YubiKeynone0/10

                  The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or documented durability/water/crush resistance testing for any YubiKey model. While this axis clearly applies to a hardware security key product aimed at regulated environments, none of the docs, community, or probe items address certification status or physical durability specs, so there is nothing to credit.

                    Feitian FIDO Keysnone0/10

                    The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or durability testing (water/crush resistance) for any Feitian key; all citations focus on protocol compatibility, interfaces, and setup guides. Missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, water/crush resistance durability specs.

                    Connectors

                    1. power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

                      weight 2 · round drawn
                      YubiKeynone0/10

                      The evidence pack contains no documentation or community confirmation of specific YubiKey form factors (USB-C, USB-A, keychain, nano) — only general docs about protocols/SDKs and community comments about size/bulkiness in vague terms (e.g., yubikey-comm-9 says 'more compact and less bulky' without specifics). Missing for 10: explicit product-line documentation of USB-A/USB-C variants, nano/keychain form factors, and any independent confirmation of the lineup breadth.

                        Feitian FIDO Keysnone0/10

                        The evidence pack covers interfaces (USB/NFC/BLE), biometric and OpenSK products, but never mentions specific form factors like USB-C vs USB-A connectors, keychain design, or nano/low-profile sizing — no product lineup breakdown by physical form is shown.

                        Nfc

                        1. power userTap the key on my phone over NFC to authenticate in mobile browsers and apps

                          weight 2 · round drawn
                          YubiKeypartialclaimed6/10

                          Yubico's own SDK docs confirm NFC support for both Android (yubikit-android supports USB and NFC-enabled YubiKeys) and iOS (yubikit-ios provides NFC OTP requests), and YubiKey's core FIDO2/WebAuthn/passkey stack (docs-27, docs-14, docs-16) is the basis for authenticating in mobile browsers/apps, but the evidence is SDK/developer-facing rather than an end-user confirmation that a stock mobile browser/app tap-to-auth flow just works. missing for 10: an explicit first-party or hands-on claim that end-users can tap NFC on a phone in a mobile browser (not just app SDK) to authenticate, and independent/community corroboration of real-world NFC mobile browser use.

                          • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
                          • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
                          • [claimed-docs] YubiKey — strongest hardware-backed passkey
                          • [claimed-docs] Passkeys are the long awaited replacement for passwords.
                          • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                          Feitian FIDO Keyspartialclaimed6/10

                          MultiPass FIDO Security Key explicitly supports NFC as one of three interfaces and is documented compatible with Android/iOS platforms, implying tap-to-authenticate via NFC on mobile; however, evidence doesn't explicitly confirm NFC (vs BLE) works with specific mobile browsers/apps or provide hands-on confirmation. missing for 10: explicit mobile browser/app NFC tap walkthrough, independent hands-on verification of NFC mobile authentication.

                          • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.
                          • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…
                          • [claimed-docs] MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.

                        Openness — open source, data portability, and self-hosting storiesOpenness

                        Open source, data portability, and self-hosting stories

                        1. ai-native userDo everything through the API that I can do in the UI

                          weight 2 · round to YubiKey
                          YubiKeypartialprobed6/10

                          Yubico's ykman CLI is documented as functionally interchangeable with the Yubico Authenticator GUI for core device configuration (enabling applications, PINs, PIV/OATH/OTP slots, firmware info), and the YubiEnterprise REST API covers fleet-management tasks that would otherwise be done via console UI, giving real API/CLI parity for administrative workflows. However there's no evidence of a unified, fully-documented API surface covering every consumer-facing UI action (e.g., newer Authenticator app credential-management screens), and no llms.txt/MCP endpoint exists for agent discovery of these surfaces. Missing for 10: comprehensive mapping of every UI feature to an API/CLI equivalent, and agent-discoverable API documentation (llms.txt/MCP/OpenAPI all return 404).

                          • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                          • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                          • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                          • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
                          • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
                          Feitian FIDO Keysnone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          • ai-native userExport all of my data in open formats and leave

                            weight 3 · round drawn
                            YubiKeynone0/10

                            YubiKey's core design explicitly prevents exporting the data it stores — private keys are generated on-device and 'cannot be exported or extracted' (yubikey-docs-23), and SSH/FIDO2 docs stress private keys 'never leave the hardware' (yubikey-docs-5). There is no vendor or community evidence of any open-format bulk data export/portability path; the product's security model is fundamentally opposed to this story.

                            • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
                            • [claimed-docs] FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.
                            • [claimed-docs] the shared secrets are stored and processed in the YubiKey's secure element
                            Feitian FIDO Keysnone0/10

                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                            • ai-native userRead the product's source under an open license

                              weight 2 · round to Feitian FIDO Keys
                              YubiKeynone0/10

                              YubiKey is closed hardware/firmware — community evidence explicitly notes it is 'a proprietary smartcard' and that Yubico 'does not permit firmware flashing,' with no vendor claim or evidence of the core product's source being published under an open license. Some client SDKs/CLIs (python-fido2, ykman) are open-source, but that is tooling around the product, not the product's own source.

                              • [community] A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…
                              • [community] Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…
                              • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
                              Feitian FIDO Keyspartialclaimed4/10

                              Feitian ships a specific 'OpenSK' hardware variant that can run firmware built from Google's open-source OpenSK repository, giving some access to readable/open-licensed source for that SKU, but this is a third-party (Google) codebase, not Feitian's own firmware for its mainstream BioPass/MultiPass keys, which remain closed. Missing for 10: evidence that Feitian's own primary product firmware/source is published under an open license, and no indication of a public source repo, license file, or docs-as-markdown/API spec for the broader product line.

                              • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                              • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                            • ai-native userSelf-host the core product

                              weight 3 · round to Feitian FIDO Keys
                              YubiKeynone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                Feitian FIDO Keyspartialclaimed5/10

                                The FIDO key is inherently a local, on-device hardware authenticator (not a hosted service), and Feitian explicitly documents that users can build firmware from Google's open-source OpenSK repository and provision it onto the hardware themselves, giving genuine control over the 'core product' without vendor cloud dependency. This is a reasonable analog to self-hosting for a hardware device, but it's not a full self-hostable software stack with deployment docs, and there's no evidence of self-hosted backend/server components (e.g., FIDO server, attestation service) that would round out a complete self-hosting story. Missing for 10: documentation of self-hosting any server-side/relying-party components, deployment guides beyond firmware flashing, and independent confirmation of OpenSK build success.

                                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…

                              Privacy posture — data-handling and privacy storiesPrivacy posture

                              Data-handling and privacy stories

                              1. ai-native userControl data retention and deletion

                                weight 2 · round drawn
                                YubiKeynone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Feitian FIDO Keysnone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  • ai-native userOpt out of telemetry and usage tracking

                                    weight 2 · round drawn
                                    YubiKeynone0/10

                                    The evidence pack covers YubiKey's hardware authentication, SDKs, and CLI tooling, but contains no mention of telemetry collection or any opt-out/privacy-control setting for Yubico software (ykman, Yubico Authenticator, or the YubiEnterprise console). Since companion software and cloud services could plausibly include telemetry, the axis applies, but there's no evidence of a telemetry opt-out feature.

                                      Feitian FIDO Keysnone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage

                                      FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

                                      Credential management

                                      1. power userList and delete the passkeys stored on my key and know its credential capacity before it fills up

                                        weight 2 · round drawn
                                        YubiKeypartialprobed4/10

                                        Yubico's ykman CLI/GUI (docs-4, probe-rt-1) provides broad scriptable device management (PIV/OATH/OTP slots, PINs, device info) and firmware/version info tools (docs-15/25), suggesting some credential-management capability exists, but no evidence explicitly confirms listing/deleting FIDO2 passkey credentials or showing passkey storage capacity/limits. Community threads discuss losing track of which accounts a key is enrolled in (yubikey-comm-7) rather than a management UI. Missing for 10: explicit documentation of a 'list/delete FIDO2 credentials' command, and disclosure of the discrete passkey slot capacity/limit warning.

                                        • [claimed-docs] Configure your YubiKey via the command line.
                                        • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                                        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                                        • [community] I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …
                                        Feitian FIDO Keyspartialclaimed4/10

                                        FEITIAN provides tools (SK Manager, iePassManager) described as managing 'FIDO PIN and credential related operations' on the key, implying some list/delete capability, and one product page claims 'no limit to accounts' for the MultiPass key. However, there is no explicit documentation of a list/delete-passkey UI, no discussion of credential capacity limits for other models, and no guidance on capacity awareness before a key fills up. missing for 10: explicit list/delete UI screenshots or steps, documented per-model credential capacity limits, and warnings/behavior when storage is full.

                                        • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                                        • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                        • [claimed-docs] There is no limit to the number of accounts registered in MultiPass FIDO® Security Key.

                                      Fido2

                                      1. security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

                                        weight 3 · round to YubiKey
                                        YubiKeyfullcommunity8/10

                                        YubiKey firmware 5+ and CTAP2 support discoverable/resident credentials for passwordless, usernameless passkey sign-in, backed by Yubico's own passkey docs, WebAuthn docs, python-fido2/java-webauthn-server SDKs, and marketing explicitly calling it 'strongest hardware-backed passkey', plus community confirmation of FIDO2/WebAuthn support alongside other smartcard apps. Missing for 10: no independent hands-on test specifically confirming resident-key/discoverable-credential storage limits or usernameless login flow success in the wild.

                                        • [claimed-docs] YubiKey 5.8 is here — hardware signing, CTAP 2.3, and smoother passkey UX.
                                        • [claimed-docs] Passkeys are the long awaited replacement for passwords.
                                        • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                                        • [claimed-docs] this guide will provide all the necessary technical knowledge required to adopt passkeys into your application
                                        • [claimed-docs] YubiKey — strongest hardware-backed passkey
                                        • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
                                        • [claimed-docs] Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…
                                        • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
                                        Feitian FIDO Keyspartialclaimed5/10

                                        Feitian's keys are explicitly W3C WebAuthn/FIDO2 compliant and marketed for passwordless sign-in scenarios like Windows Hello and Google Advanced Protection, which typically rely on discoverable credentials, but the evidence never explicitly names 'resident keys' or 'discoverable credentials' or confirms a specific stored-credential capacity/no-username login flow. Missing for 10: explicit documentation of resident-key/discoverable-credential support, stated credential storage limits, and a hands-on demonstration of username-less WebAuthn sign-in.

                                        • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                        • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).
                                        • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.
                                        • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                      2. power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

                                        weight 2 · round to YubiKey
                                        YubiKeyfullcommunity8/10

                                        YubiKey's core product design centers on FIDO2/WebAuthn and U2F as documented protocols, and community evidence corroborates that these keys function as WebAuthn/FIDO2 authenticators and PIV/GPG smartcards in real-world use across services. The docs describe passkey/WebAuthn support generically rather than confirming each specific service, but WebAuthn is a standard so this is a reasonable cross-service claim; independent community posts (yubikey-comm-14, yubikey-comm-16) reinforce broad protocol compatibility in practice. missing for 10: explicit named confirmation/citations for Google, GitHub, Microsoft, and specific password manager integrations rather than generic standard-protocol docs.

                                        • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                                        • [claimed-docs] Passkeys are the long awaited replacement for passwords.
                                        • [claimed-docs] YubiKey — strongest hardware-backed passkey
                                        • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
                                        • [community] Also, yubikey works as a PIV smartcard.
                                        • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
                                        Feitian FIDO Keyspartialclaimed7/10

                                        First-party docs confirm W3C WebAuthn/U2F compliance and dedicated guides for GitHub (OpenSSH), Microsoft/Azure AD, and Google Advanced Protection, showing broad cross-service compatibility. Missing for 10: explicit password-manager (e.g., 1Password/Bitwarden) integration guidance and independent/hands-on verification beyond vendor documentation.

                                        • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                        • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                                        • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                                        • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.
                                        • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.

                                      User verification

                                      1. security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

                                        weight 2 · round to YubiKey
                                        YubiKeyfullcommunity8/10

                                        Docs explicitly confirm FIDO2 supports optional PIN-based user verification in addition to touch/presence (yubikey-docs-6), and community evidence corroborates PIN enrollment is a real, if sometimes overlooked, setup step (yubikey-comm-13). This directly matches on-device verification (PIN) preventing a stolen key alone from authenticating; biometric variants exist on Bio series keys but aren't explicitly documented here. Missing for 10: explicit mention of built-in biometric/fingerprint verification and independent hands-on confirmation of PIN enforcement blocking a stolen key.

                                        • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
                                        • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
                                        Feitian FIDO Keysfullclaimed7/10

                                        Feitian documents biometric (fingerprint) on-device user verification for BioPass keys, explicitly noting 'losing the key will cause no security risk at all,' and separately documents FIDO PIN management via iePassManager for PIN/credential operations, satisfying the on-device UV requirement. Missing for 10: independent/hands-on verification of PIN enforcement or biometric FAR/FRR, and no explicit CTAP2 'uv' flag documentation.

                                        • [claimed-docs] Biometric technology makes BioPass FIDO2 Security Key one of the most secure tokens.
                                        • [claimed-docs] The fingerprint module prevents any misuses of the token from people other than authorized user, and losing the key will cause no security r…
                                        • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                        • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.

                                      Not comparable on these axes

                                      1. ai-native userPlug MCP servers into this product so it can use their tools

                                        weight 3 · not comparable
                                        YubiKeyn/a

                                        YubiKey is a hardware authentication device; plugging MCP servers into it so it can use their tools is a category error—it has no agentic runtime to consume tools. Evidence confirms no MCP endpoint exists, but that's incidental since the axis doesn't apply to this product type.

                                        • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
                                        Feitian FIDO Keysn/a

                                        Feitian is a hardware FIDO security key/authentication device, not an AI agent or platform that consumes MCP tools; plugging in MCP servers is a wrong-axis question for this product category.

                                        • ai-native userConnect an agent via an official MCP server

                                          weight 3 · not comparable
                                          YubiKeyn/a

                                          YubiKey is a hardware authentication device, not an agent or platform serving tools to AI agents; connecting agents via MCP servers is a category mismatch for this product type.

                                            Feitian FIDO Keysn/a

                                            Feitian FIDO Keys is a hardware security-key/authentication product, not an AI agent platform or service with an ecosystem for exposing tools to agents; MCP server connectivity is a wrong-axis question for this product category.

                                            • ai-native userIssue scoped/least-privilege API credentials for an agent

                                              weight 2 · not comparable
                                              YubiKeyn/a

                                              YubiKey is a hardware authentication device for human-presence-based MFA/passkeys/PIV/SSH — it authenticates a person via touch, PIN, or physical possession. It has no concept of issuing scoped, least-privilege API credentials to an autonomous agent (a distinct IAM/OAuth-style capability); its APIs (ykman, YubiEnterprise fleet API, python-fido2) manage the physical device itself, not agent-scoped credentials. This is a category mismatch, not a missing feature.

                                                Feitian FIDO Keysn/a

                                                Feitian is a hardware FIDO security key/authenticator product, not an API/credential-issuing platform or agent framework; issuing scoped API credentials for an AI agent is outside its product category.

                                                • ai-native userSubscribe to events via webhooks

                                                  weight 2 · not comparable
                                                  YubiKeyn/a

                                                  YubiKey is a hardware authentication device/SDK ecosystem, not an event-driven platform; there is no concept of subscribable events or webhooks applicable to its product category — this is a category error, not a missing feature.

                                                    Feitian FIDO Keysn/a

                                                    Feitian FIDO Keys is a hardware authentication device, not a service or platform with event-driven architecture; webhooks are a wrong axis for a physical security key product.

                                                    • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                      weight 2 · not comparable
                                                      YubiKeyn/a

                                                      YubiKey is a hardware authentication device (security key); it has no data surface, dashboard, or analytics function to generate AI insights from. This axis is a category error for a hardware security key product.

                                                        Feitian FIDO Keysn/a

                                                        Feitian FIDO Keys is a hardware authentication device (security key) for FIDO2/WebAuthn login, not a data platform or analytics product; it has no data store or content for AI to generate insights from. This axis is a category error for a hardware security key.

                                                        • ai-native userSet up automations that run autonomously in the background

                                                          weight 2 · not comparable
                                                          YubiKeyn/a

                                                          YubiKey is a hardware authentication device; it requires physical touch/presence for its security model and cannot run autonomous background automations — this is a category error, not a missing feature.

                                                            Feitian FIDO Keysn/a

                                                            Feitian FIDO Keys are physical authentication hardware, not an automation/agent platform; autonomous background automations are entirely outside this product's category (wrong axis).

                                                            • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                              weight 3 · not comparable
                                                              YubiKeyn/a

                                                              YubiKey is a hardware authentication device; it has no AI assistant of any kind, built-in or otherwise. This story is a category error for this product type.

                                                                Feitian FIDO Keysn/a

                                                                Feitian FIDO Keys are hardware security/authentication tokens; they have no AI assistant functionality and the category itself is unrelated to AI task delegation.

                                                                • ai-native userOperate the product with natural-language commands

                                                                  weight 2 · not comparable
                                                                  YubiKeyn/a

                                                                  YubiKey is a hardware authentication device operated via physical touch, PIN entry, and traditional CLI tools (ykman) for configuration — there is no natural-language command interface, and the product category (a cryptographic hardware token) does not involve conversational or agentic control surfaces. This axis is a category error for a hardware key rather than an unmet capability.

                                                                    Feitian FIDO Keysn/a

                                                                    Feitian FIDO Keys are physical hardware authentication tokens; natural-language/AI-agent command interaction is not a relevant axis for a hardware security key product.

                                                                    • ai-native userExplore an interactive API reference with runnable examples

                                                                      weight 2 · not comparable
                                                                      YubiKeynone0/10

                                                                      Evidence shows YubiKey's developer docs are static HTML references (SDK guides, protocol explanations) rather than an interactive, runnable API console; explicit probes for OpenAPI/Swagger specs return 404 and no llms.txt/MCP endpoint exists. The only REST API surface found (YubiEnterprise apidocs) is confirmed live but with no evidence of runnable/try-it-out examples.

                                                                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
                                                                      • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                                                                      • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
                                                                      Feitian FIDO Keysn/a

                                                                      Feitian FIDO Keys are hardware authentication devices, not an API/SDK product; an interactive API reference with runnable examples is a category mismatch (wrong axis) rather than a missing feature.

                                                                      • ai-native userTest against a sandbox environment without touching production data

                                                                        weight 1 · not comparable
                                                                        YubiKeyn/a

                                                                        YubiKey is a hardware authentication device; the notion of a sandbox environment to test against without touching production data is not a meaningful axis for this product category — it's a physical security key, not a service with test/production data separation.

                                                                          Feitian FIDO Keysn/a

                                                                          Feitian FIDO Keys is a hardware authentication device, not a software/API product with sandbox vs production environments; the sandbox-testing story is a category error for this product type.

                                                                          • ai-native userRely on versioned APIs with a documented deprecation policy

                                                                            weight 2 · not comparable
                                                                            YubiKeynone0/10

                                                                            YubiKey ships multiple SDKs and a REST API (YubiEnterprise) plus CLI tools, so the axis of API stability/versioning is applicable, but nothing in the evidence pack documents a versioning scheme or deprecation policy for any of these surfaces — firmware version references (yubikey-docs-15/25) concern hardware firmware, not API contracts, and probes found no OpenAPI spec or changelog.

                                                                            • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                                                                            • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
                                                                            • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                                                                            • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
                                                                            Feitian FIDO Keysn/a

                                                                            Feitian FIDO Keys are hardware authentication devices implementing the FIDO/WebAuthn standard, not a software service with an API surface for AI agents to consume; versioned APIs and deprecation policies are not a relevant axis for this product category.

                                                                            • ai-native userDefine rules that trigger actions automatically on events

                                                                              weight 3 · not comparable
                                                                              YubiKeyn/a

                                                                              YubiKey is a hardware authentication/security key (FIDO2, PIV, OpenPGP, OTP) — it has no event-driven rules engine or automation-trigger capability, and defining automated action rules is outside its product category as an authenticator rather than an automation platform.

                                                                                Feitian FIDO Keysn/a

                                                                                Feitian FIDO Keys are hardware authentication devices; defining automation rules triggered on events is a software/workflow automation capability entirely outside this product's category.

                                                                                • ai-native userSchedule recurring jobs or workflows

                                                                                  weight 2 · not comparable
                                                                                  YubiKeyn/a

                                                                                  YubiKey is a hardware authentication device; scheduling recurring jobs/workflows is a software automation/orchestration capability entirely outside a security key's product category — this is a wrong-axis question, not a missing feature.

                                                                                    Feitian FIDO Keysn/a

                                                                                    Feitian FIDO Keys are hardware authentication tokens for identity verification, not workflow/automation tools; scheduling recurring jobs is entirely outside this product's category.

                                                                                    • ai-native userVersion, review, and roll back my automations

                                                                                      weight 1 · not comparable
                                                                                      YubiKeyn/a

                                                                                      YubiKey is a hardware authentication device; it has no concept of automations to version, review, or roll back. This story applies to workflow/automation platforms, not a security key product.

                                                                                        Feitian FIDO Keysn/a

                                                                                        Feitian FIDO Keys are hardware authentication devices; versioning, reviewing, or rolling back automations is not a capability applicable to this product category.

                                                                                        • ai-native userChoose where my data is stored (region/residency)

                                                                                          weight 2 · not comparable
                                                                                          YubiKeyn/a

                                                                                          YubiKey is a hardware authentication device/token, not a data storage or cloud service; data residency/region selection is not a relevant axis for this product category (the evidence pack shows no user data storage service at all, aside from a minor enterprise device-inventory API unrelated to region choice).

                                                                                            Feitian FIDO Keysn/a

                                                                                            Feitian FIDO Keys are physical hardware authentication devices with no cloud data storage component; data residency/region choice is not applicable to a local hardware security key that stores no user data in a service backend.

                                                                                            • ai-native userPrevent my data from being used to train AI models

                                                                                              weight 3 · not comparable
                                                                                              YubiKeyn/a

                                                                                              YubiKey is a hardware authentication device; it has no role in AI model training data pipelines or data-usage opt-out controls, so preventing personal data from being used to train AI models is a category error for this product.

                                                                                                Feitian FIDO Keysn/a

                                                                                                Feitian FIDO Keys is a hardware authentication device (security key for FIDO2/U2F/WebAuthn), not an AI service or data platform that trains models on user data. The concept of 'preventing data from being used for AI training' is a category error for this product type.