YubiKey vs Google Titan Security Key
hardware-purchase · enterprise-subscription
·hardware-purchase
YubiKey wins · 23–5 (8 drawn)
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
Agent access
ai-native userRun the product headlessly / in CI for automation
weight 2 · round to YubiKeyYubico ships scriptable tooling (ykman CLI, python-fido2 SDK) that can configure/query keys programmatically in scripts or CI pipelines, and a fleet REST API for enterprise management — but the core authentication function inherently requires physical touch/user presence, which cannot be automated headlessly. Missing for 10: any documented way to perform actual FIDO2/PIV/OATH authentication or signing operations without a human touch event, explicit CI/automation guidance, and evidence of true headless operation for the security-critical path (only configuration/management is scriptable).
- [claimed-docs] “Configure your YubiKey via the command line.”
- [claimed-docs] “FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
ai-native userUse an official CLI
weight 2 · round to YubiKeyYubiKey ships an official CLI (ykman/yubikey-manager) for device configuration, verified installable via pip/uvx and Homebrew with scriptable device management, but this is a hardware-configuration tool, not an AI-agentic CLI designed for LLM/agent workflows — there's no evidence of AI-native features like structured output for agents, agent-oriented docs, or MCP integration. missing for 10: evidence of AI-agent-oriented usage patterns, structured/machine-readable output tailored for agentic consumption, and any llms.txt/MCP support (explicitly absent per probes).
- [claimed-docs] “Configure your YubiKey via the command line.”
- [probe] “official CLI documented at https://developers.yubico.com/yubikey-manager/”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
ai-native userDrive the product through a documented public API
weight 3 · round to YubiKeyYubiKey exposes genuine programmatic interfaces — the ykman CLI, python-fido2 SDK, PKCS#11/PIV/OpenPGP libraries, and platform SDKs (Android/iOS/.NET) — that let a developer or automated agent drive the device (yubikey-docs-4, yubikey-probe-rt-1, yubikey-probe-rt-3, yubikey-docs-8, yubikey-docs-19). There is also a separate REST API for YubiEnterprise fleet management (yubikey-probe-rt-2). However, there is no unified public REST/OpenAPI spec for the core device (probe-3 confirms 404s), and no AI-agent-oriented discovery layer like llms.txt or MCP (yubikey-probe-1, yubikey-probe-rt-4). Missing for 10: a documented OpenAPI/REST spec for core device operations, and any llms.txt/MCP support for AI-agent consumption.
- [claimed-docs] “Configure your YubiKey via the command line.”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
- [claimed-docs] “It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…”
- [claimed-docs] “The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
ai-native userBuild against official SDKs
weight 2 · round to YubiKeyYubico publishes and maintains a broad set of official SDKs (python-fido2, java-webauthn-server, .NET SDK, YubiKit Android/iOS, ykman CLI) with dedicated docs, and runtime probes confirm these packages are live and installable from public registries (PyPI, Homebrew) rather than just claimed in docs. This gives developers, including AI-native builders, real programmatic building blocks for passkeys/FIDO2/PIV integration. Missing for 10: no AI-agent-specific SDK examples or agent-oriented tooling, and no independent (non-Yubico) hands-on validation of SDK developer experience.
- [claimed-docs] “Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.”
- [claimed-docs] “The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.”
- [claimed-docs] “YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.”
- [claimed-docs] “The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
- [claimed-docs] “Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…”
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
ai-native userPerform bulk operations across many items at once
weight 2 · round to YubiKeyYubico exposes a scriptable CLI (ykman) and a YubiEnterprise fleet-management REST API that could be used to configure or manage many keys programmatically, hinting at bulk-capable automation, but no docs explicitly describe a bulk/batch operation (e.g., configuring N keys or revoking many credentials in one call). Missing for 10: explicit bulk-operation API/CLI documentation, batch examples, and independent confirmation that many items can be processed in one automated action.
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [claimed-docs] “Configure your YubiKey via the command line.”
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Openpgp
developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email
weight 2 · round to YubiKeyYubico's own docs describe OpenPGP support with RSA/ECC sign/encrypt operations using a private key stored on the YubiKey smartcard (yubikey-docs-9, yubikey-docs-26), and independent community testimony confirms real-world use of YubiKey's GPG smartcard functionality (contrasted with competitors lacking it) (yubikey-comm-14, yubikey-comm-15). This covers the underlying capability for git commit signing (via GPG) and encrypted email (via OpenPGP), though neither specific workflow (git config, email client integration) is explicitly documented in the pack. Missing for 10: explicit git commit-signing walkthrough/documentation, explicit encrypted-email (e.g., Enigmail/Thunderbird) setup guide, and more first-party depth beyond the general OpenPGP overview.
- [claimed-docs] “OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…”
- [claimed-docs] “It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as YubiKeys), through common interfaces like P…”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
- [community] “Unfortunately SoloKey doesn't work as an OpenPGP smart card, which means it's not a real substitute for a Yubikey.”
Google Titan Security Keynone0/10Titan Security Key is a FIDO/U2F authenticator with no documented OpenPGP applet or smartcard support for git commit signing or encrypted email; evidence only covers FIDO2/U2F sign-in use cases.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
Otp
power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
weight 2 · round to YubiKeyYubiKey natively supports OATH TOTP/HOTP slots (with secrets stored in the secure element) and Yubico OTP/challenge-response via the OTP application, documented and manageable via ykman/Yubico Authenticator, covering legacy services without WebAuthn. Community evidence corroborates real-world use of these legacy modes alongside FIDO2. Missing for 10: independent hands-on walkthrough of setting up HOTP/TOTP slots or challenge-response specifically, and more detail on slot capacity/limits.
- [claimed-docs] “the shared secrets are stored and processed in the YubiKey's secure element”
- [claimed-docs] “No client software needed. The OTP is just a string. If you can send a password, you can send an OTP.”
- [claimed-docs] “The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…”
- [claimed-docs] “Configure your YubiKey via the command line.”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
Google Titan Security Keynone0/10Titan Security Key is a FIDO/U2F/WebAuthn hardware authenticator; no evidence indicates it supports TOTP/HOTP seed storage or generic challenge-response slots for legacy OTP services. All documentation focuses on FIDO CTAP1/U2F/WebAuthn use cases only.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
Piv
it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
weight 2 · round to YubiKeyDocs confirm PIV smart-card functionality (PKCS#11 sign/encrypt with on-device RSA/ECC keys, non-exportable, with attestation to prove device-generated keys), and community independently corroborates real-world PIV smart-card use (yubikey-comm-16, yubikey-comm-14). This covers certificate-based login and code-signing capability, though the workstation-login and VPN integration flows themselves aren't explicitly documented in this pack. Missing for 10: explicit docs/screenshots of Windows/macOS smart-card workstation sign-in setup, VPN client PIV integration guides, and a dedicated code-signing walkthrough.
- [claimed-docs] “It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…”
- [claimed-docs] “The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.”
- [claimed-docs] “This certificate should be used for the purpose of verifying that the key was generated in device.”
- [community] “Also, yubikey works as a PIV smartcard.”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
Google Titan Security Keynone0/10Evidence only covers FIDO/U2F/FIDO2 authentication (Google Sign-In, CTAP1 sites, Advanced Protection) — no mention of PIV smart card mode, certificate-based login, workstation sign-in via smart card, VPN client certs, or code-signing use cases.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
Ssh
developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
weight 2 · round to YubiKeyYubico documents all three hardware-backed SSH paths: FIDO2 sk-ssh keys generated on-device with OpenSSH (private key never leaves hardware, touch required per operation), PIV smartcard usage via PKCS#11 for sign/encrypt with SSH, and OpenPGP smartcard keys for SSH auth. Community corroboration confirms FIDO2/PIV/OpenPGP smartcard functionality and touch-to-sign is genuinely enforced (not remotely bypassable). Missing for 10: no independent hands-on benchmark of ed25519 sk-ssh key generation end-to-end, and some community friction noted around PIN/touch UX onboarding.
- [claimed-docs] “FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.”
- [claimed-docs] “FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …”
- [claimed-docs] “It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…”
- [claimed-docs] “OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…”
- [claimed-docs] “you can generate the private key directly on the hardware, where it cannot be exported or extracted”
- [claimed-docs] “This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
- [community] “Also, yubikey works as a PIV smartcard.”
- [community] “The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.”
Google Titan Security Keynone0/10The evidence pack covers only FIDO2/U2F use for Google/web sign-in, Bluetooth pairing, NFC, and physical hardware details — there is no mention of sk-ssh, PIV, OpenPGP, or any SSH-key hardware-backing capability. missing for 10: sk-ssh/FIDO2 SSH key support, PIV applet, OpenPGP applet, any developer SSH workflow documentation.
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
Agent audit
ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
weight 2 · round to YubiKeyYubico's official ykman CLI (and underlying python-fido2/yubikey-manager libraries) exposes exactly this data programmatically: serial number, firmware version, enabled applications, PIN/PIV/OATH/OTP slot state, all scriptable without a client GUI — confirmed both in docs (docs-4, docs-15/25) and a keyless runtime probe showing full scriptable device management (probe-rt-1) plus SDK availability on PyPI (probe-rt-3). An agent can shell out to ykman on each key to build a fleet audit, though Yubico provides no built-in cross-fleet aggregation/reporting endpoint (the YubiEnterprise API in probe-rt-2 covers shipping/inventory, not live security-posture state). Missing for 10: a native fleet-wide audit/reporting API or dashboard aggregating multiple keys' state, and independent hands-on confirmation of scripting this across many devices at scale.
- [claimed-docs] “Configure your YubiKey via the command line.”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…”
- [probe] “official CLI documented at https://developers.yubico.com/yubikey-manager/”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
Attestation
security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled
weight 2 · round to YubiKeyYubiKey documents PIV attestation explicitly: certificates prove a key was generated on-device (not imported), and python-fido2 provides library support for 'verifying attestation and assertion signatures,' enabling backend registration flows to reject non-genuine or imported keys. This directly supports enforcing genuine device enrollment at registration time. Missing for 10: no independent/hands-on validation of attestation-based enrollment enforcement in production, and no explicit vendor-model allowlisting guide beyond the raw attestation cert mechanism.
- [claimed-docs] “The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.”
- [claimed-docs] “This certificate should be used for the purpose of verifying that the key was generated in device.”
- [claimed-docs] “Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
Google Titan Security Keydisputedcontradicted3/10Docs claim the key's hardware chip/firmware 'verifies that the keys haven't been tampered with' and provides 'cryptographic proof' of legitimate registration (google-titan-docs-12, docs-14, docs-20), which gestures at attestation, but there is no documentation or tooling aimed at security engineers for inspecting attestation certificates or enforcing an approved-model allowlist at registration. A hands-on report directly undercuts the 'genuine, approved model' framing: a user's non-Google Feitian MultiPass key (identical hardware to Titan) was accepted by Google's own replacement/registration system as if it were an official Titan key, showing the attestation/verification does not reliably distinguish genuine Titan units from rebranded third-party hardware (google-titan-comm-12, comm-14). Missing for 10: security-engineer-facing attestation verification API/metadata service, documented enforcement of approved key models, and any first-party/independent confirmation that model spoofing is prevented.
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …”
- [community] “I got one of Google's Advanced Protection kits, which included two keys that look exactly like the Titan keys in the article. Both are Feiti…”
Cli
developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
weight 3 · round to YubiKeyykman is Yubico's official CLI for configuring YubiKeys — enabling/disabling applications, setting PINs, managing PIV/OATH/OTP slots, and reading device/firmware state — and is documented and verified installable/scriptable via pip/Homebrew/uvx in runtime probes. Independent community mentions corroborate real-world use of ykman-adjacent workflows (e.g., PIN enrollment via CLI/GUI tools). Missing for 10: no independent hands-on developer review specifically praising ykman's scripting ergonomics beyond install verification.
- [claimed-docs] “Configure your YubiKey via the command line.”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [probe] “official CLI documented at https://developers.yubico.com/yubikey-manager/”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [community] “This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…”
Sdks
developerOfficial SDKs let me integrate the key into my own desktop and mobile apps
weight 2 · round to YubiKeyYubico provides official desktop SDK (.NET SDK, yubikey-manager), Android (YubiKit) and iOS (yubikit-ios) mobile SDKs, plus python-fido2 and java-webauthn-server libraries, all documented and confirmed live on package registries. missing for 10: independent third-party developer testimonials on ease of SDK integration, and no official cross-platform (e.g. Flutter/React Native) SDK is mentioned.
- [claimed-docs] “Yubico has developed a range of mobile SDKs, such as for iOS and Android, and also desktop SDKs to enable developers to rapidly integrate ha…”
- [claimed-docs] “The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.”
- [claimed-docs] “YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.”
- [claimed-docs] “The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…”
- [claimed-docs] “Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Agent approval
ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
weight 1 · round to YubiKeyYubiKey's FIDO2/WebAuthn and SSH implementations require a physical touch for every cryptographic operation, and SDKs like python-fido2, PKCS#11, and yubikey-manager expose this as a programmable building block that could be wired into an agent approval flow, but there is no evidence of any actual AI-agent or automation-approval integration built on this. missing for 10: any documented agent-framework integration, a sample workflow gating an AI or agent action behind YubiKey touch, or a third-party report of this pattern in use.
- [claimed-docs] “FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …”
- [claimed-docs] “you can generate the private key directly on the hardware, where it cannot be exported or extracted”
- [claimed-docs] “This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…”
- [community] “The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.”
Google Titan Security Keynone0/10Evidence only shows Titan Security Key being used for standard account sign-in / 2-Step Verification via FIDO/U2F, with no mention of any API, SDK, or workflow that lets an AI agent request a physical-touch approval gate for its own automated actions. Nothing in the docs or community discussion ties the key's touch requirement to agent-initiated or automated action approval.
- [claimed-docs] “Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
Compatibility
power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services
weight 2 · round to YubiKeyDocs show broad standards-based compatibility (FIDO2/WebAuthn, PIV, OpenPGP, OTP, SSH) and SDKs for iOS, Android, .NET, and desktop, implying cross-OS/browser support, and community posts confirm real-world use across GPG/PIV/SSH/WebAuthn workflows. However, there is no evidence of a published, browsable compatibility catalog listing specific supported services/websites or a browser support matrix as the story requests. Missing for 10: an explicit 'works with' directory of supported services/sites, and a documented OS/browser compatibility matrix beyond protocol-level claims.
- [claimed-docs] “the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password”
- [claimed-docs] “this guide will provide all the necessary technical knowledge required to adopt passkeys into your application”
- [claimed-docs] “The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.”
- [claimed-docs] “YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.”
- [claimed-docs] “The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
- [community] “Also, yubikey works as a PIV smartcard.”
Google Titan Security Keydisputedcontradicted4/10Google's docs claim broad cross-platform support (Android/iOS NFC, Linux setup via udev, FIDO CTAP1 compatibility with third-party sites) but there is no published catalog of specific supported services/sites—just a generic FIDO-standard compatibility statement. Community reports directly contradict smooth cross-browser/OS support: one user found keys 'only' worked with Chrome and failed on Mac despite official docs, while others reported success with Firefox on Linux and pairing issues on Mac, showing inconsistent real-world compatibility. missing for 10: an actual published list/catalog of compatible services, and confirmation that browser/OS support claims hold up without conflicting user reports.
- [claimed-docs] “Works with compatible Android and iOS devices through NFC”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…”
- [community] “The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.”
- [community] “I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…”
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Recovery
security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
weight 3 · round to Google Titan Security KeyYubiKeynone0/10The evidence pack contains no vendor documentation describing a lockout-recovery strategy (e.g., backup key enrollment guidance, what's recoverable vs. not). Community threads instead highlight the opposite experience — users must manually track and re-register every account per lost key with no central mechanism (yubikey-comm-7), and lost/compromised keys require full manual replacement across all enrolled services (yubikey-comm-2, yubikey-comm-6) — indicating this is an unaddressed gap rather than a documented workflow.
- [community] “I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …”
- [community] “I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…”
- [community] “They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…”
Google docs cover removing a lost key from an account (google-titan-docs-9) and enrolling a security key (google-titan-docs-15), and a community comment notes Google's own guidance to keep one key in daily use and store a backup safely (google-titan-comm-3), implying an informal backup-key strategy. However there is no first-party documentation laying out a full lockout-recovery plan (e.g., how to regain account access before removing the key, what happens if the only registered key is lost, or explicit backup-key enrollment steps). missing for 10: explicit vendor doc on account lockout scenarios, dedicated backup-key enrollment walkthrough, and clarity on what is/isn't recoverable if the sole key is lost
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [community] “Is it possible to use the Bluetooth dongle with a desktop computer without a cable? Having to carry both on your keyring kind of defeats the…”
- [community] “Pretty cool, I like that it comes with two keys at the start so you have a backup, unlike Yubi where I have to buy two before I can even get…”
Setup
power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
weight 2 · round to Google Titan Security KeyYubiKeydisputedcontradicted4/10Yubico ships an official 'Yubico Authenticator' app described as an 'intuitive and easy-to-use GUI interface' and provides technical guides for SSH/PGP/PIV/FIDO setup, but these are protocol-specific developer docs, not an end-to-end enrollment wizard for registering a key with personal accounts. A hands-on community report (yubikey-comm-13) describes exactly the opposite of guided onboarding: a new user enrolled keys without setting a PIN because the right guidance wasn't surfaced, then had to unenroll everywhere, set a PIN, and re-enroll — a concrete documented setup failure for a power user. Missing for 10: a dedicated first-run setup app/wizard walking users through registering with common accounts (Google, GitHub, etc.), and independent corroboration that such guidance works smoothly in practice.
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…”
- [community] “This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…”
- [claimed-docs] “This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.”
Google's support docs give step-by-step guided enrollment (sign in, 'Enroll your security key', device detects it and walks through sign-in) and cover related setup nuances like Linux udev rules and NFC/Bluetooth pairing, but there is no dedicated setup app—just web help pages. Community reports also note friction during first-time use (Chrome-only compatibility issues, Bluetooth key not pairing with Mac), suggesting the guided flow isn't universally smooth across platforms/browsers. Missing for 10: a purpose-built setup wizard/app, cross-browser first-run guidance, and independent confirmation that the documented steps work smoothly on all platforms.
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
- [claimed-docs] “Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.”
- [claimed-docs] “To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…”
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Source
security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device
weight 2 · round drawnYubiKeynone0/10Yubico documentation and community evidence describe YubiKey firmware as closed and non-upgradable ('proprietary smartcard', 'not being able to flash firmware is a feature'), with no mention of open-sourcing or third-party firmware audits anywhere in the evidence pack; no vendor claim or independent report of open/audited firmware exists to evaluate.
- [community] “YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…”
- [community] “Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…”
- [community] “Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…”
- [community] “A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…”
Google Titan Security Keynone0/10Google explicitly states firmware is 'developed by Google' and used to verify tamper-resistance, but there is no evidence of open-source firmware or independent third-party audit reports; community evidence only discusses hardware manufacturing (Feitian OEM) and a Bluetooth vulnerability, not firmware transparency/auditing. missing for 10: any published audit report, open-source firmware repository, or independent verification of firmware code.
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…”
Updates
security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
weight 2 · round to Google Titan Security KeyYubiKeydisputedcontradicted4/10Docs show only a firmware-version lookup tool (ykman/Authenticator) with no official advisory page, CVE list, or affected-model lookup in the evidence pack, and community reports confirm YubiKey firmware is not field-upgradable — vulnerability response instead relies on ad-hoc device replacement (comm-3, comm-5, comm-8) which posters describe as inconsistent and manual (comm-2, comm-4, comm-6), directly undercutting any 'clear fix pipeline' claim. missing for 10: published security-advisory index, affected-model/serial lookup tool, documented recall/replacement SLA, and any firmware-update delivery mechanism.
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…”
- [community] “YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…”
- [community] “Previously when their Yubikey 4's were found to be susceptible to the ROCA vulnerability, they issued replacements for any customers who had…”
- [community] “Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…”
- [community] “I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…”
- [community] “Don't have high hopes for this but I just requested a replacement device through their support system as the offered mitigations are not som…”
- [community] “They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…”
There is concrete real-world evidence of one incident: a BLE pairing vulnerability was disclosed, Google emailed affected users ('Update on your Titan Security Key') and ran a replacement program rather than a firmware patch, showing some vulnerability-response process exists but it worked through physical device replacement, not an in-field firmware update, and users found the replacement process cumbersome. There is no published advisory list/CVE tracker or affected-model lookup tool in the evidence — docs only vaguely mention Google-engineered firmware for tamper verification. Missing for 10: a public security-advisory/CVE page, a documented affected-model/serial lookup tool, and an actual firmware-update delivery mechanism (evidence shows fixes require full device replacement, not a firmware push).
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…”
- [community] “Not the most user-friendly replacement process here, Google. First I had to chat with a representative... Now I need to place a 'replacement…”
- [community] “The replacement site worked by sending me to a contact form where I had to chat with a representative then wait for an email to initiate an …”
- [community] “I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …”
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Agent provisioning
ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
weight 2 · round to YubiKeyYubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and publicly live (console.yubico.com/apidocs/), providing a programmatic surface for fleet delivery, inventory, and shipment management that an agent could call instead of a human-only console. However, the evidence pack gives no detail on specific endpoints for ordering, assignment, or pre-registration workflows, no sample agent integration, and no independent confirmation of end-to-end automation success. Missing for 10: detailed API endpoint documentation for order/assign/pre-register flows, evidence of actual agent-driven automation, and independent corroboration of the API's completeness.
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
Google Titan Security Keynone0/10This is a hardware security key with human-driven web console setup (enroll, pair, reset) via support docs; there is no evidence of any enterprise API for agent-driven ordering, assignment, or pre-registration of keys. missing for 10: documented provisioning/management API, evidence of programmatic ordering or fleet assignment, any agent/automation-facing endpoint.
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
Delivery
it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
weight 2 · round to YubiKeyYubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and live at console.yubico.com/apidocs/, described as the programmatic surface for fleet delivery, inventory, and shipment management — directly matching the API/console-driven distribution story. However, this rests on a single probe citation with no deeper documentation of the shipping workflow itself, no case studies, and no independent corroboration that enterprises use it this way in practice. Missing for 10: detailed docs on shipment/delivery mechanics, customer/independent confirmation of the service in use, and console UI evidence beyond the API doc existing.
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
Idp
it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
weight 2 · round drawnYubiKeynone0/10The evidence pack covers YubiKey's general FIDO2/WebAuthn/passkey protocol support and a fleet-management API (YubiEnterprise) for shipment/inventory, but contains no mention of specific IdP integrations (Okta, Entra ID, Google Workspace) or of admin-configurable policies enforcing hardware-key-only authentication. Since IdP integration and policy enforcement are a fair and expected axis for an enterprise MFA hardware vendor, absence of evidence means 'none' rather than 'na'. Missing for 10: documented Okta/Entra ID/Google Workspace integration guides, admin policy/enforcement console features, and any independent confirmation these integrations work in practice.
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [claimed-docs] “the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password”
- [claimed-docs] “YubiKey — strongest hardware-backed passkey”
Google Titan Security Keynone0/10The evidence pack covers consumer/personal account setup, Bluetooth pairing, form factors, and hardware attestation, but contains no evidence of IT-admin-facing integration with identity providers like Okta, Entra ID, or Google Workspace admin console policy enforcement for hardware-key-only authentication. This is a fair axis for a hardware security key vendor to address (fleet policy enforcement via IdP), but no such capability or documentation is present.
Provisioning
it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
weight 3 · round to YubiKeyYubico documents ykman for scriptable bulk device configuration (PIN/PIV/OATH/OTP setup) and a live YubiEnterprise 'YubiKey as a Service' REST API covering fleet delivery, inventory, and shipment management, plus PIV attestation to verify keys were hardware-generated — together these map to pre-registration, bulk config, and some lifecycle tracking. Missing for 10: detailed enterprise lifecycle-tracking dashboard docs, independent/customer case studies of at-scale deployment, and clearer documentation tying pre-registration workflows directly to the API rather than inferring from an apidocs page title.
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [claimed-docs] “The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.”
- [claimed-docs] “This certificate should be used for the purpose of verifying that the key was generated in device.”
- [claimed-docs] “Configure your YubiKey via the command line.”
Google Titan Security Keynone0/10Evidence covers individual end-user setup, pairing, resetting, and removing a single key, but nothing addresses IT-admin fleet capabilities like bulk pre-registration, centralized provisioning, or lifecycle/inventory tracking across an organization. Missing for 10: bulk enrollment tools/API, admin console integration for mass key registration, and lifecycle/inventory tracking dashboards.
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certifications
it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
weight 2 · round drawnYubiKeynone0/10The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or documented durability/water/crush resistance testing for any YubiKey model. While this axis clearly applies to a hardware security key product aimed at regulated environments, none of the docs, community, or probe items address certification status or physical durability specs, so there is nothing to credit.
Google Titan Security Keynone0/10The evidence pack contains no mention of FIPS 140 validation or Common Criteria certification for Titan Security Keys, nor documented water/crush resistance specs; in fact, one community report suggests the underlying Feitian hardware is fragile if dropped, contradicting any durability certification claim. missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, official durability/water-crush resistance specs.
- [community] “The wireless key is the Feitian MultiPass FIDO Security Key. I'd caution people to read the Amazon reviews (specifically people found it unr…”
Connectors
power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
weight 2 · round to Google Titan Security KeyYubiKeynone0/10The evidence pack contains no documentation or community confirmation of specific YubiKey form factors (USB-C, USB-A, keychain, nano) — only general docs about protocols/SDKs and community comments about size/bulkiness in vague terms (e.g., yubikey-comm-9 says 'more compact and less bulky' without specifics). Missing for 10: explicit product-line documentation of USB-A/USB-C variants, nano/keychain form factors, and any independent confirmation of the lineup breadth.
Docs confirm two form factors—USB-A/NFC and USB-C/NFC—but there is no evidence of a keychain or nano low-profile model, and community feedback even calls the (Bluetooth) key large rather than low-profile. missing for 10: keychain form factor, nano/low-profile form factor, independent hands-on confirmation of size/portability across the full claimed lineup.
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
- [community] “It's so big. Couldn't they have come up with a more subtle form factor?”
Nfc
power userTap the key on my phone over NFC to authenticate in mobile browsers and apps
weight 2 · round to Google Titan Security KeyYubico's own SDK docs confirm NFC support for both Android (yubikit-android supports USB and NFC-enabled YubiKeys) and iOS (yubikit-ios provides NFC OTP requests), and YubiKey's core FIDO2/WebAuthn/passkey stack (docs-27, docs-14, docs-16) is the basis for authenticating in mobile browsers/apps, but the evidence is SDK/developer-facing rather than an end-user confirmation that a stock mobile browser/app tap-to-auth flow just works. missing for 10: an explicit first-party or hands-on claim that end-users can tap NFC on a phone in a mobile browser (not just app SDK) to authenticate, and independent/community corroboration of real-world NFC mobile browser use.
- [claimed-docs] “YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.”
- [claimed-docs] “The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…”
- [claimed-docs] “YubiKey — strongest hardware-backed passkey”
- [claimed-docs] “Passkeys are the long awaited replacement for passwords.”
- [claimed-docs] “the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password”
Docs confirm the USB-A/NFC and USB-C/NFC key models work over NFC with compatible Android and iOS devices (iOS 13.3+), covering mobile browser/app authentication. Missing for 10: independent hands-on confirmation of NFC tap-to-auth specifically in third-party mobile apps (community evidence focuses mainly on Bluetooth/desktop use, not NFC mobile app flows).
- [claimed-docs] “Works with compatible Android and iOS devices through NFC”
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
- [claimed-docs] “iPhones with iOS version 13.3 or up | Yes | Yes”
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
ai-native userDo everything through the API that I can do in the UI
weight 2 · round to YubiKeyYubico's ykman CLI is documented as functionally interchangeable with the Yubico Authenticator GUI for core device configuration (enabling applications, PINs, PIV/OATH/OTP slots, firmware info), and the YubiEnterprise REST API covers fleet-management tasks that would otherwise be done via console UI, giving real API/CLI parity for administrative workflows. However there's no evidence of a unified, fully-documented API surface covering every consumer-facing UI action (e.g., newer Authenticator app credential-management screens), and no llms.txt/MCP endpoint exists for agent discovery of these surfaces. Missing for 10: comprehensive mapping of every UI feature to an API/CLI equivalent, and agent-discoverable API documentation (llms.txt/MCP/OpenAPI all return 404).
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
ai-native userExport all of my data in open formats and leave
weight 3 · round drawnYubiKeynone0/10YubiKey's core design explicitly prevents exporting the data it stores — private keys are generated on-device and 'cannot be exported or extracted' (yubikey-docs-23), and SSH/FIDO2 docs stress private keys 'never leave the hardware' (yubikey-docs-5). There is no vendor or community evidence of any open-format bulk data export/portability path; the product's security model is fundamentally opposed to this story.
- [claimed-docs] “you can generate the private key directly on the hardware, where it cannot be exported or extracted”
- [claimed-docs] “FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.”
- [claimed-docs] “the shared secrets are stored and processed in the YubiKey's secure element”
ai-native userRead the product's source under an open license
weight 2 · round drawnYubiKeynone0/10YubiKey is closed hardware/firmware — community evidence explicitly notes it is 'a proprietary smartcard' and that Yubico 'does not permit firmware flashing,' with no vendor claim or evidence of the core product's source being published under an open license. Some client SDKs/CLIs (python-fido2, ykman) are open-source, but that is tooling around the product, not the product's own source.
- [community] “A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…”
- [community] “Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…”
- [community] “YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…”
ai-native userSelf-host the core product
weight 3 · round drawnYubiKeynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
ai-native userControl data retention and deletion
weight 2 · round drawnYubiKeynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userOpt out of telemetry and usage tracking
weight 2 · round drawnYubiKeynone0/10The evidence pack covers YubiKey's hardware authentication, SDKs, and CLI tooling, but contains no mention of telemetry collection or any opt-out/privacy-control setting for Yubico software (ykman, Yubico Authenticator, or the YubiEnterprise console). Since companion software and cloud services could plausibly include telemetry, the axis applies, but there's no evidence of a telemetry opt-out feature.
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Credential management
power userList and delete the passkeys stored on my key and know its credential capacity before it fills up
weight 2 · round to YubiKeyYubico's ykman CLI/GUI (docs-4, probe-rt-1) provides broad scriptable device management (PIV/OATH/OTP slots, PINs, device info) and firmware/version info tools (docs-15/25), suggesting some credential-management capability exists, but no evidence explicitly confirms listing/deleting FIDO2 passkey credentials or showing passkey storage capacity/limits. Community threads discuss losing track of which accounts a key is enrolled in (yubikey-comm-7) rather than a management UI. Missing for 10: explicit documentation of a 'list/delete FIDO2 credentials' command, and disclosure of the discrete passkey slot capacity/limit warning.
- [claimed-docs] “Configure your YubiKey via the command line.”
- [probe] “PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [community] “I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …”
Google Titan Security Keynone0/10The evidence covers removing a key from a Google account and unpairing Bluetooth, but there is no mention of an on-key credential management tool that lists or deletes individual passkeys stored on the Titan key itself, nor any documentation of the key's credential storage capacity or warnings about it filling up.
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “If you want to stop using a Bluetooth Titan Security Key with one or more devices, you can unpair the key.”
Fido2
security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
weight 3 · round to YubiKeyYubiKey firmware 5+ and CTAP2 support discoverable/resident credentials for passwordless, usernameless passkey sign-in, backed by Yubico's own passkey docs, WebAuthn docs, python-fido2/java-webauthn-server SDKs, and marketing explicitly calling it 'strongest hardware-backed passkey', plus community confirmation of FIDO2/WebAuthn support alongside other smartcard apps. Missing for 10: no independent hands-on test specifically confirming resident-key/discoverable-credential storage limits or usernameless login flow success in the wild.
- [claimed-docs] “YubiKey 5.8 is here — hardware signing, CTAP 2.3, and smoother passkey UX.”
- [claimed-docs] “Passkeys are the long awaited replacement for passwords.”
- [claimed-docs] “the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password”
- [claimed-docs] “this guide will provide all the necessary technical knowledge required to adopt passkeys into your application”
- [claimed-docs] “YubiKey — strongest hardware-backed passkey”
- [claimed-docs] “Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.”
- [claimed-docs] “Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
Docs confirm passkey creation for Google Accounts (implying a discoverable, device-bound credential that lets sign-in without typing a password) via google-titan-docs-2, but the same docs explicitly describe third-party site support only via 'FIDO CTAP1 standards' (google-titan-docs-4), which does not guarantee resident-key/FIDO2 support broadly. No explicit mention of FIDO2/CTAP2 or 'discoverable credentials' terminology anywhere in the pack. Missing for 10: explicit FIDO2/CTAP2 protocol documentation, direct mention of resident/discoverable credentials, and independent verification of username-less sign-in across non-Google WebAuthn services.
- [claimed-docs] “If you want to sign in with just your security key and skip your password when possible, you must create a passkey.”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
weight 2 · round to YubiKeyYubiKey's core product design centers on FIDO2/WebAuthn and U2F as documented protocols, and community evidence corroborates that these keys function as WebAuthn/FIDO2 authenticators and PIV/GPG smartcards in real-world use across services. The docs describe passkey/WebAuthn support generically rather than confirming each specific service, but WebAuthn is a standard so this is a reasonable cross-service claim; independent community posts (yubikey-comm-14, yubikey-comm-16) reinforce broad protocol compatibility in practice. missing for 10: explicit named confirmation/citations for Google, GitHub, Microsoft, and specific password manager integrations rather than generic standard-protocol docs.
- [claimed-docs] “the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password”
- [claimed-docs] “Passkeys are the long awaited replacement for passwords.”
- [claimed-docs] “YubiKey — strongest hardware-backed passkey”
- [community] “So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…”
- [community] “Also, yubikey works as a PIV smartcard.”
- [claimed-docs] “FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …”
Google's own docs confirm broad FIDO/U2F and CTAP1 compatibility beyond Google services and even Advanced Protection use, implying standards-based interoperability, but no evidence explicitly names GitHub, Microsoft, or password-manager integrations. Community reports also flag real-world friction (e.g., 'You can only use Security Keys with Google Chrome' on Mac), showing cross-browser/service compatibility isn't seamless everywhere. missing for 10: explicit confirmation/testing with GitHub, Microsoft accounts, and specific password managers; resolution of the Chrome-only browser limitation reported by users.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “If you’re a journalist, activist, or someone else at risk of targeted online attacks, you can use Titan Security Keys with the Advanced Prot…”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…”
- [community] “The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.”
User verification
security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
weight 2 · round to YubiKeyDocs explicitly confirm FIDO2 supports optional PIN-based user verification in addition to touch/presence (yubikey-docs-6), and community evidence corroborates PIN enrollment is a real, if sometimes overlooked, setup step (yubikey-comm-13). This directly matches on-device verification (PIN) preventing a stolen key alone from authenticating; biometric variants exist on Bio series keys but aren't explicitly documented here. Missing for 10: explicit mention of built-in biometric/fingerprint verification and independent hands-on confirmation of PIN enforcement blocking a stolen key.
- [claimed-docs] “FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …”
- [community] “This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…”
Google Titan Security Keynone0/10The evidence pack describes Titan Security Keys as simple touch-based FIDO/U2F/FIDO2 keys (USB-A/NFC, USB-C/NFC, Bluetooth) with no mention of an on-device PIN pad or biometric sensor for user verification; all sign-in flows described are 'insert/tap key' without any PIN or biometric step. Missing for 10: any documentation of a FIDO2 PIN-setting flow, a fingerprint/biometric sensor, or independent confirmation of on-device user verification.
- [claimed-docs] “If you want to sign in with just your security key and skip your password when possible, you must create a passkey.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
Not comparable on these axes
ai-native userPoint an agent at llms.txt or agent-oriented docs
weight 2 · not comparableYubiKeynone0/10Direct probes confirm no llms.txt or agent-oriented docs exist on any Yubico domain (404s across docs.yubico.com, developers.yubico.com, www.yubico.com), and no MCP endpoint resolves; documentation is human-oriented HTML only.
ai-native userPlug MCP servers into this product so it can use their tools
weight 3 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; plugging MCP servers into it so it can use their tools is a category error—it has no agentic runtime to consume tools. Evidence confirms no MCP endpoint exists, but that's incidental since the axis doesn't apply to this product type.
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
ai-native userConnect an agent via an official MCP server
weight 3 · not comparableYubiKeyn/aYubiKey is a hardware authentication device, not an agent or platform serving tools to AI agents; connecting agents via MCP servers is a category mismatch for this product type.
ai-native userIssue scoped/least-privilege API credentials for an agent
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device for human-presence-based MFA/passkeys/PIV/SSH — it authenticates a person via touch, PIN, or physical possession. It has no concept of issuing scoped, least-privilege API credentials to an autonomous agent (a distinct IAM/OAuth-style capability); its APIs (ykman, YubiEnterprise fleet API, python-fido2) manage the physical device itself, not agent-scoped credentials. This is a category mismatch, not a missing feature.
ai-native userSubscribe to events via webhooks
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device/SDK ecosystem, not an event-driven platform; there is no concept of subscribable events or webhooks applicable to its product category — this is a category error, not a missing feature.
ai-native userGet AI-generated insights and suggestions from my data inside the product
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device (security key); it has no data surface, dashboard, or analytics function to generate AI insights from. This axis is a category error for a hardware security key product.
ai-native userSet up automations that run autonomously in the background
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; it requires physical touch/presence for its security model and cannot run autonomous background automations — this is a category error, not a missing feature.
ai-native userDelegate tasks to a built-in AI assistant inside the product
weight 3 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; it has no AI assistant of any kind, built-in or otherwise. This story is a category error for this product type.
ai-native userOperate the product with natural-language commands
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device operated via physical touch, PIN entry, and traditional CLI tools (ykman) for configuration — there is no natural-language command interface, and the product category (a cryptographic hardware token) does not involve conversational or agentic control surfaces. This axis is a category error for a hardware key rather than an unmet capability.
ai-native userExplore an interactive API reference with runnable examples
weight 2 · not comparableYubiKeynone0/10Evidence shows YubiKey's developer docs are static HTML references (SDK guides, protocol explanations) rather than an interactive, runnable API console; explicit probes for OpenAPI/Swagger specs return 404 and no llms.txt/MCP endpoint exists. The only REST API surface found (YubiEnterprise apidocs) is confirmed live but with no evidence of runnable/try-it-out examples.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)
weight 2 · not comparableYubiKeynone0/10Explicit probes for OpenAPI/Swagger specs at docs.yubico.com and developers.yubico.com all returned 404s, and no llms.txt or machine-readable API spec was found anywhere in Yubico's domains. While a YubiEnterprise REST API console exists, there is no evidence it is exposed as a downloadable OpenAPI/machine-readable spec.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
ai-native userTest against a sandbox environment without touching production data
weight 1 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; the notion of a sandbox environment to test against without touching production data is not a meaningful axis for this product category — it's a physical security key, not a service with test/production data separation.
ai-native userRely on versioned APIs with a documented deprecation policy
weight 2 · not comparableYubiKeynone0/10YubiKey ships multiple SDKs and a REST API (YubiEnterprise) plus CLI tools, so the axis of API stability/versioning is applicable, but nothing in the evidence pack documents a versioning scheme or deprecation policy for any of these surfaces — firmware version references (yubikey-docs-15/25) concern hardware firmware, not API contracts, and probes found no OpenAPI spec or changelog.
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman”
- [claimed-docs] “The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…”
- [probe] “PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…”
ai-native userDefine rules that trigger actions automatically on events
weight 3 · not comparableYubiKeyn/aYubiKey is a hardware authentication/security key (FIDO2, PIV, OpenPGP, OTP) — it has no event-driven rules engine or automation-trigger capability, and defining automated action rules is outside its product category as an authenticator rather than an automation platform.
ai-native userSchedule recurring jobs or workflows
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; scheduling recurring jobs/workflows is a software automation/orchestration capability entirely outside a security key's product category — this is a wrong-axis question, not a missing feature.
ai-native userVersion, review, and roll back my automations
weight 1 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; it has no concept of automations to version, review, or roll back. This story applies to workflow/automation platforms, not a security key product.
ai-native userChoose where my data is stored (region/residency)
weight 2 · not comparableYubiKeyn/aYubiKey is a hardware authentication device/token, not a data storage or cloud service; data residency/region selection is not a relevant axis for this product category (the evidence pack shows no user data storage service at all, aside from a minor enterprise device-inventory API unrelated to region choice).
ai-native userPrevent my data from being used to train AI models
weight 3 · not comparableYubiKeyn/aYubiKey is a hardware authentication device; it has no role in AI model training data pipelines or data-usage opt-out controls, so preventing personal data from being used to train AI models is a category error for this product.