Skip to content

YubiKey vs SoloKeys Solo 2

hardware-purchase · enterprise-subscription

·

hardware-purchase · open-source

YubiKey wins · 247 (7 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    YubiKeynone0/10

    Direct probes confirm no llms.txt or agent-oriented docs exist on any Yubico domain (404s across docs.yubico.com, developers.yubico.com, www.yubico.com), and no MCP endpoint resolves; documentation is human-oriented HTML only.

    • [probe] PROBE llms.txt: HTTP 404 at https://docs.yubico.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://docs.yubico.com/.md
    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
    SoloKeys Solo 2none0/10

    Explicit probes confirm docs.solokeys.dev has no llms.txt (404) and no openapi/markdown-alternative endpoints; the only llms.txt found is a generic Shopify shopping-agent file unrelated to technical/product documentation, so there is no agent-oriented documentation to point an AI agent at.

    • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md
    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to YubiKey
    YubiKeypartialprobed4/10

    Yubico ships scriptable tooling (ykman CLI, python-fido2 SDK) that can configure/query keys programmatically in scripts or CI pipelines, and a fleet REST API for enterprise management — but the core authentication function inherently requires physical touch/user presence, which cannot be automated headlessly. Missing for 10: any documented way to perform actual FIDO2/PIV/OATH authentication or signing operations without a human touch event, explicit CI/automation guidance, and evidence of true headless operation for the security-critical path (only configuration/management is scriptable).

    • [claimed-docs] Configure your YubiKey via the command line.
    • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
    SoloKeys Solo 2none0/10

    Solo 2 is a physical security key requiring human touch confirmation for every action, and while a CLI exists (solo2 list, admin commands), there's no documented support for headless/CI automation; a runtime probe shows the official CLI is bit-rotted (ImportError, incompatible fido2 dependency) with no firmware release in 4 years, further undermining any automation use case.

    • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
    • [github] solo2 list # list connected devices (alias: solo2 ls)
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
  3. ai-native userUse an official CLI

    weight 2 · round to YubiKey
    YubiKeypartialprobed6/10

    YubiKey ships an official CLI (ykman/yubikey-manager) for device configuration, verified installable via pip/uvx and Homebrew with scriptable device management, but this is a hardware-configuration tool, not an AI-agentic CLI designed for LLM/agent workflows — there's no evidence of AI-native features like structured output for agents, agent-oriented docs, or MCP integration. missing for 10: evidence of AI-agent-oriented usage patterns, structured/machine-readable output tailored for agentic consumption, and any llms.txt/MCP support (explicitly absent per probes).

    • [claimed-docs] Configure your YubiKey via the command line.
    • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
    SoloKeys Solo 2disputedcontradicted3/10

    GitHub docs show an official `solo2` CLI with scriptable commands (list, admin set led, monitor, wipe) suitable for automation, but a runtime probe found the official Solo CLI (solo-python) actually fails to run due to a dependency ImportError, and no Solo 2 firmware release has shipped in 4 years despite ongoing CI commits — concretely contradicting the claim of a working, maintained official CLI. Missing for 10: evidence of AI-agent-specific CLI usage/documentation, confirmation the solo2 (Rust) CLI itself runs cleanly, and independent corroboration beyond the vendor's own repo.

    • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
    • [github] solo2 list # list connected devices (alias: solo2 ls)
    • [claimed-docs] solo monitor <serial-port>
    • [claimed-docs] You can "wipe" a device using `fido2-token -R`
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
  4. ai-native userDrive the product through a documented public API

    weight 3 · round to YubiKey
    YubiKeypartialprobed5/10

    YubiKey exposes genuine programmatic interfaces — the ykman CLI, python-fido2 SDK, PKCS#11/PIV/OpenPGP libraries, and platform SDKs (Android/iOS/.NET) — that let a developer or automated agent drive the device (yubikey-docs-4, yubikey-probe-rt-1, yubikey-probe-rt-3, yubikey-docs-8, yubikey-docs-19). There is also a separate REST API for YubiEnterprise fleet management (yubikey-probe-rt-2). However, there is no unified public REST/OpenAPI spec for the core device (probe-3 confirms 404s), and no AI-agent-oriented discovery layer like llms.txt or MCP (yubikey-probe-1, yubikey-probe-rt-4). Missing for 10: a documented OpenAPI/REST spec for core device operations, and any llms.txt/MCP support for AI-agent consumption.

    • [claimed-docs] Configure your YubiKey via the command line.
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
    • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
    • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
    • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
    SoloKeys Solo 2none0/10

    Solo 2 exposes a hardware CLI (solo2 app/list) and standard protocols like FIDO2/PIV/OpenPGP, but there is no documented public REST/programmatic API for AI-driven control, and probes confirm no OpenAPI spec or llms.txt exists (404s) while the closest thing to an SDK (solo-python CLI) is reported bit-rotted and broken via ImportError. No evidence of a working, documented API surface an AI agent could drive.

    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…
  5. ai-native userBuild against official SDKs

    weight 2 · round to YubiKey
    YubiKeyfullprobed8/10

    Yubico publishes and maintains a broad set of official SDKs (python-fido2, java-webauthn-server, .NET SDK, YubiKit Android/iOS, ykman CLI) with dedicated docs, and runtime probes confirm these packages are live and installable from public registries (PyPI, Homebrew) rather than just claimed in docs. This gives developers, including AI-native builders, real programmatic building blocks for passkeys/FIDO2/PIV integration. Missing for 10: no AI-agent-specific SDK examples or agent-oriented tooling, and no independent (non-Yubico) hands-on validation of SDK developer experience.

    • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
    • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
    • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
    • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
    • [claimed-docs] Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…
    SoloKeys Solo 2none0/10

    Evidence shows firmware-build tooling (Rust/cargo builds, solo2 CLI, customization docs) rather than an official SDK for third-party/AI-native application development, and the one CLI tool cited is reported bit-rotted and broken in 2026 (ImportError, no releases in 4 years). No client library, API reference, or SDK package is documented for developers to build against.

    • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
    • [claimed-docs] rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
    • [github] On a **Hacker** key you can build and flash your own firmware.
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…

Api quality

  1. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

    weight 2 · round drawn
    YubiKeynone0/10

    Explicit probes for OpenAPI/Swagger specs at docs.yubico.com and developers.yubico.com all returned 404s, and no llms.txt or machine-readable API spec was found anywhere in Yubico's domains. While a YubiEnterprise REST API console exists, there is no evidence it is exposed as a downloadable OpenAPI/machine-readable spec.

    • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
    SoloKeys Solo 2none0/10

    SoloKeys is a hardware security key with a CLI and firmware documentation, not an API/web service; a machine-readable OpenAPI spec would be a fair thing to ask for if it exposed a network API, but probes explicitly show no OpenAPI/swagger spec exists at any candidate path and no llms.txt for the technical docs.

    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
    • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…

Automation depth — how much of the product can run unattendedAutomation depth

How much of the product can run unattended

  1. ai-native userPerform bulk operations across many items at once

    weight 2 · round to YubiKey
    YubiKeypartialprobed4/10

    Yubico exposes a scriptable CLI (ykman) and a YubiEnterprise fleet-management REST API that could be used to configure or manage many keys programmatically, hinting at bulk-capable automation, but no docs explicitly describe a bulk/batch operation (e.g., configuring N keys or revoking many credentials in one call). Missing for 10: explicit bulk-operation API/CLI documentation, batch examples, and independent confirmation that many items can be processed in one automated action.

    • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
    • [claimed-docs] Configure your YubiKey via the command line.
    SoloKeys Solo 2none0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

    Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido

    What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

    Openpgp

    1. developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email

      weight 2 · round to YubiKey
      YubiKeyfullcommunity7/10

      Yubico's own docs describe OpenPGP support with RSA/ECC sign/encrypt operations using a private key stored on the YubiKey smartcard (yubikey-docs-9, yubikey-docs-26), and independent community testimony confirms real-world use of YubiKey's GPG smartcard functionality (contrasted with competitors lacking it) (yubikey-comm-14, yubikey-comm-15). This covers the underlying capability for git commit signing (via GPG) and encrypted email (via OpenPGP), though neither specific workflow (git config, email client integration) is explicitly documented in the pack. Missing for 10: explicit git commit-signing walkthrough/documentation, explicit encrypted-email (e.g., Enigmail/Thunderbird) setup guide, and more first-party depth beyond the general OpenPGP overview.

      • [claimed-docs] OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…
      • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as YubiKeys), through common interfaces like P…
      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
      • [community] Unfortunately SoloKey doesn't work as an OpenPGP smart card, which means it's not a real substitute for a Yubikey.
      SoloKeys Solo 2disputedcontradicted3/10

      The GitHub README lists OpenPGP as a supported protocol (solokeys-gh-1, solokeys-gh-8), which would enable git commit signing and encrypted email use cases, but community comments directly contradict this — users report 'it doesn't do OpenPGP' and 'I'm really hoping they bring GPG to the Solokey... but I'm starting to lose confidence' (solokeys-comm-2, solokeys-comm-4). There is no first-party documentation walking through GPG key generation, git signing setup, or email encryption workflows, and no independent hands-on confirmation that OpenPGP actually works on shipped hardware. Missing for 10: verified working OpenPGP applet on shipped Solo 2 units, official docs for GPG/git-signing setup, and independent confirmation resolving the community's contradicting reports.

      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
      • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
      • [community] Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …
      • [community] I'm really hoping they bring GPG to the Solokey V1, but I'm starting to lose confidence

    Otp

    1. power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

      weight 2 · round to YubiKey
      YubiKeyfullcommunity8/10

      YubiKey natively supports OATH TOTP/HOTP slots (with secrets stored in the secure element) and Yubico OTP/challenge-response via the OTP application, documented and manageable via ykman/Yubico Authenticator, covering legacy services without WebAuthn. Community evidence corroborates real-world use of these legacy modes alongside FIDO2. Missing for 10: independent hands-on walkthrough of setting up HOTP/TOTP slots or challenge-response specifically, and more detail on slot capacity/limits.

      • [claimed-docs] the shared secrets are stored and processed in the YubiKey's secure element
      • [claimed-docs] No client software needed. The OTP is just a string. If you can send a password, you can send an OTP.
      • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
      • [claimed-docs] Configure your YubiKey via the command line.
      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
      SoloKeys Solo 2fullprobed6/10

      GitHub docs explicitly state Solo 2 speaks OATH (TOTP/HOTP) in addition to FIDO2/WebAuthn, PIV, and OpenPGP, directly supporting legacy OTP slot functionality. However, missing for 10: no CLI/setup walkthrough for configuring TOTP/HOTP slots, no independent hands-on confirmation the OATH applet works reliably, and a runtime probe shows the official Solo CLI has bit-rotted (import errors) and firmware hasn't been updated in years, raising doubts about current usability.

      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
      • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Piv

    1. it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

      weight 2 · round to YubiKey
      YubiKeyfullcommunity7/10

      Docs confirm PIV smart-card functionality (PKCS#11 sign/encrypt with on-device RSA/ECC keys, non-exportable, with attestation to prove device-generated keys), and community independently corroborates real-world PIV smart-card use (yubikey-comm-16, yubikey-comm-14). This covers certificate-based login and code-signing capability, though the workstation-login and VPN integration flows themselves aren't explicitly documented in this pack. Missing for 10: explicit docs/screenshots of Windows/macOS smart-card workstation sign-in setup, VPN client PIV integration guides, and a dedicated code-signing walkthrough.

      • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
      • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
      • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
      • [community] Also, yubikey works as a PIV smartcard.
      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
      SoloKeys Solo 2partialprobed4/10

      GitHub docs confirm Solo 2 'speaks... PIV' alongside FIDO2/OATH/OpenPGP, supporting the core claim that certificate-based smart-card auth is possible, but there is no vendor documentation on PIV provisioning, workstation/VPN sign-in setup, or code-signing workflows, and a runtime probe shows the official CLI is bit-rotted and firmware hasn't shipped a release in 4 years, raising doubt about current enterprise usability. Missing for 10: PIV certificate enrollment/management docs, workstation/VPN sign-in integration guides, code-signing workflow evidence, and confirmation the PIV applet still functions with current tooling.

      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
      • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Ssh

    1. developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

      weight 2 · round to YubiKey
      YubiKeyfullcommunity9/10

      Yubico documents all three hardware-backed SSH paths: FIDO2 sk-ssh keys generated on-device with OpenSSH (private key never leaves hardware, touch required per operation), PIV smartcard usage via PKCS#11 for sign/encrypt with SSH, and OpenPGP smartcard keys for SSH auth. Community corroboration confirms FIDO2/PIV/OpenPGP smartcard functionality and touch-to-sign is genuinely enforced (not remotely bypassable). Missing for 10: no independent hands-on benchmark of ed25519 sk-ssh key generation end-to-end, and some community friction noted around PIN/touch UX onboarding.

      • [claimed-docs] FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.
      • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
      • [claimed-docs] It enables RSA or ECC sign/encrypt operations using a private key stored on a smartcard (such as the YubiKey), through common interfaces lik…
      • [claimed-docs] OpenPGP is an open standard for signing and encrypting. It enables RSA or ECC sign/encrypt operations using a private key stored on a smartc…
      • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
      • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
      • [community] Also, yubikey works as a PIV smartcard.
      • [community] The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.
      SoloKeys Solo 2disputedcontradicted4/10

      GitHub docs assert the device 'speaks OATH (TOTP/HOTP), PIV, and OpenPGP' alongside its core FIDO2/WebAuthn support, which would in principle back sk-ssh (FIDO2), PIV, and GPG-based SSH keys — but a community commenter on the same Solo2 announcement explicitly states 'it doesn't do OpenPGP,' and an independent runtime probe shows the official solo-python CLI is broken (ImportError with current python-fido2) and firmware hasn't shipped since 2022, casting doubt that these advertised protocols are actually usable today for SSH auth. Missing for 10: explicit sk-ssh/PIV/OpenPGP SSH-key setup documentation, working current CLI/firmware evidence, and resolution of the OpenPGP support contradiction.

      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
      • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
      • [community] Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling

    Building with and managing the key — CLIs, SDKs, attestation

    Agent audit

    1. ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

      weight 2 · round to YubiKey
      YubiKeyfullprobed8/10

      Yubico's official ykman CLI (and underlying python-fido2/yubikey-manager libraries) exposes exactly this data programmatically: serial number, firmware version, enabled applications, PIN/PIV/OATH/OTP slot state, all scriptable without a client GUI — confirmed both in docs (docs-4, docs-15/25) and a keyless runtime probe showing full scriptable device management (probe-rt-1) plus SDK availability on PyPI (probe-rt-3). An agent can shell out to ykman on each key to build a fleet audit, though Yubico provides no built-in cross-fleet aggregation/reporting endpoint (the YubiEnterprise API in probe-rt-2 covers shipping/inventory, not live security-posture state). Missing for 10: a native fleet-wide audit/reporting API or dashboard aggregating multiple keys' state, and independent hands-on confirmation of scripting this across many devices at scale.

      • [claimed-docs] Configure your YubiKey via the command line.
      • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
      • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
      • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
      • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
      SoloKeys Solo 2partialprobed3/10

      The Solo 2 CLI exposes some device-state commands (`solo2 list` for connected devices/serials, `solo2 app admin ...` for config) suggesting basic programmatic querying, but there is no evidence of commands to enumerate firmware version, enabled applications, or stored credentials for fleet auditing. A runtime probe also shows the official Python CLI tooling (solo-python) is broken due to dependency incompatibility, undermining reliability of programmatic access. missing for 10: documented API/CLI output for firmware version and enabled-app enumeration, credential enumeration, a working/maintained CLI tool, any structured/machine-readable output format for fleet-scale auditing.

      • [github] solo2 list # list connected devices (alias: solo2 ls)
      • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Attestation

    1. security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled

      weight 2 · round to YubiKey
      YubiKeyfullprobed8/10

      YubiKey documents PIV attestation explicitly: certificates prove a key was generated on-device (not imported), and python-fido2 provides library support for 'verifying attestation and assertion signatures,' enabling backend registration flows to reject non-genuine or imported keys. This directly supports enforcing genuine device enrollment at registration time. Missing for 10: no independent/hands-on validation of attestation-based enrollment enforcement in production, and no explicit vendor-model allowlisting guide beyond the raw attestation cert mechanism.

      • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
      • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
      • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
      SoloKeys Solo 2partialclaimed3/10

      The docs confirm Solo 2 ships with a factory attestation key and even allow customizing/generating your own attestation key pair for bulk deployment, implying WebAuthn/FIDO2 attestation is present in principle. However there is no documentation of a FIDO Alliance MDS listing, stable AAGUID, or any RP-side verification workflow that a security engineer could use to confirm the device model at registration — and the ability to swap the attestation key yourself could actually undermine trust in a fixed identity. missing for 10: MDS/AAGUID metadata for RP verification, documented attestation-cert chain details, guidance for enterprises on enforcing genuine-model checks, independent confirmation that registration-time attestation works as expected.

      • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
      • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.

    Cli

    1. developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

      weight 3 · round to YubiKey
      YubiKeyfullprobed9/10

      ykman is Yubico's official CLI for configuring YubiKeys — enabling/disabling applications, setting PINs, managing PIV/OATH/OTP slots, and reading device/firmware state — and is documented and verified installable/scriptable via pip/Homebrew/uvx in runtime probes. Independent community mentions corroborate real-world use of ykman-adjacent workflows (e.g., PIN enrollment via CLI/GUI tools). Missing for 10: no independent hands-on developer review specifically praising ykman's scripting ergonomics beyond install verification.

      • [claimed-docs] Configure your YubiKey via the command line.
      • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
      • [probe] official CLI documented at https://developers.yubico.com/yubikey-manager/
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
      • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
      SoloKeys Solo 2disputedcontradicted3/10

      Docs and GitHub show a `solo2` CLI with some admin commands (`solo2 list`, `solo2 app admin set led`, firmware `update`) but no documented commands for setting PINs or managing slots, and reading device state relies on generic third-party `fido2-token` rather than a Solo-specific command. A runtime probe found the official Solo CLI (solo-python) actually fails to even run (`ImportError: cannot import name CTAP1`) due to incompatibility with current fido2 2.x, and firmware hasn't been released in 4 years — concrete evidence the tooling has bit-rotted rather than delivering the claimed scriptable management. missing for 10: working PIN-setting command, slot management, device-state reporting, and a CLI that runs without import errors on current dependencies.

      • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
      • [github] solo2 list # list connected devices (alias: solo2 ls)
      • [claimed-docs] You can "wipe" a device using `fido2-token -R`
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Sdks

    1. developerOfficial SDKs let me integrate the key into my own desktop and mobile apps

      weight 2 · round to YubiKey
      YubiKeyfullprobed8/10

      Yubico provides official desktop SDK (.NET SDK, yubikey-manager), Android (YubiKit) and iOS (yubikit-ios) mobile SDKs, plus python-fido2 and java-webauthn-server libraries, all documented and confirmed live on package registries. missing for 10: independent third-party developer testimonials on ease of SDK integration, and no official cross-platform (e.g. Flutter/React Native) SDK is mentioned.

      • [claimed-docs] Yubico has developed a range of mobile SDKs, such as for iOS and Android, and also desktop SDKs to enable developers to rapidly integrate ha…
      • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
      • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
      • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
      • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
      SoloKeys Solo 2none0/10

      Evidence shows only a device-management CLI (solo2 app admin/list) and firmware-building/customization tooling for the key itself, not any SDK for embedding the key into third-party desktop or mobile applications. The runtime probe even shows the existing Solo Python CLI is broken/bit-rotted, and no library/SDK for app integration is documented anywhere in the pack.

      • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
      • [github] solo2 list # list connected devices (alias: solo2 ls)
      • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat

    Where the key works — platforms, browsers, service compatibility catalogs

    Agent approval

    1. ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

      weight 1 · round to YubiKey
      YubiKeypartialprobed4/10

      YubiKey's FIDO2/WebAuthn and SSH implementations require a physical touch for every cryptographic operation, and SDKs like python-fido2, PKCS#11, and yubikey-manager expose this as a programmable building block that could be wired into an agent approval flow, but there is no evidence of any actual AI-agent or automation-approval integration built on this. missing for 10: any documented agent-framework integration, a sample workflow gating an AI or agent action behind YubiKey touch, or a third-party report of this pattern in use.

      • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
      • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
      • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's python-fido2 SDK resolves on the public PyPI registry (fido2 2.2.1), alongside yubikey-manager…
      • [community] The whole point of this touch to sign is that it can't be hacked remotely :) and you can just turn it off for most modes.
      SoloKeys Solo 2partialprobed3/10

      Solo 2 documents a generic touch-to-confirm step for WebAuthn/FIDO2 authentication (solokeys-docs-1), which could theoretically gate any human-in-the-loop confirmation, but there is no evidence tying this to AI-agent-initiated action approval flows, agentic tool integrations, or any AI-native ecosystem support. Additionally, runtime evidence shows the official CLI is broken/bit-rotted and firmware hasn't shipped in 4 years, raising doubts about active ecosystem maintenance. Missing for 10: any documentation or integration example of using Solo 2 touch confirmation as an approval gate for AI/agent workflows, evidence of SDK/API hooks for agent tooling, and independent confirmation of this use case.

      • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Compatibility

    1. power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services

      weight 2 · round to YubiKey

      Docs show broad standards-based compatibility (FIDO2/WebAuthn, PIV, OpenPGP, OTP, SSH) and SDKs for iOS, Android, .NET, and desktop, implying cross-OS/browser support, and community posts confirm real-world use across GPG/PIV/SSH/WebAuthn workflows. However, there is no evidence of a published, browsable compatibility catalog listing specific supported services/websites or a browser support matrix as the story requests. Missing for 10: an explicit 'works with' directory of supported services/sites, and a documented OS/browser compatibility matrix beyond protocol-level claims.

      • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
      • [claimed-docs] this guide will provide all the necessary technical knowledge required to adopt passkeys into your application
      • [claimed-docs] The SDK allows you to integrate the YubiKey and its applications into your .NET-based application or library.
      • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
      • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
      • [community] Also, yubikey works as a PIV smartcard.
      SoloKeys Solo 2partialprobed3/10

      Solo 2 claims broad compatibility (any USB port, no drivers, FIDO2/passkey standard, NFC for Android/iOS, OATH/PIV/OpenPGP) but there is no published compatibility catalog listing specific supported services/sites, and a runtime probe shows the official CLI tooling has bit-rotted and firmware hasn't been updated in years, raising doubts about maintained cross-platform support. Missing for 10: a published service/site compatibility list, browser-specific compatibility documentation, and evidence the tooling/firmware is actively maintained to keep pace with OS/browser changes.

      • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
      • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
      • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

    Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery

    Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

    Recovery

    1. security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

      weight 3 · round drawn
      YubiKeynone0/10

      The evidence pack contains no vendor documentation describing a lockout-recovery strategy (e.g., backup key enrollment guidance, what's recoverable vs. not). Community threads instead highlight the opposite experience — users must manually track and re-register every account per lost key with no central mechanism (yubikey-comm-7), and lost/compromised keys require full manual replacement across all enrolled services (yubikey-comm-2, yubikey-comm-6) — indicating this is an unaddressed gap rather than a documented workflow.

      • [community] I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …
      • [community] I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…
      • [community] They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…
      SoloKeys Solo 2none0/10

      No evidence in the pack discusses backup key enrollment, multi-key registration strategies, or what is/isn't recoverable if a Solo 2 is lost — documentation covers setup, building, and CLI usage but never addresses lockout/recovery planning.

      Setup

      1. power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

        weight 2 · round to SoloKeys Solo 2

        Yubico ships an official 'Yubico Authenticator' app described as an 'intuitive and easy-to-use GUI interface' and provides technical guides for SSH/PGP/PIV/FIDO setup, but these are protocol-specific developer docs, not an end-to-end enrollment wizard for registering a key with personal accounts. A hands-on community report (yubikey-comm-13) describes exactly the opposite of guided onboarding: a new user enrolled keys without setting a PIN because the right guidance wasn't surfaced, then had to unenroll everywhere, set a PIN, and re-enroll — a concrete documented setup failure for a power user. Missing for 10: a dedicated first-run setup app/wizard walking users through registering with common accounts (Google, GitHub, etc.), and independent corroboration that such guidance works smoothly in practice.

        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
        • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
        • [claimed-docs] This guide shows how to generate and use SSH keys directly on your FIDO2 security key with OpenSSH.
        SoloKeys Solo 2partialprobed3/10

        Docs mention simple plug-and-play basics ('insert into USB port, no software required', 'touch sensor to confirm') but there is no evidence of a dedicated setup app or step-by-step account-registration walkthrough; the FIDO2 side of onboarding is essentially per-website. Additionally, a runtime probe shows the official companion CLI is bit-rotted (import errors) and firmware hasn't been updated in years, undermining confidence in any first-time-setup tooling. Missing for 10: a documented onboarding wizard/app, account-registration walkthrough for accounts, working companion CLI/tooling.

        • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
        • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
        • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

      Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness

      What runs on the device — open-source firmware, update policy, vulnerability response

      Source

      1. security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

        weight 2 · round to SoloKeys Solo 2
        YubiKeynone0/10

        Yubico documentation and community evidence describe YubiKey firmware as closed and non-upgradable ('proprietary smartcard', 'not being able to flash firmware is a feature'), with no mention of open-sourcing or third-party firmware audits anywhere in the evidence pack; no vendor claim or independent report of open/audited firmware exists to evaluate.

        • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
        • [community] Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…
        • [community] Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…
        • [community] A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…
        SoloKeys Solo 2fullprobed8/10

        The Solo 2 firmware is openly published on GitHub, buildable from source, and the 'Hacker' variant explicitly supports flashing custom firmware, letting anyone inspect and verify what runs on the device; this is corroborated by community commentary confirming 'it's open source firmware, not open source hardware.' Updates are also SHA-256 verified before flashing, adding transparency to the update process. missing for 10: no formal independent third-party security audit is cited, and runtime evidence shows the firmware/tooling has not been updated since 2022, raising questions about ongoing maintenance of the open codebase.

        • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
        • [github] On a **Hacker** key you can build and flash your own firmware.
        • [github] `update` downloads the signed release, **verifies its SHA-256**, and flashes it.
        • [community] This is an LPC55S69. So it's open source firmware, not open source hardware.
        • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

      Updates

      1. security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

        weight 2 · round to YubiKey

        Docs show only a firmware-version lookup tool (ykman/Authenticator) with no official advisory page, CVE list, or affected-model lookup in the evidence pack, and community reports confirm YubiKey firmware is not field-upgradable — vulnerability response instead relies on ad-hoc device replacement (comm-3, comm-5, comm-8) which posters describe as inconsistent and manual (comm-2, comm-4, comm-6), directly undercutting any 'clear fix pipeline' claim. missing for 10: published security-advisory index, affected-model/serial lookup tool, documented recall/replacement SLA, and any firmware-update delivery mechanism.

        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
        • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
        • [community] Previously when their Yubikey 4's were found to be susceptible to the ROCA vulnerability, they issued replacements for any customers who had…
        • [community] Not being able to flash the firmware is a feature, not a bug :) Its the fundamental reason I won't buy NitroHSM because of the unknown-unkno…
        • [community] I think the most annoying part of this is that you cannot just replace a YubiKey. You need to manually go through each account and replace t…
        • [community] Don't have high hopes for this but I just requested a replacement device through their support system as the offered mitigations are not som…
        • [community] They really should [issue replacements]. The recovery of the one secret the device is supposed to keep is catastrophic. Sure, the recovery i…
        SoloKeys Solo 2disputedcontradicted3/10

        The GitHub docs describe a signed, SHA-256-verified update mechanism (solokeys-gh-2), but there is no evidence of published security advisories or an affected-model lookup, and a runtime probe shows the official CLI is bit-rotted (ImportError against current fido2 lib) and no firmware release has shipped in ~4 years despite ongoing dependency commits — directly undercutting the claim that fixes reliably reach devices. missing for 10: security advisory feed/CVE list, affected-model/version lookup tool, evidence of recent firmware releases actually reaching users, working update tooling.

        • [github] `update` downloads the signed release, **verifies its SHA-256**, and flashes it.
        • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

      Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management

      Keys at organization scale — bulk provisioning, delivery services, IdP policies

      Agent provisioning

      1. ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

        weight 2 · round to YubiKey
        YubiKeypartialprobed5/10

        Yubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and publicly live (console.yubico.com/apidocs/), providing a programmatic surface for fleet delivery, inventory, and shipment management that an agent could call instead of a human-only console. However, the evidence pack gives no detail on specific endpoints for ordering, assignment, or pre-registration workflows, no sample agent integration, and no independent confirmation of end-to-end automation success. Missing for 10: detailed API endpoint documentation for order/assign/pre-register flows, evidence of actual agent-driven automation, and independent corroboration of the API's completeness.

        • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
        SoloKeys Solo 2none0/10

        There is no evidence of any enterprise/fleet management API for ordering, assignment, or pre-registration of keys — the CLI is a local hardware management tool (list, flash, LED), and probe evidence shows no OpenAPI/API docs exist and the CLI itself is bit-rotted. This is a consumer/hacker hardware key product with no enterprise provisioning system at all.

        • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
        • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
        • [github] solo2 list # list connected devices (alias: solo2 ls)

      Delivery

      1. it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

        weight 2 · round to YubiKey
        YubiKeypartialprobed6/10

        Yubico's YubiEnterprise 'YubiKey as a Service' REST API is documented and live at console.yubico.com/apidocs/, described as the programmatic surface for fleet delivery, inventory, and shipment management — directly matching the API/console-driven distribution story. However, this rests on a single probe citation with no deeper documentation of the shipping workflow itself, no case studies, and no independent corroboration that enterprises use it this way in practice. Missing for 10: detailed docs on shipment/delivery mechanics, customer/independent confirmation of the service in use, and console UI evidence beyond the API doc existing.

        • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
        SoloKeys Solo 2none0/10

        No evidence of any enterprise provisioning/shipping API, console, or fleet-deployment logistics integration; SoloKeys is a consumer hardware key sold via a Shopify store with no fleet-management tooling documented, and CLI/API evidence is limited to device-local admin commands and firmware building. Probes even show bit-rot in the CLI and no API/OpenAPI documentation exists.

        • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
        • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
        • [claimed-docs] Pack of colored cases for Solo 2
        • [github] solo2 list # list connected devices (alias: solo2 ls)

      Idp

      1. it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

        weight 2 · round drawn
        YubiKeynone0/10

        The evidence pack covers YubiKey's general FIDO2/WebAuthn/passkey protocol support and a fleet-management API (YubiEnterprise) for shipment/inventory, but contains no mention of specific IdP integrations (Okta, Entra ID, Google Workspace) or of admin-configurable policies enforcing hardware-key-only authentication. Since IdP integration and policy enforcement are a fair and expected axis for an enterprise MFA hardware vendor, absence of evidence means 'none' rather than 'na'. Missing for 10: documented Okta/Entra ID/Google Workspace integration guides, admin policy/enforcement console features, and any independent confirmation these integrations work in practice.

        • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
        • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
        • [claimed-docs] YubiKey — strongest hardware-backed passkey
        SoloKeys Solo 2none0/10

        No evidence anywhere in the pack mentions IdP integrations (Okta, Entra ID, Google Workspace), fleet enrollment/management tools, or policy enforcement for hardware-key authentication; evidence only covers WebAuthn/FIDO2 protocol support, firmware building, and hardware details. This is a plausible axis for a security key vendor (many competitors offer admin/fleet consoles), but SoloKeys shows nothing to support it.

        Provisioning

        1. it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

          weight 3 · round to YubiKey
          YubiKeypartialprobed6/10

          Yubico documents ykman for scriptable bulk device configuration (PIN/PIV/OATH/OTP setup) and a live YubiEnterprise 'YubiKey as a Service' REST API covering fleet delivery, inventory, and shipment management, plus PIV attestation to verify keys were hardware-generated — together these map to pre-registration, bulk config, and some lifecycle tracking. Missing for 10: detailed enterprise lifecycle-tracking dashboard docs, independent/customer case studies of at-scale deployment, and clearer documentation tying pre-registration workflows directly to the API rather than inferring from an apidocs page title.

          • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
          • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
          • [claimed-docs] The concept of attestation is used to show that a certain asymmetric key has been generated on device and not imported.
          • [claimed-docs] This certificate should be used for the purpose of verifying that the key was generated in device.
          • [claimed-docs] Configure your YubiKey via the command line.
          SoloKeys Solo 2none0/10

          Evidence covers individual key setup, CLI device listing/config (`solo2 list`, `admin set led`), and custom attestation-key generation, with one offhand mention of building attestation keys 'for maybe 100,000 devices'—but there is no documented bulk-enrollment workflow, admin console, pre-registration pipeline, or lifecycle/issuance tracking system for organizations. Runtime probes further show the official CLI is broken (ImportError) and no firmware has shipped in 4 years, undercutting any claim of active enterprise tooling.

          • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
          • [github] solo2 list # list connected devices (alias: solo2 ls)
          • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

        Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors

        The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

        Certifications

        1. it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

          weight 2 · round drawn
          YubiKeynone0/10

          The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or documented durability/water/crush resistance testing for any YubiKey model. While this axis clearly applies to a hardware security key product aimed at regulated environments, none of the docs, community, or probe items address certification status or physical durability specs, so there is nothing to credit.

            SoloKeys Solo 2none0/10

            No evidence of FIPS 140 validation or Common Criteria certification anywhere in the pack; only a community comment mentions 'water resistant' informally (solokeys-comm-7), and another comment casts doubt on tamper-resistance claims (solokeys-comm-1). No documented crush resistance or regulated-environment certification exists.

            • [community] Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…
            • [community] I'm still curious how the key is tamper resistent when filling it with transparent epoxy... it should be fairly easy to remove the epoxy and…

          Connectors

          1. power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

            weight 2 · round drawn
            YubiKeynone0/10

            The evidence pack contains no documentation or community confirmation of specific YubiKey form factors (USB-C, USB-A, keychain, nano) — only general docs about protocols/SDKs and community comments about size/bulkiness in vague terms (e.g., yubikey-comm-9 says 'more compact and less bulky' without specifics). Missing for 10: explicit product-line documentation of USB-A/USB-C variants, nano/keychain form factors, and any independent confirmation of the lineup breadth.

              SoloKeys Solo 2none0/10

              Evidence shows Solo 2 exists as a security key with NFC variant and generic USB port compatibility, and community comments mention a 'reversible USB-A'/'reversible usb plug', but there is no evidence of a broader lineup with distinct USB-C vs USB-A SKUs or keychain vs low-profile nano form factors — only a single case/color accessory line is mentioned.

              • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
              • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
              • [community] "Reversible USB-A" now there's a feature I wish we'd see more often!
              • [community] Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…
              • [claimed-docs] Pack of colored cases for Solo 2

            Nfc

            1. power userTap the key on my phone over NFC to authenticate in mobile browsers and apps

              weight 2 · round to SoloKeys Solo 2
              YubiKeypartialclaimed6/10

              Yubico's own SDK docs confirm NFC support for both Android (yubikit-android supports USB and NFC-enabled YubiKeys) and iOS (yubikit-ios provides NFC OTP requests), and YubiKey's core FIDO2/WebAuthn/passkey stack (docs-27, docs-14, docs-16) is the basis for authenticating in mobile browsers/apps, but the evidence is SDK/developer-facing rather than an end-user confirmation that a stock mobile browser/app tap-to-auth flow just works. missing for 10: an explicit first-party or hands-on claim that end-users can tap NFC on a phone in a mobile browser (not just app SDK) to authenticate, and independent/community corroboration of real-world NFC mobile browser use.

              • [claimed-docs] YubiKit is an Android library provided by Yubico to enable YubiKey support in Android apps. Both USB and NFC-enabled YubiKeys are supported.
              • [claimed-docs] The library supports NFC-enabled YubiKeys and provides the APIs to request an OTP (Yubico OTP or HOTP) from the NFC YubiKeys using a NFC-ena…
              • [claimed-docs] YubiKey — strongest hardware-backed passkey
              • [claimed-docs] Passkeys are the long awaited replacement for passwords.
              • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
              SoloKeys Solo 2fullclaimed7/10

              SoloKeys explicitly markets NFC tap-to-authenticate for compatible Android and iOS devices as a feature of Solo 2, supporting WebAuthn/passkeys which work across mobile browsers/apps. Missing for 10: no independent hands-on confirmation of NFC mobile browser/app compatibility, and community discussion focuses on other aspects (tamper resistance, OpenPGP) rather than validating NFC mobile use.

              • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
              • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
              • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.

            Openness — open source, data portability, and self-hosting storiesOpenness

            Open source, data portability, and self-hosting stories

            1. ai-native userDo everything through the API that I can do in the UI

              weight 2 · round to YubiKey
              YubiKeypartialprobed6/10

              Yubico's ykman CLI is documented as functionally interchangeable with the Yubico Authenticator GUI for core device configuration (enabling applications, PINs, PIV/OATH/OTP slots, firmware info), and the YubiEnterprise REST API covers fleet-management tasks that would otherwise be done via console UI, giving real API/CLI parity for administrative workflows. However there's no evidence of a unified, fully-documented API surface covering every consumer-facing UI action (e.g., newer Authenticator app credential-management screens), and no llms.txt/MCP endpoint exists for agent discovery of these surfaces. Missing for 10: comprehensive mapping of every UI feature to an API/CLI equivalent, and agent-discoverable API documentation (llms.txt/MCP/OpenAPI all return 404).

              • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
              • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
              • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
              • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
              • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
              SoloKeys Solo 2none0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              • ai-native userExport all of my data in open formats and leave

                weight 3 · round drawn
                YubiKeynone0/10

                YubiKey's core design explicitly prevents exporting the data it stores — private keys are generated on-device and 'cannot be exported or extracted' (yubikey-docs-23), and SSH/FIDO2 docs stress private keys 'never leave the hardware' (yubikey-docs-5). There is no vendor or community evidence of any open-format bulk data export/portability path; the product's security model is fundamentally opposed to this story.

                • [claimed-docs] you can generate the private key directly on the hardware, where it cannot be exported or extracted
                • [claimed-docs] FIDO2 security keys, such as the YubiKey, strengthen SSH security by ensuring your private SSH keys never leave the hardware security key.
                • [claimed-docs] the shared secrets are stored and processed in the YubiKey's secure element
                SoloKeys Solo 2none0/10

                The evidence pack shows Solo 2 supports open standards (WebAuthn, OATH, PIV, OpenPGP) and lets users customize/replace the attestation key or wipe the device, but there is no documentation of any way to export stored credentials/private key material in open formats to migrate elsewhere — by design, FIDO2/PIV/OpenPGP keys generated on-device are non-extractable. missing for 10: any documented data-export/migration path, evidence of extractable key material, or open-format backup/portability tooling.

                • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
                • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
              • ai-native userRead the product's source under an open license

                weight 2 · round to SoloKeys Solo 2
                YubiKeynone0/10

                YubiKey is closed hardware/firmware — community evidence explicitly notes it is 'a proprietary smartcard' and that Yubico 'does not permit firmware flashing,' with no vendor claim or evidence of the core product's source being published under an open license. Some client SDKs/CLIs (python-fido2, ykman) are open-source, but that is tooling around the product, not the product's own source.

                • [community] A Yubikey is just a proprietary smartcard with a bunch of apps installed and some HID emulation (pretending to be a keyboard, which you like…
                • [community] Yubico hardware [is] more compact and less bulky than anything else out there... Yubico software [has an] extensive featureset with more con…
                • [community] YubiKey Firmware is Not Upgradable... So, Yubico is providing free replacements, right? I have a handful of these Yubikeys…
                SoloKeys Solo 2fullcommunity8/10

                The firmware source is hosted openly on GitHub (solokeys/solo2), with build instructions, hackable firmware flashing, and even a dedicated 'Hacker' key edition explicitly for reading/modifying source and firmware end-to-end. Community confirms firmware is open source (though hardware/chip is not), corroborating the licensing model. Missing for 10: no explicit license file/name cited, and no independent audit of license terms beyond community mention that firmware (not hardware) is open.

                • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
                • [github] On a **Hacker** key you can build and flash your own firmware.
                • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
                • [community] This is an LPC55S69. So it's open source firmware, not open source hardware.
              • ai-native userSelf-host the core product

                weight 3 · round to SoloKeys Solo 2
                YubiKeynone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  SoloKeys Solo 2partialprobed5/10

                  The Solo 2 'Hacker' edition ships with fully open-source firmware that users can build, flash, and customize themselves (own attestation keys, own firmware, full toolchain via Rust/cargo), which is the closest analogue to 'self-hosting' for a hardware security key — no cloud dependency by design. However, runtime evidence shows the surrounding tooling has bit-rotted (solo-python CLI fails on current fido2 libs) and no firmware release has shipped in 4 years, undermining confidence that self-building/self-hosting the core product is currently practical. Missing for 10: a working, up-to-date official build/flash pipeline, and independent confirmation that a user can successfully self-build current firmware today.

                  • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
                  • [github] On a **Hacker** key you can build and flash your own firmware.
                  • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
                  • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
                  • [claimed-docs] rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
                  • [claimed-docs] cargo build --release --features board-lpcxpresso55,develop
                  • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

                Privacy posture — data-handling and privacy storiesPrivacy posture

                Data-handling and privacy stories

                1. ai-native userControl data retention and deletion

                  weight 2 · round to SoloKeys Solo 2
                  YubiKeynone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    SoloKeys Solo 2partialclaimed4/10

                    Evidence shows credentials are stored only on-device rather than in a vendor cloud (solokeys-docs-2), and a device wipe is possible via the third-party `fido2-token -R` command (solokeys-docs-10), giving users some control over deletion. However, this is not a first-party, documented retention/deletion feature — it's a generic FIDO2 tool tip buried in a GitHub releases page, with no official SoloKeys documentation on data retention policy or granular per-credential deletion. Missing for 10: native SoloKeys CLI/tool for credential management and wipe, official retention policy documentation, and independent confirmation the wipe command works reliably.

                    • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                    • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                  • ai-native userOpt out of telemetry and usage tracking

                    weight 2 · round to SoloKeys Solo 2
                    YubiKeynone0/10

                    The evidence pack covers YubiKey's hardware authentication, SDKs, and CLI tooling, but contains no mention of telemetry collection or any opt-out/privacy-control setting for Yubico software (ykman, Yubico Authenticator, or the YubiEnterprise console). Since companion software and cloud services could plausibly include telemetry, the axis applies, but there's no evidence of a telemetry opt-out feature.

                      SoloKeys Solo 2partialclaimed3/10

                      Solo 2 is explicitly marketed as working entirely locally ('stays on your key, not their cloud', no software/drivers required), which implies no cloud usage-tracking to opt out of, but there is no explicit telemetry policy, settings, or opt-out control documented for the CLI/companion tooling. missing for 10: explicit telemetry/privacy policy statement, any opt-out toggle or setting, confirmation that the solo2 CLI/companion app sends no usage analytics.

                      • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                      • [claimed-docs] No more sticky notes. No more forgotten passwords. No more texts with six digit codes.
                      • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.

                    Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage

                    FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

                    Credential management

                    1. power userList and delete the passkeys stored on my key and know its credential capacity before it fills up

                      weight 2 · round to YubiKey
                      YubiKeypartialprobed4/10

                      Yubico's ykman CLI/GUI (docs-4, probe-rt-1) provides broad scriptable device management (PIV/OATH/OTP slots, PINs, device info) and firmware/version info tools (docs-15/25), suggesting some credential-management capability exists, but no evidence explicitly confirms listing/deleting FIDO2 passkey credentials or showing passkey storage capacity/limits. Community threads discuss losing track of which accounts a key is enrolled in (yubikey-comm-7) rather than a management UI. Missing for 10: explicit documentation of a 'list/delete FIDO2 credentials' command, and disclosure of the discrete passkey slot capacity/limit warning.

                      • [claimed-docs] Configure your YubiKey via the command line.
                      • [probe] PROBE runtime (recorded 2026-09-15): Yubico's official ykman CLI installs keylessly from public registries and identifies itself — `uvx --fr…
                      • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                      • [community] I have redundant keys for backup access. But I have no idea which accounts I used the lost key for, in order to log into them one by one to …
                      SoloKeys Solo 2none0/10

                      No evidence describes per-passkey listing, deletion, or credential-capacity reporting; the only related CLI ops shown are `solo2 list` (lists connected devices, not credentials) and `fido2-token -R` (wipes the entire key, not selective deletion). Additionally, a runtime probe shows the official CLI is now broken (ImportError against modern fido2 libs), further undermining any credential-management workflow.

                      • [github] solo2 list # list connected devices (alias: solo2 ls)
                      • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

                    Fido2

                    1. security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

                      weight 3 · round to YubiKey
                      YubiKeyfullcommunity8/10

                      YubiKey firmware 5+ and CTAP2 support discoverable/resident credentials for passwordless, usernameless passkey sign-in, backed by Yubico's own passkey docs, WebAuthn docs, python-fido2/java-webauthn-server SDKs, and marketing explicitly calling it 'strongest hardware-backed passkey', plus community confirmation of FIDO2/WebAuthn support alongside other smartcard apps. Missing for 10: no independent hands-on test specifically confirming resident-key/discoverable-credential storage limits or usernameless login flow success in the wild.

                      • [claimed-docs] YubiKey 5.8 is here — hardware signing, CTAP 2.3, and smoother passkey UX.
                      • [claimed-docs] Passkeys are the long awaited replacement for passwords.
                      • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                      • [claimed-docs] this guide will provide all the necessary technical knowledge required to adopt passkeys into your application
                      • [claimed-docs] YubiKey — strongest hardware-backed passkey
                      • [claimed-docs] Provides library functionality for communicating with a FIDO device over USB as well as verifying attestation and assertion signatures.
                      • [claimed-docs] Provides implementations of the Relying Party operations required for a server to support Web Authentication, including passkey authenticati…
                      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
                      SoloKeys Solo 2fullclaimed7/10

                      Solo 2 is marketed explicitly as a passkey/WebAuthn security key that stores credentials on-device rather than in a cloud, and general FIDO2 passkey support inherently implies discoverable/resident credentials for usernameless sign-in ([solokeys-docs-2], [solokeys-docs-9], [solokeys-gh-1]). Missing for 10: explicit documentation of resident-key storage limits/technical FIDO2 conformance details, and independent hands-on confirmation of a usernameless login flow (only marketing copy corroborates this).

                      • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                      • [claimed-docs] No more sticky notes. No more forgotten passwords. No more texts with six digit codes.
                      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                    2. power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

                      weight 2 · round to YubiKey
                      YubiKeyfullcommunity8/10

                      YubiKey's core product design centers on FIDO2/WebAuthn and U2F as documented protocols, and community evidence corroborates that these keys function as WebAuthn/FIDO2 authenticators and PIV/GPG smartcards in real-world use across services. The docs describe passkey/WebAuthn support generically rather than confirming each specific service, but WebAuthn is a standard so this is a reasonable cross-service claim; independent community posts (yubikey-comm-14, yubikey-comm-16) reinforce broad protocol compatibility in practice. missing for 10: explicit named confirmation/citations for Google, GitHub, Microsoft, and specific password manager integrations rather than generic standard-protocol docs.

                      • [claimed-docs] the WebAuthn API enables servers to register and authenticate users using public key cryptography instead of a password
                      • [claimed-docs] Passkeys are the long awaited replacement for passwords.
                      • [claimed-docs] YubiKey — strongest hardware-backed passkey
                      • [community] So far, Yubikeys are the only ones I've found that support both FIDO2/WebAuthn as well as GPG smart card functionality for use with pass(1).…
                      • [community] Also, yubikey works as a PIV smartcard.
                      • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
                      SoloKeys Solo 2partialprobed6/10

                      Solo 2 is a standard WebAuthn/FIDO2/U2F device that would work with any relying party supporting those standards (Google, GitHub, Microsoft, many password managers), and vendor docs confirm FIDO2/passkey and U2F-style support plus broad protocol coverage (OATH, PIV, OpenPGP). However there is no explicit first-party or independent testing evidence confirming compatibility with each named service, and a runtime probe shows the companion CLI tooling has bit-rotted with no firmware update in 4 years, raising doubts about ongoing maintenance/compatibility. Missing for 10: explicit per-service (Google/GitHub/Microsoft/password manager) compatibility confirmation, independent hands-on verification across these services, and evidence of active firmware maintenance to keep pace with protocol changes.

                      • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                      • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
                      • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…

                    User verification

                    1. security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

                      weight 2 · round to YubiKey
                      YubiKeyfullcommunity8/10

                      Docs explicitly confirm FIDO2 supports optional PIN-based user verification in addition to touch/presence (yubikey-docs-6), and community evidence corroborates PIN enrollment is a real, if sometimes overlooked, setup step (yubikey-comm-13). This directly matches on-device verification (PIN) preventing a stolen key alone from authenticating; biometric variants exist on Bio series keys but aren't explicitly documented here. Missing for 10: explicit mention of built-in biometric/fingerprint verification and independent hands-on confirmation of PIN enforcement blocking a stolen key.

                      • [claimed-docs] FIDO2 also requires user presence (a touch on your YubiKey) for cryptographic operations, and can optionally enforce user verification (PIN …
                      • [community] This part can be frustrating for a novice adopting security keys. The key works out of the box without PIN. If you didn't come across the ri…
                      SoloKeys Solo 2none0/10

                      Evidence only shows a capacitive touch sensor for user presence confirmation (solokeys-docs-1), which is a presence test, not FIDO2 user verification via PIN or biometric. No documentation or community evidence mentions a settable FIDO2 PIN or biometric sensor on Solo 2, so the specific 'stolen key alone cannot authenticate' verification story is unevidenced.

                      • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
                      • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                      • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.

                    Not comparable on these axes

                    1. ai-native userPlug MCP servers into this product so it can use their tools

                      weight 3 · not comparable
                      YubiKeyn/a

                      YubiKey is a hardware authentication device; plugging MCP servers into it so it can use their tools is a category error—it has no agentic runtime to consume tools. Evidence confirms no MCP endpoint exists, but that's incidental since the axis doesn't apply to this product type.

                      • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
                      SoloKeys Solo 2n/a

                      Solo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator), not an AI agent or platform with tool-use capability; MCP server integration is not a fair axis for this product category.

                      • ai-native userConnect an agent via an official MCP server

                        weight 3 · not comparable
                        YubiKeyn/a

                        YubiKey is a hardware authentication device, not an agent or platform serving tools to AI agents; connecting agents via MCP servers is a category mismatch for this product type.

                          SoloKeys Solo 2n/a

                          SoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/OATH/PIV/OpenPGP authenticator); it has no product role as an agent tool server and no evidence of an MCP server offering. Connecting AI agents via MCP is outside this product's category.

                          • ai-native userIssue scoped/least-privilege API credentials for an agent

                            weight 2 · not comparable
                            YubiKeyn/a

                            YubiKey is a hardware authentication device for human-presence-based MFA/passkeys/PIV/SSH — it authenticates a person via touch, PIN, or physical possession. It has no concept of issuing scoped, least-privilege API credentials to an autonomous agent (a distinct IAM/OAuth-style capability); its APIs (ykman, YubiEnterprise fleet API, python-fido2) manage the physical device itself, not agent-scoped credentials. This is a category mismatch, not a missing feature.

                              SoloKeys Solo 2n/a

                              SoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator); it has no concept of API credentials or agent-scoped access tokens, which is entirely outside its product category.

                              • ai-native userSubscribe to events via webhooks

                                weight 2 · not comparable
                                YubiKeyn/a

                                YubiKey is a hardware authentication device/SDK ecosystem, not an event-driven platform; there is no concept of subscribable events or webhooks applicable to its product category — this is a category error, not a missing feature.

                                  SoloKeys Solo 2n/a

                                  Solo 2 is a hardware security key (USB/NFC FIDO2 device); webhooks/event subscriptions are not a fair capability for this product category, which has no server-side or event-driven architecture.

                                  • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                    weight 2 · not comparable
                                    YubiKeyn/a

                                    YubiKey is a hardware authentication device (security key); it has no data surface, dashboard, or analytics function to generate AI insights from. This axis is a category error for a hardware security key product.

                                      SoloKeys Solo 2n/a

                                      SoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OATH/PIV/OpenPGP); it does not process or store user data in a way that would support AI-generated insights or suggestions. This axis is a category error for an authentication hardware token.

                                      • ai-native userSet up automations that run autonomously in the background

                                        weight 2 · not comparable
                                        YubiKeyn/a

                                        YubiKey is a hardware authentication device; it requires physical touch/presence for its security model and cannot run autonomous background automations — this is a category error, not a missing feature.

                                          SoloKeys Solo 2n/a

                                          SoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OTP); it has no automation/workflow-orchestration capability and the concept of 'background autonomous automations' does not apply to a physical security token requiring touch confirmation.

                                          • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                            weight 3 · not comparable
                                            YubiKeyn/a

                                            YubiKey is a hardware authentication device; it has no AI assistant of any kind, built-in or otherwise. This story is a category error for this product type.

                                              SoloKeys Solo 2n/a

                                              SoloKeys Solo 2 is a hardware security key for FIDO2/WebAuthn authentication, not an AI assistant or agentic platform; delegating tasks to a built-in AI assistant is a category error for this product type.

                                              • ai-native userOperate the product with natural-language commands

                                                weight 2 · not comparable
                                                YubiKeyn/a

                                                YubiKey is a hardware authentication device operated via physical touch, PIN entry, and traditional CLI tools (ykman) for configuration — there is no natural-language command interface, and the product category (a cryptographic hardware token) does not involve conversational or agentic control surfaces. This axis is a category error for a hardware key rather than an unmet capability.

                                                  SoloKeys Solo 2n/a

                                                  Solo 2 is a hardware security key/authenticator; operating it is inherently physical (touch sensor, insert USB, tap NFC) or via CLI commands, not natural-language interaction. This is a category error—natural-language operation is not a fair axis for a hardware auth token.

                                                  • ai-native userExplore an interactive API reference with runnable examples

                                                    weight 2 · not comparable
                                                    YubiKeynone0/10

                                                    Evidence shows YubiKey's developer docs are static HTML references (SDK guides, protocol explanations) rather than an interactive, runnable API console; explicit probes for OpenAPI/Swagger specs return 404 and no llms.txt/MCP endpoint exists. The only REST API surface found (YubiEnterprise apidocs) is confirmed live but with no evidence of runnable/try-it-out examples.

                                                    • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
                                                    • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                                                    • [probe] PROBE runtime negative (recorded 2026-09-15): Yubico publishes no llms.txt on any host — https://docs.yubico.com/llms.txt answers HTTP 404 (…
                                                    SoloKeys Solo 2n/a

                                                    SoloKeys Solo 2 is a hardware security key with a CLI/firmware toolchain, not an API/SaaS product; there is no API surface for which an interactive reference with runnable examples would be a meaningful offering. The probes confirm no OpenAPI/API docs exist, but this reflects the product category, not a missing capability.

                                                    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
                                                    • [github] solo2 list # list connected devices (alias: solo2 ls)
                                                  • ai-native userTest against a sandbox environment without touching production data

                                                    weight 1 · not comparable
                                                    YubiKeyn/a

                                                    YubiKey is a hardware authentication device; the notion of a sandbox environment to test against without touching production data is not a meaningful axis for this product category — it's a physical security key, not a service with test/production data separation.

                                                      SoloKeys Solo 2n/a

                                                      SoloKeys Solo 2 is a physical hardware security key; the concept of a 'sandbox environment vs production data' for AI-native testing does not apply to this product category.

                                                      • ai-native userRely on versioned APIs with a documented deprecation policy

                                                        weight 2 · not comparable
                                                        YubiKeynone0/10

                                                        YubiKey ships multiple SDKs and a REST API (YubiEnterprise) plus CLI tools, so the axis of API stability/versioning is applicable, but nothing in the evidence pack documents a versioning scheme or deprecation policy for any of these surfaces — firmware version references (yubikey-docs-15/25) concern hardware firmware, not API contracts, and probes found no OpenAPI spec or changelog.

                                                        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator ... or ykman
                                                        • [claimed-docs] The quickest and most convenient way to determine your device's firmware version is to use either the Yubico Authenticator with its intuitiv…
                                                        • [probe] PROBE runtime (recorded 2026-09-15): the YubiEnterprise 'YubiKey as a Service' REST API documentation is live and public at console.yubico.c…
                                                        • [probe] PROBE openapi: all candidate paths 404 (https://docs.yubico.com/openapi.json, https://docs.yubico.com/swagger.json, https://docs.yubico.com/…
                                                        SoloKeys Solo 2n/a

                                                        SoloKeys Solo 2 is a hardware security key that implements standard protocols (FIDO2/WebAuthn, OATH, PIV, OpenPGP); it is not an API-driven service or SDK for which a versioned API deprecation policy would be a meaningful axis. This story is a category error for this product type.

                                                        • ai-native userDefine rules that trigger actions automatically on events

                                                          weight 3 · not comparable
                                                          YubiKeyn/a

                                                          YubiKey is a hardware authentication/security key (FIDO2, PIV, OpenPGP, OTP) — it has no event-driven rules engine or automation-trigger capability, and defining automated action rules is outside its product category as an authenticator rather than an automation platform.

                                                            SoloKeys Solo 2n/a

                                                            Solo 2 is a hardware security key (FIDO2/passkey/OATH/PIV authenticator); it has no rules/automation engine or event-trigger system, and this axis is a category error for an authentication hardware token.

                                                            • ai-native userSchedule recurring jobs or workflows

                                                              weight 2 · not comparable
                                                              YubiKeyn/a

                                                              YubiKey is a hardware authentication device; scheduling recurring jobs/workflows is a software automation/orchestration capability entirely outside a security key's product category — this is a wrong-axis question, not a missing feature.

                                                                SoloKeys Solo 2n/a

                                                                SoloKeys Solo 2 is a hardware security key for authentication; scheduling recurring jobs/workflows is not a capability that applies to this product category.

                                                                • ai-native userVersion, review, and roll back my automations

                                                                  weight 1 · not comparable
                                                                  YubiKeyn/a

                                                                  YubiKey is a hardware authentication device; it has no concept of automations to version, review, or roll back. This story applies to workflow/automation platforms, not a security key product.

                                                                    SoloKeys Solo 2n/a

                                                                    SoloKeys Solo 2 is a hardware security key/authenticator; 'automations' with version/review/rollback is not a concept applicable to this product category.

                                                                    • ai-native userChoose where my data is stored (region/residency)

                                                                      weight 2 · not comparable
                                                                      YubiKeyn/a

                                                                      YubiKey is a hardware authentication device/token, not a data storage or cloud service; data residency/region selection is not a relevant axis for this product category (the evidence pack shows no user data storage service at all, aside from a minor enterprise device-inventory API unrelated to region choice).

                                                                        SoloKeys Solo 2n/a

                                                                        Solo 2 is a local hardware security key whose keys never leave the device ('stays on your key, not their cloud') — there is no cloud data storage or region selection concept applicable to this product category.

                                                                        • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                                                                      • ai-native userPrevent my data from being used to train AI models

                                                                        weight 3 · not comparable
                                                                        YubiKeyn/a

                                                                        YubiKey is a hardware authentication device; it has no role in AI model training data pipelines or data-usage opt-out controls, so preventing personal data from being used to train AI models is a category error for this product.

                                                                          SoloKeys Solo 2n/a

                                                                          Solo 2 is a hardware security key (FIDO2/passkey/OATH/PIV/OpenPGP authenticator); it has no relationship to AI model training data or consent controls over such use. This story is a category error for this product type.