Skip to content

Rank #5 of 6 in Hardware Security Keys

Feitian FIDO Keys logo

Feitian FIDO Keys

Feitian Technologies · commercial

no public signals

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

0.0/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

0.0/100

Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →

What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

27.0/100

Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →

Building with and managing the key — CLIs, SDKs, attestation

8.0/100

Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →

Where the key works — platforms, browsers, service compatibility catalogs

30.0/100

Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →

Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

34.8/100

Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →

What runs on the device — open-source firmware, update policy, vulnerability response

15.0/100

Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →

Keys at organization scale — bulk provisioning, delivery services, IdP policies

8.0/100

Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →

The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

12.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

13.8/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →

FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

40.2/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1n/auntestednone yet

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10C

The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

Fido2

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage3partial5/10C

The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

Recovery

security engineerEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery3partial5/10C

Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

Cli

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling3partial4/10C

Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

Provisioning

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management3none0/10

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3n/auntestednone yet

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

Setup

power userEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery2partial7/10C

The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

User verification

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2full7/10C

The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

Fido2

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2partial7/10C

My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

Ssh

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2partial6/10C

Tap the key on my phone over NFC to authenticate in mobile browsers and apps

Nfc

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2partial6/10C

The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

Piv

it adminBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2partial6/10C

The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

Otp

power userBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2partial6/10C

The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

Idp

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2partial6/10C

The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

Source

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2partial5/10C

The key works across my operating systems and browsers, with a published compatibility catalog of supported services

Compatibility

power userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat2partial5/10C

List and delete the passkeys stored on my key and know its credential capacity before it fills up

Credential management

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2partial4/10C

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial4/10C

An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

Agent provisioning

ai-native userFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2none0/10

An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

Agent audit

ai-native userDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2none0/10

An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

Delivery

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2none0/10

Official SDKs let me integrate the key into my own desktop and mobile apps

Sdks

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2none0/10

Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

Certifications

it adminForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Keep OpenPGP keys on the device and use them for git commit signing and encrypted email

Openpgp

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

Connectors

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

Updates

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2noneuntestednone yet

Verify device attestation at registration to enforce that only genuine, approved key models are enrolled

Attestation

security engineerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2noneuntestednone yet

Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

Agent approval

ai-native userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat1partial5/10C

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1n/auntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 37 stories with headroom

What would move Feitian FIDO Keys’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDrive the product through a documented public API

    nonemoves agent-readyimpact 45

    Feitian FIDO Keys are hardware authentication devices with no documented public API for programmatic/agentic control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404, and no evidence describes any API surface for AI agents to drive.

  2. Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

    nonemoves PA Scoreimpact 30

    Evidence only shows per-device configuration tools (SK Manager, iePassManager) for individual FIDO/PIV/OTP settings, not organization-wide bulk provisioning, pre-registration workflows, or lifecycle/inventory tracking across a fleet of keys.

  3. Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave

    nonemoves PA Scoreimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  4. Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs

    nonemoves agent-readyimpact 30

    Feitian is a hardware FIDO key vendor with no evidence of an llms.txt or agent-oriented documentation; probes explicitly show 404s for llms.txt, markdown docs, and OpenAPI endpoints.

  5. Agenticness — how well agents can access and operate the productRun the product headlessly / in CI for automation

    nonemoves agent-readyimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  6. Agenticness — how well agents can access and operate the productUse an official CLI

    nonemoves agent-readyimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  7. Agenticness — how well agents can access and operate the productBuild against official SDKs

    nonemoves agent-readyimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  8. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    Feitian's FIDO key documentation covers WebAuthn/FIDO2 standards and setup guides but no OpenAPI/Swagger spec is published; explicit probes for llms.txt, docs-md, and openapi.json all returned 404.

Showing the top 8 of 37 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map9 surfaces · 17 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Business model

hardware-purchase

Hardware purchase across a broad budget catalog — ePass K39 USB-C $28.50, K9B USB-A NFC $38, BioPass K45 biometric $60, biometric PIV models to $71.50.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 15 '26 — no movement recorded yet
Agent-readytracked since Sep 15 '26 — no movement recorded yet

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data