Skip to content

How SoloKeys Solo 2’s scores are calculated

The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.

verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10

PA Score6/100

Agent-ready 1.6 × 0.30 = 0.48

API quality 0.0 × 0.20 = 0.00

Openness 25.0 × 0.20 = 5.00

Built-in AI n/a — excluded, its ×0.15 weight renormalized away

Automation 0.0 × 0.15 = 0.00

(0.48 + 0.00 + 5.00 + 0.00) ÷ (0.30 + 0.20 + 0.20 + 0.15) = 5.48 ÷ 0.85 = 6.4 — weights renormalized over the scored components

Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.

Agent-ready1.6/100×0.30 of the PA blend

Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.

Point an agent at llms.txt or agent-oriented docsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://docs.solokeys.dev/llms.txtPROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
  • [probe] https://docs.solokeys.dev/.mdPROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md
  • [probe] https://docs.solokeys.dev/openapi.jsonPROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)
  • [probe] https://solokeys.com/llms.txtPROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).

Run the product headlessly / in CI for automationweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [claimed-docs] https://solokeys.com/When prompted, touch the capacitive sensor on your Solo 2 to confirm.
  • [github] https://github.com/solokeys/solo2solo2 list # list connected devices (alias: solo2 ls)
  • [probe] https://github.com/solokeys/solo1-cliPROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.

Plug MCP servers into this product so it can use their toolsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Connect an agent via an official MCP serverweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Use an official CLIweight 2

2 (weight) × 3 (quality) × 0.3 (disputed) = 1.8 of 20 max

  • [github] https://github.com/solokeys/solo2solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
  • [github] https://github.com/solokeys/solo2solo2 list # list connected devices (alias: solo2 ls)
  • [claimed-docs] https://docs.solokeys.dev/building/solo monitor <serial-port>
  • [claimed-docs] https://github.com/solokeys/solo2/releasesYou can "wipe" a device using `fido2-token -R`
  • [probe] https://github.com/solokeys/solo1-cliPROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.

Drive the product through a documented public APIweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [probe] https://docs.solokeys.dev/openapi.jsonPROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)
  • [probe] https://docs.solokeys.dev/llms.txtPROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
  • [probe] https://github.com/solokeys/solo1-cliPROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.
  • [probe] https://solokeys.com/llms.txtPROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).

Issue scoped/least-privilege API credentials for an agentweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Build against official SDKsweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [claimed-docs] https://docs.solokeys.dev/building/To build, develop and debug the firmware for the STM32L432.
  • [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-startedrustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
  • [github] https://github.com/solokeys/solo2On a **Hacker** key you can build and flash your own firmware.
  • [probe] https://github.com/solokeys/solo1-cliPROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.
  • [probe] https://docs.solokeys.dev/openapi.jsonPROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)

Subscribe to events via webhooksweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Agent-ready = 1.8 ÷ 110 × 100 = 1.6

API quality0.0/100×0.20 of the PA blend

The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.

Explore an interactive API reference with runnable examplesweight 2

n/a — not applicable to this product: excluded from numerator and denominator

  • [probe] https://docs.solokeys.dev/openapi.jsonPROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)
  • [github] https://github.com/solokeys/solo2solo2 list # list connected devices (alias: solo2 ls)

Download a machine-readable API spec (OpenAPI or equivalent)weight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

  • [probe] https://docs.solokeys.dev/openapi.jsonPROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)
  • [probe] https://docs.solokeys.dev/llms.txtPROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
  • [probe] https://solokeys.com/llms.txtPROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).

Test against a sandbox environment without touching production dataweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Rely on versioned APIs with a documented deprecation policyweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

API quality = 0.0 ÷ 20 × 100 = 0.0

Openness25.0/100×0.20 of the PA blend

Can you leave, inspect, or self-host — data export, open source, portability.

Do everything through the API that I can do in the UIweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Export all of my data in open formats and leaveweight 3

3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max

  • [claimed-docs] https://github.com/solokeys/solo2/releasesYou can "wipe" a device using `fido2-token -R`
  • [github] https://github.com/solokeys/solo2It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
  • [claimed-docs] https://docs.solokeys.dev/customization/If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
  • [claimed-docs] https://docs.solokeys.dev/customization/Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)

Read the product's source under an open licenseweight 2

2 (weight) × 8 (quality) × 1.0 (full) = 16.0 of 20 max

  • [github] https://github.com/solokeys/solo2Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end to end.
  • [github] https://github.com/solokeys/solo2On a **Hacker** key you can build and flash your own firmware.
  • [github] https://github.com/solokeys/solo2It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
  • [claimed-docs] https://docs.solokeys.dev/building/To build, develop and debug the firmware for the STM32L432.
  • [community] https://news.ycombinator.com/item?id=26118571This is an LPC55S69. So it's open source firmware, not open source hardware.

Self-host the core productweight 3

3 (weight) × 5 (quality) × 0.6 (partial) = 9.0 of 30 max

  • [github] https://github.com/solokeys/solo2Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end to end.
  • [github] https://github.com/solokeys/solo2On a **Hacker** key you can build and flash your own firmware.
  • [claimed-docs] https://docs.solokeys.dev/customization/If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
  • [claimed-docs] https://docs.solokeys.dev/building/To build, develop and debug the firmware for the STM32L432.
  • [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-startedrustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
  • [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-startedcargo build --release --features board-lpcxpresso55,develop
  • [probe] https://github.com/solokeys/solo1-cliPROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.

Openness = 25.0 ÷ 100 × 100 = 25.0

Built-in AIn/a×0.15 of the PA blend

Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.

Get AI-generated insights and suggestions from my data inside the productweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Set up automations that run autonomously in the backgroundweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Delegate tasks to a built-in AI assistant inside the productweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Operate the product with natural-language commandsweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

every cell n/a — unscored (not zero), excluded from the blend

Automation0.0/100×0.15 of the PA blend

Depth of automation primitives — rules, scheduling, bulk operations, webhooks.

Perform bulk operations across many items at onceweight 2

2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Define rules that trigger actions automatically on eventsweight 3

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Schedule recurring jobs or workflowsweight 2

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Version, review, and roll back my automationsweight 1

n/a — not applicable to this product: excluded from numerator and denominator

no evidence cited — the verdict rests on absence of evidence, re-checked on refresh

Automation = 0.0 ÷ 20 × 100 = 0.0