How SoloKeys Solo 2’s scores are calculated
The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.
verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10
PA Score6/100
Agent-ready 1.6 × 0.30 = 0.48
API quality 0.0 × 0.20 = 0.00
Openness 25.0 × 0.20 = 5.00
Built-in AI n/a — excluded, its ×0.15 weight renormalized away
Automation 0.0 × 0.15 = 0.00
(0.48 + 0.00 + 5.00 + 0.00) ÷ (0.30 + 0.20 + 0.20 + 0.15) = 5.48 ÷ 0.85 = 6.4 — weights renormalized over the scored components
Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.
Agent-ready1.6/100×0.30 of the PA blend
Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.
Point an agent at llms.txt or agent-oriented docsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://docs.solokeys.dev/llms.txt“PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] https://docs.solokeys.dev/.md“PROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md”
- [probe] https://docs.solokeys.dev/openapi.json“PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)”
- [probe] https://solokeys.com/llms.txt“PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).”
Run the product headlessly / in CI for automationweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [claimed-docs] https://solokeys.com/“When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [github] https://github.com/solokeys/solo2“solo2 list # list connected devices (alias: solo2 ls)”
- [probe] https://github.com/solokeys/solo1-cli“PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.”
Plug MCP servers into this product so it can use their toolsweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Connect an agent via an official MCP serverweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Use an official CLIweight 2
2 (weight) × 3 (quality) × 0.3 (disputed) = 1.8 of 20 max
- [github] https://github.com/solokeys/solo2“solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] https://github.com/solokeys/solo2“solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] https://docs.solokeys.dev/building/“solo monitor <serial-port>”
- [claimed-docs] https://github.com/solokeys/solo2/releases“You can "wipe" a device using `fido2-token -R`”
- [probe] https://github.com/solokeys/solo1-cli“PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.”
Drive the product through a documented public APIweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
- [probe] https://docs.solokeys.dev/openapi.json“PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)”
- [probe] https://docs.solokeys.dev/llms.txt“PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] https://github.com/solokeys/solo1-cli“PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.”
- [probe] https://solokeys.com/llms.txt“PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).”
Issue scoped/least-privilege API credentials for an agentweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Build against official SDKsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [claimed-docs] https://docs.solokeys.dev/building/“To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-started“rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [github] https://github.com/solokeys/solo2“On a **Hacker** key you can build and flash your own firmware.”
- [probe] https://github.com/solokeys/solo1-cli“PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.”
- [probe] https://docs.solokeys.dev/openapi.json“PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)”
Subscribe to events via webhooksweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Agent-ready = 1.8 ÷ 110 × 100 = 1.6
API quality0.0/100×0.20 of the PA blend
The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.
Explore an interactive API reference with runnable examplesweight 2
n/a — not applicable to this product: excluded from numerator and denominator
- [probe] https://docs.solokeys.dev/openapi.json“PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)”
- [github] https://github.com/solokeys/solo2“solo2 list # list connected devices (alias: solo2 ls)”
Download a machine-readable API spec (OpenAPI or equivalent)weight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://docs.solokeys.dev/openapi.json“PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokeys.dev/api/openapi.json, https://docs.solokeys.dev/.well-known/openapi.json)”
- [probe] https://docs.solokeys.dev/llms.txt“PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] https://solokeys.com/llms.txt“PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-generated shopping-agent file for the store (it recommends the shop.app SKILL.md) — NOT product or technical documentation. docs.solokeys.dev has no llms.txt (404).”
Test against a sandbox environment without touching production dataweight 1
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Rely on versioned APIs with a documented deprecation policyweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
API quality = 0.0 ÷ 20 × 100 = 0.0
Openness25.0/100×0.20 of the PA blend
Can you leave, inspect, or self-host — data export, open source, portability.
Do everything through the API that I can do in the UIweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Export all of my data in open formats and leaveweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
- [claimed-docs] https://github.com/solokeys/solo2/releases“You can "wipe" a device using `fido2-token -R`”
- [github] https://github.com/solokeys/solo2“It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] https://docs.solokeys.dev/customization/“If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] https://docs.solokeys.dev/customization/“Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
Read the product's source under an open licenseweight 2
2 (weight) × 8 (quality) × 1.0 (full) = 16.0 of 20 max
- [github] https://github.com/solokeys/solo2“Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end to end.”
- [github] https://github.com/solokeys/solo2“On a **Hacker** key you can build and flash your own firmware.”
- [github] https://github.com/solokeys/solo2“It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] https://docs.solokeys.dev/building/“To build, develop and debug the firmware for the STM32L432.”
- [community] https://news.ycombinator.com/item?id=26118571“This is an LPC55S69. So it's open source firmware, not open source hardware.”
Self-host the core productweight 3
3 (weight) × 5 (quality) × 0.6 (partial) = 9.0 of 30 max
- [github] https://github.com/solokeys/solo2“Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end to end.”
- [github] https://github.com/solokeys/solo2“On a **Hacker** key you can build and flash your own firmware.”
- [claimed-docs] https://docs.solokeys.dev/customization/“If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] https://docs.solokeys.dev/building/“To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-started“rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [claimed-docs] https://hackmd.io/@solokeys/solo2-getting-started“cargo build --release --features board-lpcxpresso55,develop”
- [probe] https://github.com/solokeys/solo1-cli“PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'ImportError: cannot import name CTAP1 from fido2.ctap1' (solo-python 0.1.1 is incompatible with current python-fido2 2.x), and the last tagged Solo 2 firmware release is 2.964.0 from 2022-08-25. Repos still receive dependency/CI commits (Aug 2026), but no firmware release in 4 years.”
Openness = 25.0 ÷ 100 × 100 = 25.0
Built-in AIn/a×0.15 of the PA blend
Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.
Get AI-generated insights and suggestions from my data inside the productweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Set up automations that run autonomously in the backgroundweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Delegate tasks to a built-in AI assistant inside the productweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Operate the product with natural-language commandsweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
every cell n/a — unscored (not zero), excluded from the blend
Automation0.0/100×0.15 of the PA blend
Depth of automation primitives — rules, scheduling, bulk operations, webhooks.
Perform bulk operations across many items at onceweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Define rules that trigger actions automatically on eventsweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Schedule recurring jobs or workflowsweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Version, review, and roll back my automationsweight 1
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Automation = 0.0 ÷ 20 × 100 = 0.0