How Token2’s scores are calculated
The full audit trail, recomputed from the verdict data at build time through the same code that produced the leaderboard: verdict × quality × story weight per cell, cells sum to dimension scores, dimensions blend into the PA Score. Every number on the product page is reproducible from this page alone; for why the formula looks like this, see the methodology.
verdict factors: full ×1.0 · partial ×0.6 · disputed ×0.3 · none ×0.0 · n/a excluded from both sides · cell points = weight × quality × factor · cell max = weight × 10
PA Score15/100
Agent-ready 9.8 × 0.30 = 2.94
API quality 0.0 × 0.20 = 0.00
Openness 21.0 × 0.20 = 4.20
Built-in AI n/a — excluded, its ×0.15 weight renormalized away
Automation 36.0 × 0.15 = 5.40
(2.94 + 0.00 + 4.20 + 5.40) ÷ (0.30 + 0.20 + 0.20 + 0.15) = 12.54 ÷ 0.85 = 14.8 — weights renormalized over the scored components
Scores are stored to 1 decimal; the product page’s pills round to whole numbers for display. Each dimension below shows the stories, verdicts, and cited evidence behind its number.
Agent-ready9.8/100×0.30 of the PA blend
Outside-in: can YOUR agent reach and drive this product — API, MCP, CLI, headless runs, agent docs.
Point an agent at llms.txt or agent-oriented docsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
- [probe] https://www.token2.com/site/page/tools-for-fido-security-keys.md“PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md”
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
Run the product headlessly / in CI for automationweight 2
2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max
- [claimed-docs] https://github.com/token2/fido2_bulkenroll_entraid“This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.”
- [github] https://github.com/token2/fido2-manage“SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent”
- [claimed-docs] https://www.token2.com/site/page/tools-for-fido-security-keys“fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It also provides a GUI written in Python/tkinter.”
- [probe] https://github.com/token2/fido2-manage“official CLI documented at https://github.com/token2/fido2-manage”
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
Plug MCP servers into this product so it can use their toolsweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Connect an agent via an official MCP serverweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Use an official CLIweight 2
2 (weight) × 5 (quality) × 0.6 (partial) = 6.0 of 20 max
- [github] https://github.com/token2/fido2-manage“fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management”
- [github] https://github.com/token2/fido2-manage“PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete, enroll”
- [github] https://github.com/token2/fido2-manage“SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent”
- [claimed-docs] https://github.com/token2/fido2_bulkenroll_entraid“This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.”
- [probe] https://github.com/token2/fido2-manage“PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under different platforms' — is live on GitHub (112 stars, pushed 2026-09-11), alongside fido2_bulkenroll_entraid, a PowerShell bulk-enrollment tool for Entra ID. Unusually strong scriptable provisioning for a budget vendor; works against any CTAP2 key.”
- [probe] https://github.com/token2/fido2-manage“official CLI documented at https://github.com/token2/fido2-manage”
Drive the product through a documented public APIweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
- [probe] https://www.token2.com/site/page/tools-for-fido-security-keys.md“PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md”
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
- [github] https://github.com/token2/fido2-manage“Resident credentials (passkeys): list (with user handle), delete, edit metadata”
Issue scoped/least-privilege API credentials for an agentweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Build against official SDKsweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Subscribe to events via webhooksweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Agent-ready = 10.8 ÷ 110 × 100 = 9.8
API quality0.0/100×0.20 of the PA blend
The programmable surface once an agent is there — machine-readable spec, interactive docs, sandbox, versioning discipline.
Explore an interactive API reference with runnable examplesweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
- [probe] https://www.token2.com/site/page/tools-for-fido-security-keys.md“PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md”
Download a machine-readable API spec (OpenAPI or equivalent)weight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
- [probe] https://www.token2.com/site/page/tools-for-fido-security-keys.md“PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md”
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
Test against a sandbox environment without touching production dataweight 1
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Rely on versioned APIs with a documented deprecation policyweight 2
2 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 20 max
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
- [probe] https://www.token2.com/llms.txt“PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt”
- [probe] https://www.token2.com/site/page/tools-for-fido-security-keys.md“PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md”
API quality = 0.0 ÷ 60 × 100 = 0.0
Openness21.0/100×0.20 of the PA blend
Can you leave, inspect, or self-host — data export, open source, portability.
Do everything through the API that I can do in the UIweight 2
2 (weight) × 4 (quality) × 0.6 (partial) = 4.8 of 20 max
- [github] https://github.com/token2/fido2-manage“Resident credentials (passkeys): list (with user handle), delete, edit metadata”
- [github] https://github.com/token2/fido2-manage“PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete, enroll”
- [github] https://github.com/token2/fido2-manage“SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent”
- [claimed-docs] https://www.token2.com/site/page/tools-for-fido-security-keys“It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.”
- [claimed-docs] https://www.token2.com/tools/totp-toolset“Generate and verify TOTP codes entirely in your browser. Algorithm: SHA-1. All computation happens locally — no seed is ever sent to a server.”
- [claimed-docs] https://www.token2.com/tools/fido2-demo“Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.”
- [probe] https://www.token2.com/openapi.json“PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api/openapi.json, https://www.token2.com/.well-known/openapi.json)”
- [probe] https://github.com/token2/fido2-manage“official CLI documented at https://github.com/token2/fido2-manage”
- [probe] https://github.com/token2/fido2-manage“PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under different platforms' — is live on GitHub (112 stars, pushed 2026-09-11), alongside fido2_bulkenroll_entraid, a PowerShell bulk-enrollment tool for Entra ID. Unusually strong scriptable provisioning for a budget vendor; works against any CTAP2 key.”
Export all of my data in open formats and leaveweight 3
3 (weight) × 5 (quality) × 0.6 (partial) = 9.0 of 30 max
- [claimed-docs] https://www.token2.com/tools/totp-toolset“Export the current seed as an Entra ID hardware-token import file (CSV or JSON).”
- [github] https://github.com/token2/fido2-manage“Resident credentials (passkeys): list (with user handle), delete, edit metadata”
- [github] https://github.com/token2/fido2-manage“SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent”
- [claimed-docs] https://www.token2.com/site/page/tools-for-fido-security-keys“This manufacturer-agnostic tool works with any FIDO2.1 device.”
- [probe] https://github.com/token2/fido2-manage“PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under different platforms' — is live on GitHub (112 stars, pushed 2026-09-11), alongside fido2_bulkenroll_entraid, a PowerShell bulk-enrollment tool for Entra ID. Unusually strong scriptable provisioning for a budget vendor; works against any CTAP2 key.”
Read the product's source under an open licenseweight 2
2 (weight) × 6 (quality) × 0.6 (partial) = 7.2 of 20 max
- [claimed-docs] https://www.token2.com/site/page/tools-for-fido-security-keys“Open-source cross-platform desktop companion application for managing FIDO2 security keys.”
- [github] https://github.com/token2/fido2-manage“Resident credentials (passkeys): list (with user handle), delete, edit metadata”
- [github] https://github.com/token2/fido2-manage“fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management”
- [claimed-docs] https://github.com/token2/fido2_bulkenroll_entraid“This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.”
- [probe] https://github.com/token2/fido2-manage“PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under different platforms' — is live on GitHub (112 stars, pushed 2026-09-11), alongside fido2_bulkenroll_entraid, a PowerShell bulk-enrollment tool for Entra ID. Unusually strong scriptable provisioning for a budget vendor; works against any CTAP2 key.”
Self-host the core productweight 3
3 (weight) × 0 (quality) × 0.0 (none) = 0.0 of 30 max
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Openness = 21.0 ÷ 100 × 100 = 21.0
Built-in AIn/a×0.15 of the PA blend
Inside-out: how agentic the product itself is for its users — built-in assistants, autonomous features.
Get AI-generated insights and suggestions from my data inside the productweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Set up automations that run autonomously in the backgroundweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Delegate tasks to a built-in AI assistant inside the productweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Operate the product with natural-language commandsweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
every cell n/a — unscored (not zero), excluded from the blend
Automation36.0/100×0.15 of the PA blend
Depth of automation primitives — rules, scheduling, bulk operations, webhooks.
Perform bulk operations across many items at onceweight 2
2 (weight) × 6 (quality) × 0.6 (partial) = 7.2 of 20 max
- [claimed-docs] https://github.com/token2/fido2_bulkenroll_entraid“This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.”
- [github] https://github.com/token2/fido2-manage“Resident credentials (passkeys): list (with user handle), delete, edit metadata”
- [github] https://github.com/token2/fido2-manage“PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete, enroll”
- [github] https://github.com/token2/fido2-manage“SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent”
- [probe] https://github.com/token2/fido2-manage“PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under different platforms' — is live on GitHub (112 stars, pushed 2026-09-11), alongside fido2_bulkenroll_entraid, a PowerShell bulk-enrollment tool for Entra ID. Unusually strong scriptable provisioning for a budget vendor; works against any CTAP2 key.”
Define rules that trigger actions automatically on eventsweight 3
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Schedule recurring jobs or workflowsweight 2
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Version, review, and roll back my automationsweight 1
n/a — not applicable to this product: excluded from numerator and denominator
no evidence cited — the verdict rests on absence of evidence, re-checked on refresh
Automation = 7.2 ÷ 20 × 100 = 36.0