Rank #1 of 6 in Hardware Security Keys
Access
Try itExperimental
See what an agent can do with YubiKey before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$brew info --json=v2 ykman | grep descrecorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →
Building with and managing the key — CLIs, SDKs, attestation
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where YubiKey stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
~5/10
unlocks → Machine-readable spec · Versioning policy · Full data export
Subscribe to events via webhooks
n/an/a
Build against official SDKs
✓8/10
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
✓7/10
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
✓8/10
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
✓7/10
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
✓9/10
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
✓8/10
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
✓8/10
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
✓9/10
Official SDKs let me integrate the key into my own desktop and mobile apps
✓8/10
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
~5/10
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
~6/10
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
—0/10
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
~6/10
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
—–
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
—–
Tap the key on my phone over NFC to authenticate in mobile browsers and apps
~6/10
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 5/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably Cli | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 3 | full | 9/10 | Tprobed | |
The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username Fido2 | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 3 | full | 8/10 | Xcommunity | |
Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys Provisioning | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 3 | partial | 6/10 | Tprobed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ||
The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost Recovery | security engineer | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 3 | none | 0/10 | ||
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | n/a | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch Ssh | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | full | 9/10 | Xcommunity | |
An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet Agent audit | ai-native user | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | full | 8/10 | Tprobed | |
Official SDKs let me integrate the key into my own desktop and mobile apps Sdks | developer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | full | 8/10 | Tprobed | |
The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn Otp | power user | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | full | 8/10 | Xcommunity | |
The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate User verification | security engineer | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | full | 8/10 | Xcommunity | |
The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers Fido2 | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | full | 8/10 | Xcommunity | |
Verify device attestation at registration to enforce that only genuine, approved key models are enrolled Attestation | security engineer | Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling | 2 | full | 8/10 | Tprobed | |
Keep OpenPGP keys on the device and use them for git commit signing and encrypted email Openpgp | developer | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | full | 7/10 | Xcommunity | |
The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device Piv | it admin | Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido | 2 | full | 7/10 | Xcommunity | |
An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics Delivery | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | partial | 6/10 | Tprobed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Tap the key on my phone over NFC to authenticate in mobile browsers and apps Nfc | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | partial | 6/10 | Cclaimed | |
An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console Agent provisioning | ai-native user | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | partial | 5/10 | Tprobed | |
The key works across my operating systems and browsers, with a published compatibility catalog of supported services Compatibility | power user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 2 | partial | 5/10 | Xcommunity | |
First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts Setup | power user | Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery | 2 | disputed | 4/10 | Dcontradicted | |
List and delete the passkeys stored on my key and know its credential capacity before it fills up Credential management | power user | Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage | 2 | partial | 4/10 | Tprobed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 4/10 | Tprobed | |
The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices Updates | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | disputed | 4/10 | Dcontradicted | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | 0/10 | ||
The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device Source | security engineer | Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness | 2 | none | 0/10 | ||
The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication Idp | it admin | Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management | 2 | none | 0/10 | ||
Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance) Certifications | it admin | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | none | untested | none yet | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors Connectors | power user | Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors | 2 | none | untested | none yet | |
Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions Agent approval | ai-native user | Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat | 1 | partial | 4/10 | Tprobed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 26 stories with headroom
What would move YubiKey’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
nonemoves PA Scoreimpact 30
The evidence pack contains no vendor documentation describing a lockout-recovery strategy (e.g., backup key enrollment guidance, what's recoverable vs.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
YubiKey's core design explicitly prevents exporting the data it stores — private keys are generated on-device and 'cannot be exported or extracted' (yubikey-docs-23), and SSH/FIDO2 docs stress private keys 'never leave the hardware' (yubikey-docs-5).
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
Direct probes confirm no llms.txt or agent-oriented docs exist on any Yubico domain (404s across docs.yubico.com, developers.yubico.com, www.yubico.com), and no MCP endpoint resolves; documentation is human-oriented HTML only.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Evidence shows YubiKey's developer docs are static HTML references (SDK guides, protocol explanations) rather than an interactive, runnable API console; explicit probes for OpenAPI/Swagger specs return 404 and no llms.txt/MCP endpoint exists.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Explicit probes for OpenAPI/Swagger specs at docs.yubico.com and developers.yubico.com all returned 404s, and no llms.txt or machine-readable API spec was found anywhere in Yubico's domains.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
YubiKey ships multiple SDKs and a REST API (YubiEnterprise) plus CLI tools, so the axis of API stability/versioning is applicable, but nothing in the evidence pack documents a versioning scheme or deprecation policy for any of these surfaces — firmware version references (yubikey-docs-15/25) concern hardware firmware, not API contracts, and probes found no OpenAPI spec or changelog.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
partialq5/10moves agent-readyimpact 22.5
Missing: a documented OpenAPI/REST spec for core device operations, and any llms.txt/MCP support for AI-agent consumption.
Showing the top 8 of 26 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map20 surfaces · 26 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
Hacker News13 stories
- Keep OpenPGP keys on the device and use them for git commit signing and encrypted email
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- List and delete the passkeys stored on my key and know its credential capacity before it fills up
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
- The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
Yubikey manager docs12 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Perform bulk operations across many items at once
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- Official SDKs let me integrate the key into my own desktop and mobile apps
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Do everything through the API that I can do in the UI
- List and delete the passkeys stored on my key and know its credential capacity before it fills up
Apidocs docs8 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Perform bulk operations across many items at once
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
- An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
- Do everything through the API that I can do in the UI
Python fido2 docs8 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- Official SDKs let me integrate the key into my own desktop and mobile apps
- Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
Hardware docs6 stories
- An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
- Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
- Do everything through the API that I can do in the UI
- List and delete the passkeys stored on my key and know its credential capacity before it fills up
Ssh docs6 stories
- Run the product headlessly / in CI for automation
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
- First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
- The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
Piv docs5 stories
- Drive the product through a documented public API
- The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
- My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
- Verify device attestation at registration to enforce that only genuine, approved key models are enrolled
- Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
Yubikit ios docs5 stories
- Build against official SDKs
- The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
- Official SDKs let me integrate the key into my own desktop and mobile apps
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
Passkeys docs4 stories
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
Webauthn docs4 stories
- The key works across my operating systems and browsers, with a published compatibility catalog of supported services
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
Yesdk docs4 stories
Yubikit android docs4 stories
docs.yubico.com3 stories
yubico.com3 stories
- Tap the key on my phone over NFC to authenticate in mobile browsers and apps
- The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
- The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
developers.yubico.com2 stories
Java webauthn server docs2 stories
Pgp docs2 stories
Oath docs1 story
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$brew info --json=v2 ykman | grep descreproduced$ brew info --json=v2 ykman | grep desc "desc": "Tool for managing your Yubi[redacted] configuration"
$uvx --from yubikey-manager ykman --versionreproduced$ uvx --from yubi[redacted]-manager ykman --version Yubi[redacted] Manager (ykman) version: 5.9.2
$curl -s -o /dev/null -w "HTTP %{http_code}" https://docs.yubico.com/llms.txtreproduced$ curl -s -o /dev/null -w "HTTP %{http_code}" https://docs.yubico.com/llms.txt
HTTP 404
$curl -sL https://console.yubico.com/apidocs/ | grep -o "<title>...</title>"reproduced$ curl -sL https://console.yubico.com/apidocs/ | grep -o "<title>...</title>" <title>Yubi[redacted] as a Service API Documentation</title>
$curl -s https://pypi.org/pypi/fido2/json | python3 -c "...print(name, version)"reproduced$ curl -s https://pypi.org/pypi/fido2/json | python3 -c "...print(name, version)" fido2 2.2.1
Business model
Hardware purchase (YubiKey 5C NFC $58; Security Key series less); YubiEnterprise Subscription and Delivery for fleet procurement, with a REST API (YubiKey as a Service).
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
