Skip to content

Rank #1 of 6 in Hardware Security Keys

YubiKey logo

YubiKey

Yubico · commercial

1.2k116/yrpypi 10.3k/wk

Try itExperimental

See what an agent can do with YubiKey before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$brew info --json=v2 ykman | grep descrecorded session — replayed, not live
recorded 2026-09-15 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

21.8/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

24.0/100

Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →

What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

77.5/100

Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →

Building with and managing the key — CLIs, SDKs, attestation

83.3/100

Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →

Where the key works — platforms, browsers, service compatibility catalogs

28.0/100

Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →

Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

4.8/100

Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →

What runs on the device — open-source firmware, update policy, vulnerability response

6.0/100

Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →

Keys at organization scale — bulk provisioning, delivery services, IdP policies

26.7/100

Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →

The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

12.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

7.2/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →

FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

67.6/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3partial5/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/a0/10

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1n/auntestednone yet

Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

Cli

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling3full9/10T

The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

Fido2

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage3full8/10X

Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

Provisioning

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management3partial6/10T

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3none0/10

The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

Recovery

security engineerEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery3none0/10

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3n/auntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3noneuntestednone yet

My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

Ssh

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2full9/10X

An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

Agent audit

ai-native userDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2full8/10T

Official SDKs let me integrate the key into my own desktop and mobile apps

Sdks

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2full8/10T

The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

Otp

power userBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2full8/10X

The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

User verification

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2full8/10X

The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

Fido2

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2full8/10X

Verify device attestation at registration to enforce that only genuine, approved key models are enrolled

Attestation

security engineerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2full8/10T

Keep OpenPGP keys on the device and use them for git commit signing and encrypted email

Openpgp

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2full7/10X

The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

Piv

it adminBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2full7/10X

An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

Delivery

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2partial6/10T

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10T

Tap the key on my phone over NFC to authenticate in mobile browsers and apps

Nfc

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2partial6/10C

An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

Agent provisioning

ai-native userFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2partial5/10T

The key works across my operating systems and browsers, with a published compatibility catalog of supported services

Compatibility

power userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat2partial5/10X

First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

Setup

power userEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery2disputed4/10D

List and delete the passkeys stored on my key and know its credential capacity before it fills up

Credential management

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2partial4/10T

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial4/10T

The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

Updates

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2disputed4/10D

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2none0/10

The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

Source

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2none0/10

The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

Idp

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2none0/10

Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

Certifications

it adminForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

Connectors

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

Agent approval

ai-native userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat1partial4/10T

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1n/auntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 26 stories with headroom

What would move YubiKey’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

    nonemoves PA Scoreimpact 30

    The evidence pack contains no vendor documentation describing a lockout-recovery strategy (e.g., backup key enrollment guidance, what's recoverable vs.

  2. Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave

    nonemoves PA Scoreimpact 30

    YubiKey's core design explicitly prevents exporting the data it stores — private keys are generated on-device and 'cannot be exported or extracted' (yubikey-docs-23), and SSH/FIDO2 docs stress private keys 'never leave the hardware' (yubikey-docs-5).

  3. Openness — open source, data portability, and self-hosting storiesSelf-host the core product

    nonemoves PA Scoreimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  4. Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs

    nonemoves agent-readyimpact 30

    Direct probes confirm no llms.txt or agent-oriented docs exist on any Yubico domain (404s across docs.yubico.com, developers.yubico.com, www.yubico.com), and no MCP endpoint resolves; documentation is human-oriented HTML only.

  5. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    Evidence shows YubiKey's developer docs are static HTML references (SDK guides, protocol explanations) rather than an interactive, runnable API console; explicit probes for OpenAPI/Swagger specs return 404 and no llms.txt/MCP endpoint exists.

  6. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    Explicit probes for OpenAPI/Swagger specs at docs.yubico.com and developers.yubico.com all returned 404s, and no llms.txt or machine-readable API spec was found anywhere in Yubico's domains.

  7. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    YubiKey ships multiple SDKs and a REST API (YubiEnterprise) plus CLI tools, so the axis of API stability/versioning is applicable, but nothing in the evidence pack documents a versioning scheme or deprecation policy for any of these surfaces — firmware version references (yubikey-docs-15/25) concern hardware firmware, not API contracts, and probes found no OpenAPI spec or changelog.

  8. Agenticness — how well agents can access and operate the productDrive the product through a documented public API

    partialq5/10moves agent-readyimpact 22.5

    Missing: a documented OpenAPI/REST spec for core device operations, and any llms.txt/MCP support for AI-agent consumption.

Showing the top 8 of 26 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map20 surfaces · 26 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

Hacker News13 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$brew info --json=v2 ykman | grep descreproduced
$ brew info --json=v2 ykman | grep desc
"desc": "Tool for managing your Yubi[redacted] configuration"
$uvx --from yubikey-manager ykman --versionreproduced
$ uvx --from yubi[redacted]-manager ykman --version
Yubi[redacted] Manager (ykman) version: 5.9.2
$curl -s -o /dev/null -w "HTTP %{http_code}" https://docs.yubico.com/llms.txtreproduced
$ curl -s -o /dev/null -w "HTTP %{http_code}" https://docs.yubico.com/llms.txt
HTTP 404
$curl -sL https://console.yubico.com/apidocs/ | grep -o "<title>...</title>"reproduced
$ curl -sL https://console.yubico.com/apidocs/ | grep -o "<title>...</title>"
<title>Yubi[redacted] as a Service API Documentation</title>
$curl -s https://pypi.org/pypi/fido2/json | python3 -c "...print(name, version)"reproduced
$ curl -s https://pypi.org/pypi/fido2/json | python3 -c "...print(name, version)"
fido2 2.2.1

Business model

hardware-purchaseenterprise-subscription

Hardware purchase (YubiKey 5C NFC $58; Security Key series less); YubiEnterprise Subscription and Delivery for fleet procurement, with a REST API (YubiKey as a Service).

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 15 '26 — no movement recorded yet
Agent-readytracked since Sep 15 '26 — no movement recorded yet

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data