Hardware Security Keys — procurement report
ProductArena · rankings as of 2026-09-15 · evidence as of 2026-09-15 · 6 products · 54 judged requirements · 324 judged cells
Methodology: Every product is judged against a shared taxonomy of user stories using cited evidence — hands-on probes > repository code > independent community sources > vendor claims — never opinion. Full writeup: https://ultrametric.ai/productarena/methodology
Leaderboard
| # | Product | PA Score | Coverage score | Applicable cells | Confidence |
|---|---|---|---|---|---|
| 1 | YubiKey | 17.8 | 33.9 | 40/54 | A |
| 2 | Nitrokey | 17.4 | 23.5 | 40/54 | A |
| 3 | Token2 | 14.8 | 20.3 | 40/54 | B |
| 4 | SoloKeys Solo 2 | 6.4 | 16.5 | 38/54 | A |
| 5 | Feitian FIDO Keys | 3.2 | 15.3 | 38/54 | C |
| 6 | Google Titan Security Key | 0.0 | 7.2 | 36/54 | D |
PA Score = agent-readiness blend (see methodology). Coverage score = weighted share of judged requirements met. Confidence = how much of the score rests on tested vs claimed evidence (A–D).
Uncertainty note
The current #1/#2 gap in this arena is not close enough to qualify for the multi-judge uncertainty pass (or the pass has not covered it yet) — no extra caveat applies beyond the per-product confidence grades above.
Buyer checklist (RFP)
The arena's 54 judged user stories as requirements, grouped by theme. Priorities mirror the story weights our scoring uses (3 = must-have, 2 = should-have, 1 = nice-to-have). Interactive version with per-requirement verdicts for the top products: /arena/security-keys/checklist
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
- ai-native userPlug MCP servers into this product so it can use their toolsmust-have
- ai-native userConnect an agent via an official MCP servermust-have
- ai-native userDrive the product through a documented public APImust-have
- ai-native userDelegate tasks to a built-in AI assistant inside the productmust-have
- ai-native userPoint an agent at llms.txt or agent-oriented docsshould-have
- ai-native userRun the product headlessly / in CI for automationshould-have
- ai-native userUse an official CLIshould-have
- ai-native userIssue scoped/least-privilege API credentials for an agentshould-have
- ai-native userBuild against official SDKsshould-have
- ai-native userSubscribe to events via webhooksshould-have
- ai-native userGet AI-generated insights and suggestions from my data inside the productshould-have
- ai-native userSet up automations that run autonomously in the backgroundshould-have
- ai-native userOperate the product with natural-language commandsshould-have
- ai-native userExplore an interactive API reference with runnable examplesshould-have
- ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)should-have
- ai-native userRely on versioned APIs with a documented deprecation policyshould-have
- ai-native userTest against a sandbox environment without touching production datanice-to-have
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
- ai-native userDefine rules that trigger actions automatically on eventsmust-have
- ai-native userPerform bulk operations across many items at onceshould-have
- ai-native userSchedule recurring jobs or workflowsshould-have
- ai-native userVersion, review, and roll back my automationsnice-to-have
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
- developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted emailshould-have
- power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthnshould-have
- it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the deviceshould-have
- developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touchshould-have
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
- developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptablymust-have
- ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleetshould-have
- security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolledshould-have
- developerOfficial SDKs let me integrate the key into my own desktop and mobile appsshould-have
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
- power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported servicesshould-have
- ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actionsnice-to-have
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
- security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lostmust-have
- power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accountsshould-have
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
- security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the deviceshould-have
- security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devicesshould-have
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
- it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keysmust-have
- ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only consoleshould-have
- it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logisticsshould-have
- it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authenticationshould-have
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
- it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)should-have
- power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factorsshould-have
- power userTap the key on my phone over NFC to authenticate in mobile browsers and appsshould-have
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
- ai-native userExport all of my data in open formats and leavemust-have
- ai-native userSelf-host the core productmust-have
- ai-native userDo everything through the API that I can do in the UIshould-have
- ai-native userRead the product's source under an open licenseshould-have
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
- ai-native userPrevent my data from being used to train AI modelsmust-have
- ai-native userChoose where my data is stored (region/residency)should-have
- ai-native userControl data retention and deletionshould-have
- ai-native userOpt out of telemetry and usage trackingshould-have
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
- security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a usernamemust-have
- power userList and delete the passkeys stored on my key and know its credential capacity before it fills upshould-have
- power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managersshould-have
- security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticateshould-have
Appendix: recorded probes
Hands-on probe recordings — transcripts/videos a human can replay, the strongest evidence tier. Watch them at https://ultrametric.ai/productarena/proofs
- Nitrokey
uvx --from pynitrokey nitropy versionterminal · recorded 2026-09-15 · exit 0 - Nitrokey
curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/Nitrokey/nitrokey-3-firmware/releases/latestterminal · recorded 2026-09-15 · exit 0 - Nitrokey
curl -s https://pypi.org/pypi/nitrokey/json | python3 -c "...print(name, version)"terminal · recorded 2026-09-15 · exit 0 - SoloKeys Solo 2
uvx --from solo-python solo versionterminal · recorded 2026-09-15 · exit 0 - SoloKeys Solo 2
curl -s https://solokeys.com/llms.txt | head -3terminal · recorded 2026-09-15 · exit 0 - Token2
curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/token2/fido2-manageterminal · recorded 2026-09-15 · exit 0 - YubiKey
brew info --json=v2 ykman | grep descterminal · recorded 2026-09-15 · exit 0 - YubiKey
uvx --from yubikey-manager ykman --versionterminal · recorded 2026-09-15 · exit 0 - YubiKey
curl -s -o /dev/null -w "HTTP %{http_code}" https://docs.yubico.com/llms.txtterminal · recorded 2026-09-15 · exit 0 - YubiKey
curl -sL https://console.yubico.com/apidocs/ | grep -o "<title>...</title>"terminal · recorded 2026-09-15 · exit 0 - YubiKey
curl -s https://pypi.org/pypi/fido2/json | python3 -c "...print(name, version)"terminal · recorded 2026-09-15 · exit 0
Cite as: ProductArena by Ultrametric Inc, Hardware Security Keys arena, rankings as of 2026-09-15 — https://ultrametric.ai/productarena/arena/security-keys
License: © 2026 Ultrametric Inc. Brief quotation of individual verdicts, scores, or evidence excerpts is permitted with attribution to "ProductArena by Ultrametric Inc (ultrametric.ai/productarena)", as is use of the data to evaluate, contest, or contribute corrections. Bulk copying, redistribution, or use to build competing datasets requires prior written permission (see DATA-LICENSE in the repository).
No liability: rankings, verdicts, and scores are research outputs derived from the cited evidence at a point in time, provided "as is", without warranties. Ultrametric Inc accepts no responsibility for procurement, purchasing, or other decisions made in reliance on them — verify against the cited evidence before acting (https://ultrametric.ai/productarena/terms).