Skip to content

Hardware Security Keys Arena

Google Titan Security Key vs Feitian FIDO Keys

Feitian FIDO Keys wins · 415 (17 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round drawn
    Google Titan Security Keynone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Feitian FIDO Keysnone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      • ai-native userUse an official CLI

        weight 2 · round drawn
        Google Titan Security Keynone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          Feitian FIDO Keysnone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          • ai-native userDrive the product through a documented public API

            weight 3 · round drawn
            Google Titan Security Keynone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              Feitian FIDO Keysnone0/10

              Feitian FIDO Keys are hardware authentication devices with no documented public API for programmatic/agentic control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404, and no evidence describes any API surface for AI agents to drive.

              • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
              • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
              • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…
            • ai-native userBuild against official SDKs

              weight 2 · round drawn
              Google Titan Security Keynone0/10

              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Feitian FIDO Keysnone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                Automation depth — how much of the product can run unattendedAutomation depth

                How much of the product can run unattended

                1. ai-native userPerform bulk operations across many items at once

                  weight 2 · round drawn
                  Google Titan Security Keynone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Feitian FIDO Keysnone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido

                    What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

                    Openpgp

                    1. developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email

                      weight 2 · round drawn
                      Google Titan Security Keynone0/10

                      Titan Security Key is a FIDO/U2F authenticator with no documented OpenPGP applet or smartcard support for git commit signing or encrypted email; evidence only covers FIDO2/U2F sign-in use cases.

                      • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                      • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                      Feitian FIDO Keysnone0/10

                      Evidence covers FIDO/U2F, PIV, OTP, and OpenSSH use cases, but there is no mention of OpenPGP key storage, git commit signing, or encrypted email support anywhere in the pack.

                      Otp

                      1. power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

                        weight 2 · round to Feitian FIDO Keys
                        Google Titan Security Keynone0/10

                        Titan Security Key is a FIDO/U2F/WebAuthn hardware authenticator; no evidence indicates it supports TOTP/HOTP seed storage or generic challenge-response slots for legacy OTP services. All documentation focuses on FIDO CTAP1/U2F/WebAuthn use cases only.

                        • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                        • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                        Feitian FIDO Keyspartialclaimed6/10

                        Feitian documents HOTP functionality that emulates HID keyboard to auto-type OTP values, plus an OTP Tool to switch protocols and an SK Manager to manage OTP/PIV/FIDO functions, confirming legacy OTP slot support beyond WebAuthn. However, there's no detail on TOTP support, challenge-response mode, or number of OTP slots available. Missing for 10: TOTP-specific documentation, challenge-response mode details, slot capacity/configuration specifics, and independent hands-on verification.

                        • [claimed-docs] The HOTP function of FEITIAN FIDO Security Key emulates HID Keyboard protocol to enable automatically type the value in.
                        • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.
                        • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.

                      Piv

                      1. it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

                        weight 2 · round to Feitian FIDO Keys
                        Google Titan Security Keynone0/10

                        Evidence only covers FIDO/U2F/FIDO2 authentication (Google Sign-In, CTAP1 sites, Advanced Protection) — no mention of PIV smart card mode, certificate-based login, workstation sign-in via smart card, VPN client certs, or code-signing use cases.

                        • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                        • [claimed-docs] One security key can be used to sign in to work and personal services.
                        • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                        Feitian FIDO Keyspartialclaimed6/10

                        Feitian documents PIV smart card functionality via the SK Manager tool, including macOS PIV smart card logon configuration and general PIV/FIDO/OTP management, supporting workstation sign-in use cases. However, evidence does not explicitly confirm VPN certificate-based authentication or code signing use cases with PIV, nor detail Windows/Active Directory PIV smart card logon specifically. Missing for 10: explicit VPN certificate-auth documentation, code-signing workflow evidence, Windows PIV smart card logon docs, and independent/third-party validation of PIV compliance.

                        • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                        • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.

                      Ssh

                      1. developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

                        weight 2 · round to Feitian FIDO Keys
                        Google Titan Security Keynone0/10

                        The evidence pack covers only FIDO2/U2F use for Google/web sign-in, Bluetooth pairing, NFC, and physical hardware details — there is no mention of sk-ssh, PIV, OpenPGP, or any SSH-key hardware-backing capability. missing for 10: sk-ssh/FIDO2 SSH key support, PIV applet, OpenPGP applet, any developer SSH workflow documentation.

                          Feitian FIDO Keyspartialclaimed6/10

                          Feitian docs explicitly cover FIDO2 sk-ssh usage for OpenSSH/GitHub/Linux server login (feitian-docs-6) and PIV smart-card functionality including macOS PIV logon via SK Manager (feitian-docs-9, feitian-docs-10), supporting hardware-backed SSH auth with physical touch. However, no OpenPGP-based SSH key support is documented anywhere in the pack. Missing for 10: explicit OpenPGP applet/SSH support, independent/hands-on verification of sk-ssh workflow, and unified documentation tying all three methods together.

                          • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                          • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                          • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.

                        Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling

                        Building with and managing the key — CLIs, SDKs, attestation

                        Agent audit

                        1. ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

                          weight 2 · round drawn
                          Google Titan Security Keynone0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                            Feitian FIDO Keysnone0/10

                            There is a SK Manager GUI tool for managing FIDO/PIV/OTP functions, but no evidence of any programmatic API, CLI output, or SDK exposing serial, firmware version, enabled applications, or credential state for automated fleet auditing by an agent; probes for API/docs endpoints all returned 404.

                            • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                            • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                            • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                            • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                          Attestation

                          1. security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled

                            weight 2 · round to Google Titan Security Key
                            Google Titan Security Keydisputedcontradicted3/10

                            Docs claim the key's hardware chip/firmware 'verifies that the keys haven't been tampered with' and provides 'cryptographic proof' of legitimate registration (google-titan-docs-12, docs-14, docs-20), which gestures at attestation, but there is no documentation or tooling aimed at security engineers for inspecting attestation certificates or enforcing an approved-model allowlist at registration. A hands-on report directly undercuts the 'genuine, approved model' framing: a user's non-Google Feitian MultiPass key (identical hardware to Titan) was accepted by Google's own replacement/registration system as if it were an official Titan key, showing the attestation/verification does not reliably distinguish genuine Titan units from rebranded third-party hardware (google-titan-comm-12, comm-14). Missing for 10: security-engineer-facing attestation verification API/metadata service, documented enforcement of approved key models, and any first-party/independent confirmation that model spoofing is prevented.

                            • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                            • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                            • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                            • [community] I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …
                            • [community] I got one of Google's Advanced Protection kits, which included two keys that look exactly like the Titan keys in the article. Both are Feiti…
                            Feitian FIDO Keysnone0/10

                            No evidence in the pack discusses FIDO attestation, AAGUID verification, metadata service (MDS) support, or any mechanism for security engineers to validate genuine Feitian key models at registration; the docs cover general FIDO compatibility, interfaces, and setup guides only.

                            Cli

                            1. developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

                              weight 3 · round to Feitian FIDO Keys
                              Google Titan Security Keynone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                Feitian FIDO Keyspartialclaimed4/10

                                Feitian offers GUI tools (SK Manager, iePassManager, OTP Tool) for managing FIDO/PIV/OTP functions, PINs, and slots, but these are graphical utilities, not documented as scriptable CLIs. No evidence of a command-line interface, scripting API, or automation-friendly tooling for enabling apps, setting PINs, or reading device state. missing for 10: dedicated CLI tool, scripting/automation documentation, examples of headless/scriptable configuration workflows.

                                • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                                • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                                • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.

                              Sdks

                              1. developerOfficial SDKs let me integrate the key into my own desktop and mobile apps

                                weight 2 · round drawn
                                Google Titan Security Keynone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Feitian FIDO Keysnone0/10

                                  Evidence covers WebAuthn/FIDO2 standard support, OS integrations (Windows Hello, Azure AD, OpenSSH), and firmware provisioning via Google's OpenSK repo, but nothing indicates Feitian ships its own official SDK for developers to embed key support into custom desktop/mobile apps. Probe results also confirm no API/docs discoverability artifacts. This is an applicable axis for a hardware key vendor (SDKs are common in this space) but no evidence of one existing.

                                  • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                  • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                  • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                                Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat

                                Where the key works — platforms, browsers, service compatibility catalogs

                                Agent approval

                                1. ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

                                  weight 1 · round to Feitian FIDO Keys
                                  Google Titan Security Keynone0/10

                                  Evidence only shows Titan Security Key being used for standard account sign-in / 2-Step Verification via FIDO/U2F, with no mention of any API, SDK, or workflow that lets an AI agent request a physical-touch approval gate for its own automated actions. Nothing in the docs or community discussion ties the key's touch requirement to agent-initiated or automated action approval.

                                  • [claimed-docs] Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.
                                  • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                  Feitian FIDO Keyspartialclaimed5/10

                                  Feitian keys are standard FIDO2/WebAuthn/U2F hardware tokens that inherently require a physical touch to complete authentication (feitian-docs-1, feitian-docs-4, feitian-docs-18), which is the underlying mechanism that could be wired into an agent's approval flow via WebAuthn. However, there is no evidence of any AI-agent-specific integration, SDK, or documented workflow showing the key used as a human-approval gate for agent-initiated actions. Missing for 10: explicit AI-agent/automation integration examples, documentation of using the key as an approval gate in agentic pipelines, and any third-party corroboration of this use case.

                                  • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                  • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.
                                  • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…

                                Compatibility

                                1. power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services

                                  weight 2 · round to Feitian FIDO Keys
                                  Google Titan Security Keydisputedcontradicted4/10

                                  Google's docs claim broad cross-platform support (Android/iOS NFC, Linux setup via udev, FIDO CTAP1 compatibility with third-party sites) but there is no published catalog of specific supported services/sites—just a generic FIDO-standard compatibility statement. Community reports directly contradict smooth cross-browser/OS support: one user found keys 'only' worked with Chrome and failed on Mac despite official docs, while others reported success with Firefox on Linux and pairing issues on Mac, showing inconsistent real-world compatibility. missing for 10: an actual published list/catalog of compatible services, and confirmation that browser/OS support claims hold up without conflicting user reports.

                                  • [claimed-docs] Works with compatible Android and iOS devices through NFC
                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                  • [claimed-docs] To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.
                                  • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                                  • [community] I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…
                                  • [community] The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.
                                  • [community] I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…
                                  Feitian FIDO Keyspartialclaimed5/10

                                  Feitian documents cross-platform compatibility (Windows, macOS, Linux, Android/iOS) and integration guides for specific platforms (Windows Hello, Azure AD, GitHub/OpenSSH, Google Advanced Protection, PIV/macOS), and multi-interface support (USB/NFC/BLE) which implies broad OS/browser reach. However there is no published, centralized compatibility catalog or matrix listing supported browsers/services, and no independent verification of claims. Missing for 10: a formal published compatibility catalog/matrix of supported services and browsers, independent/hands-on verification of cross-platform claims.

                                  • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                  • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).
                                  • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                                  • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                                  • [claimed-docs] MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.
                                  • [claimed-docs] Recognized as a HID device, no driver is needed for MultiPass FIDO® Security Key to work on Microsoft Windows, macOS and Linux via USB.
                                  • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.

                                Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery

                                Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

                                Recovery

                                1. security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

                                  weight 3 · round to Feitian FIDO Keys
                                  Google Titan Security Keypartialcommunity4/10

                                  Google docs cover removing a lost key from an account (google-titan-docs-9) and enrolling a security key (google-titan-docs-15), and a community comment notes Google's own guidance to keep one key in daily use and store a backup safely (google-titan-comm-3), implying an informal backup-key strategy. However there is no first-party documentation laying out a full lockout-recovery plan (e.g., how to regain account access before removing the key, what happens if the only registered key is lost, or explicit backup-key enrollment steps). missing for 10: explicit vendor doc on account lockout scenarios, dedicated backup-key enrollment walkthrough, and clarity on what is/isn't recoverable if the sole key is lost

                                  • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                  • [community] Is it possible to use the Bluetooth dongle with a desktop computer without a cable? Having to carry both on your keyring kind of defeats the…
                                  • [community] Pretty cool, I like that it comes with two keys at the start so you have a backup, unlike Yubi where I have to buy two before I can even get…
                                  Feitian FIDO Keyspartialclaimed5/10

                                  FAQ entries state that a lost key can be worked around by logging in with a backup security key or another method, then disabling the lost key and provisioning a new one, which is a real but minimal statement of a lockout-recovery strategy (feitian-docs-14, feitian-docs-24). However, there is no dedicated recovery guide explaining what is and isn't recoverable (e.g., per-relying-party re-registration necessity, loss of resident/discoverable credentials, biometric enrollment data) beyond this brief FAQ mention. Missing for 10: a structured recovery/lockout doc, explicit treatment of what is NOT recoverable (credentials tied to lost key), and guidance on enrolling multiple backup keys per service rather than just a generic FAQ answer.

                                  • [claimed-docs] The dedicated users can still logon to the account by using back-up security key or other method.
                                  • [claimed-docs] The dedicated users can still logon to the account by using back-up security key or other method. Then user can disable the lost security ke…

                                Setup

                                1. power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

                                  weight 2 · round to Feitian FIDO Keys
                                  Google Titan Security Keypartialcommunity5/10

                                  Google's support docs give step-by-step guided enrollment (sign in, 'Enroll your security key', device detects it and walks through sign-in) and cover related setup nuances like Linux udev rules and NFC/Bluetooth pairing, but there is no dedicated setup app—just web help pages. Community reports also note friction during first-time use (Chrome-only compatibility issues, Bluetooth key not pairing with Mac), suggesting the guided flow isn't universally smooth across platforms/browsers. Missing for 10: a purpose-built setup wizard/app, cross-browser first-run guidance, and independent confirmation that the documented steps work smoothly on all platforms.

                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                  • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                                  • [claimed-docs] Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.
                                  • [claimed-docs] To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.
                                  • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                                  • [community] I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…
                                  Feitian FIDO Keyspartialclaimed7/10

                                  Feitian provides first-party guided documentation for pairing keys (BLE setup guide), registering with specific platforms (Windows, Azure AD, Microsoft, GitHub/Linux via OpenSSH), and a dedicated SK Manager desktop app for configuring FIDO/PIV/OTP functions, which together resemble a guided enrollment flow for a power user. However, missing for 10: independent/hands-on user reports confirming the setup experience is clear in practice, and no single unified 'wizard' walkthrough spanning consumer-account registration (e.g., Google/Microsoft account UI) rather than platform/OS-level docs.

                                  • [claimed-docs] Learn how to pair your FEITIAN Bluetooth FIDO2 security key to your device.
                                  • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your personal Windows.
                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                                  • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.

                                Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness

                                What runs on the device — open-source firmware, update policy, vulnerability response

                                Source

                                1. security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

                                  weight 2 · round to Feitian FIDO Keys
                                  Google Titan Security Keynone0/10

                                  Google explicitly states firmware is 'developed by Google' and used to verify tamper-resistance, but there is no evidence of open-source firmware or independent third-party audit reports; community evidence only discusses hardware manufacturing (Feitian OEM) and a Bluetooth vulnerability, not firmware transparency/auditing. missing for 10: any published audit report, open-source firmware repository, or independent verification of firmware code.

                                  • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                                  • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                                  • [community] Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…
                                  Feitian FIDO Keyspartialclaimed5/10

                                  Feitian offers a specific OpenSK hardware variant where users can build firmware from Google's open-source OpenSK repo and flash it themselves, directly addressing the transparency concern for that model. However, the flagship BioPass and MultiPass FIDO keys firmware is not documented as open source or independently audited, and no third-party security audit reports are cited anywhere in the pack. missing for 10: independent firmware audit reports for mainstream product lines, confirmation that BioPass and MultiPass firmware not just the niche OpenSK SKU is open or audited, and hands-on verification that shipped OpenSK devices match the public source

                                  • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                  • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…

                                Updates

                                1. security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

                                  weight 2 · round to Google Titan Security Key
                                  Google Titan Security Keypartialcommunity4/10

                                  There is concrete real-world evidence of one incident: a BLE pairing vulnerability was disclosed, Google emailed affected users ('Update on your Titan Security Key') and ran a replacement program rather than a firmware patch, showing some vulnerability-response process exists but it worked through physical device replacement, not an in-field firmware update, and users found the replacement process cumbersome. There is no published advisory list/CVE tracker or affected-model lookup tool in the evidence — docs only vaguely mention Google-engineered firmware for tamper verification. Missing for 10: a public security-advisory/CVE page, a documented affected-model/serial lookup tool, and an actual firmware-update delivery mechanism (evidence shows fixes require full device replacement, not a firmware push).

                                  • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                                  • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                                  • [community] Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…
                                  • [community] Not the most user-friendly replacement process here, Google. First I had to chat with a representative... Now I need to place a 'replacement…
                                  • [community] The replacement site worked by sending me to a contact form where I had to chat with a representative then wait for an email to initiate an …
                                  • [community] I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …
                                  Feitian FIDO Keysnone0/10

                                  No evidence of security advisories, CVE tracking, affected-model lookup tools, or a documented firmware update delivery mechanism; only general product/setup docs and an OpenSK build guide are present, none of which address vulnerability response or patch distribution.

                                  Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management

                                  Keys at organization scale — bulk provisioning, delivery services, IdP policies

                                  Agent provisioning

                                  1. ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

                                    weight 2 · round drawn
                                    Google Titan Security Keynone0/10

                                    This is a hardware security key with human-driven web console setup (enroll, pair, reset) via support docs; there is no evidence of any enterprise API for agent-driven ordering, assignment, or pre-registration of keys. missing for 10: documented provisioning/management API, evidence of programmatic ordering or fleet assignment, any agent/automation-facing endpoint.

                                    • [claimed-docs] Enroll your security key. You might need to sign in.
                                    • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                                    • [claimed-docs] One security key can be used to sign in to work and personal services.
                                    Feitian FIDO Keysnone0/10

                                    No evidence of any enterprise API for provisioning, ordering, or assignment of keys — all documentation is consumer/end-user setup guides, and probes for API/docs endpoints returned 404s.

                                    • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                                    • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                                    • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                                  Delivery

                                  1. it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

                                    weight 2 · round drawn
                                    Google Titan Security Keynone0/10

                                    No evidence of any bulk-shipping logistics, distribution API, admin console, or fleet-provisioning workflow for shipping keys to distributed employees; evidence covers only individual key setup, replacement RMA process, and hardware/community feedback.

                                      Feitian FIDO Keysnone0/10

                                      No evidence of any API, console, or enterprise fulfillment/logistics/shipping-management capability; probes confirm no API/docs exist for this. Evidence covers only device features (FIDO2, biometrics, NFC/BLE/USB) and setup guides, nothing about distributed shipping orchestration.

                                      • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                                      • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                                      • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…

                                    Idp

                                    1. it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

                                      weight 2 · round to Feitian FIDO Keys
                                      Google Titan Security Keynone0/10

                                      The evidence pack covers consumer/personal account setup, Bluetooth pairing, form factors, and hardware attestation, but contains no evidence of IT-admin-facing integration with identity providers like Okta, Entra ID, or Google Workspace admin console policy enforcement for hardware-key-only authentication. This is a fair axis for a hardware security key vendor to address (fleet policy enforcement via IdP), but no such capability or documentation is present.

                                        Feitian FIDO Keyspartialclaimed6/10

                                        Feitian keys are documented as fully W3C WebAuthn/FIDO2-compliant HID devices with explicit setup guides for Azure AD-joined Windows, Microsoft applications, and Google Advanced Protection, which implies interoperability with major identity providers. However, there is no explicit documentation or guide for Okta or Google Workspace integration, nor any mention of admin-side policy enforcement (e.g., requiring hardware-key-only auth) within these IdPs. Missing for 10: Okta-specific integration guide, Google Workspace-specific setup docs, and evidence of IdP admin policy controls enforcing hardware-key requirements.

                                        • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                        • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                                        • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.
                                        • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.
                                        • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).

                                      Provisioning

                                      1. it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

                                        weight 3 · round drawn
                                        Google Titan Security Keynone0/10

                                        Evidence covers individual end-user setup, pairing, resetting, and removing a single key, but nothing addresses IT-admin fleet capabilities like bulk pre-registration, centralized provisioning, or lifecycle/inventory tracking across an organization. Missing for 10: bulk enrollment tools/API, admin console integration for mass key registration, and lifecycle/inventory tracking dashboards.

                                          Feitian FIDO Keysnone0/10

                                          Evidence only shows per-device configuration tools (SK Manager, iePassManager) for individual FIDO/PIV/OTP settings, not organization-wide bulk provisioning, pre-registration workflows, or lifecycle/inventory tracking across a fleet of keys. No admin console, CSV/bulk import, or enterprise deployment tooling is documented.

                                          • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                                          • [claimed-docs] Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.
                                          • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                          • [claimed-docs] Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.

                                        Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors

                                        The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

                                        Certifications

                                        1. it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

                                          weight 2 · round drawn
                                          Google Titan Security Keynone0/10

                                          The evidence pack contains no mention of FIPS 140 validation or Common Criteria certification for Titan Security Keys, nor documented water/crush resistance specs; in fact, one community report suggests the underlying Feitian hardware is fragile if dropped, contradicting any durability certification claim. missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, official durability/water-crush resistance specs.

                                          • [community] The wireless key is the Feitian MultiPass FIDO Security Key. I'd caution people to read the Amazon reviews (specifically people found it unr…
                                          Feitian FIDO Keysnone0/10

                                          The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or durability testing (water/crush resistance) for any Feitian key; all citations focus on protocol compatibility, interfaces, and setup guides. Missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, water/crush resistance durability specs.

                                          Connectors

                                          1. power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

                                            weight 2 · round to Google Titan Security Key
                                            Google Titan Security Keypartialcommunity4/10

                                            Docs confirm two form factors—USB-A/NFC and USB-C/NFC—but there is no evidence of a keychain or nano low-profile model, and community feedback even calls the (Bluetooth) key large rather than low-profile. missing for 10: keychain form factor, nano/low-profile form factor, independent hands-on confirmation of size/portability across the full claimed lineup.

                                            • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                                            • [community] It's so big. Couldn't they have come up with a more subtle form factor?
                                            Feitian FIDO Keysnone0/10

                                            The evidence pack covers interfaces (USB/NFC/BLE), biometric and OpenSK products, but never mentions specific form factors like USB-C vs USB-A connectors, keychain design, or nano/low-profile sizing — no product lineup breakdown by physical form is shown.

                                            Nfc

                                            1. power userTap the key on my phone over NFC to authenticate in mobile browsers and apps

                                              weight 2 · round to Google Titan Security Key
                                              Google Titan Security Keyfullclaimed7/10

                                              Docs confirm the USB-A/NFC and USB-C/NFC key models work over NFC with compatible Android and iOS devices (iOS 13.3+), covering mobile browser/app authentication. Missing for 10: independent hands-on confirmation of NFC tap-to-auth specifically in third-party mobile apps (community evidence focuses mainly on Bluetooth/desktop use, not NFC mobile app flows).

                                              • [claimed-docs] Works with compatible Android and iOS devices through NFC
                                              • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                                              • [claimed-docs] iPhones with iOS version 13.3 or up | Yes | Yes
                                              Feitian FIDO Keyspartialclaimed6/10

                                              MultiPass FIDO Security Key explicitly supports NFC as one of three interfaces and is documented compatible with Android/iOS platforms, implying tap-to-authenticate via NFC on mobile; however, evidence doesn't explicitly confirm NFC (vs BLE) works with specific mobile browsers/apps or provide hands-on confirmation. missing for 10: explicit mobile browser/app NFC tap walkthrough, independent hands-on verification of NFC mobile authentication.

                                              • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.
                                              • [claimed-docs] USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…
                                              • [claimed-docs] MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.

                                            Openness — open source, data portability, and self-hosting storiesOpenness

                                            Open source, data portability, and self-hosting stories

                                            1. ai-native userDo everything through the API that I can do in the UI

                                              weight 2 · round drawn
                                              Google Titan Security Keynone0/10

                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                Feitian FIDO Keysnone0/10

                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                • ai-native userExport all of my data in open formats and leave

                                                  weight 3 · round drawn
                                                  Google Titan Security Keynone0/10

                                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                    Feitian FIDO Keysnone0/10

                                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                    • ai-native userRead the product's source under an open license

                                                      weight 2 · round to Feitian FIDO Keys
                                                      Google Titan Security Keynone0/10

                                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                        Feitian FIDO Keyspartialclaimed4/10

                                                        Feitian ships a specific 'OpenSK' hardware variant that can run firmware built from Google's open-source OpenSK repository, giving some access to readable/open-licensed source for that SKU, but this is a third-party (Google) codebase, not Feitian's own firmware for its mainstream BioPass/MultiPass keys, which remain closed. Missing for 10: evidence that Feitian's own primary product firmware/source is published under an open license, and no indication of a public source repo, license file, or docs-as-markdown/API spec for the broader product line.

                                                        • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                                        • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                                      • ai-native userSelf-host the core product

                                                        weight 3 · round to Feitian FIDO Keys
                                                        Google Titan Security Keynone0/10

                                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                          Feitian FIDO Keyspartialclaimed5/10

                                                          The FIDO key is inherently a local, on-device hardware authenticator (not a hosted service), and Feitian explicitly documents that users can build firmware from Google's open-source OpenSK repository and provision it onto the hardware themselves, giving genuine control over the 'core product' without vendor cloud dependency. This is a reasonable analog to self-hosting for a hardware device, but it's not a full self-hostable software stack with deployment docs, and there's no evidence of self-hosted backend/server components (e.g., FIDO server, attestation service) that would round out a complete self-hosting story. Missing for 10: documentation of self-hosting any server-side/relying-party components, deployment guides beyond firmware flashing, and independent confirmation of OpenSK build success.

                                                          • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                                          • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…

                                                        Privacy posture — data-handling and privacy storiesPrivacy posture

                                                        Data-handling and privacy stories

                                                        1. ai-native userControl data retention and deletion

                                                          weight 2 · round drawn
                                                          Google Titan Security Keynone0/10

                                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                            Feitian FIDO Keysnone0/10

                                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                            • ai-native userOpt out of telemetry and usage tracking

                                                              weight 2 · round drawn
                                                              Google Titan Security Keynone0/10

                                                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                Feitian FIDO Keysnone0/10

                                                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                                                Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage

                                                                FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

                                                                Credential management

                                                                1. power userList and delete the passkeys stored on my key and know its credential capacity before it fills up

                                                                  weight 2 · round to Feitian FIDO Keys
                                                                  Google Titan Security Keynone0/10

                                                                  The evidence covers removing a key from a Google account and unpairing Bluetooth, but there is no mention of an on-key credential management tool that lists or deletes individual passkeys stored on the Titan key itself, nor any documentation of the key's credential storage capacity or warnings about it filling up.

                                                                  • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                                                                  • [claimed-docs] If you want to stop using a Bluetooth Titan Security Key with one or more devices, you can unpair the key.
                                                                  Feitian FIDO Keyspartialclaimed4/10

                                                                  FEITIAN provides tools (SK Manager, iePassManager) described as managing 'FIDO PIN and credential related operations' on the key, implying some list/delete capability, and one product page claims 'no limit to accounts' for the MultiPass key. However, there is no explicit documentation of a list/delete-passkey UI, no discussion of credential capacity limits for other models, and no guidance on capacity awareness before a key fills up. missing for 10: explicit list/delete UI screenshots or steps, documented per-model credential capacity limits, and warnings/behavior when storage is full.

                                                                  • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.
                                                                  • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                                                  • [claimed-docs] There is no limit to the number of accounts registered in MultiPass FIDO® Security Key.

                                                                Fido2

                                                                1. security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

                                                                  weight 3 · round drawn
                                                                  Google Titan Security Keypartialclaimed5/10

                                                                  Docs confirm passkey creation for Google Accounts (implying a discoverable, device-bound credential that lets sign-in without typing a password) via google-titan-docs-2, but the same docs explicitly describe third-party site support only via 'FIDO CTAP1 standards' (google-titan-docs-4), which does not guarantee resident-key/FIDO2 support broadly. No explicit mention of FIDO2/CTAP2 or 'discoverable credentials' terminology anywhere in the pack. Missing for 10: explicit FIDO2/CTAP2 protocol documentation, direct mention of resident/discoverable credentials, and independent verification of username-less sign-in across non-Google WebAuthn services.

                                                                  • [claimed-docs] If you want to sign in with just your security key and skip your password when possible, you must create a passkey.
                                                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                                                  • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                                                                  Feitian FIDO Keyspartialclaimed5/10

                                                                  Feitian's keys are explicitly W3C WebAuthn/FIDO2 compliant and marketed for passwordless sign-in scenarios like Windows Hello and Google Advanced Protection, which typically rely on discoverable credentials, but the evidence never explicitly names 'resident keys' or 'discoverable credentials' or confirms a specific stored-credential capacity/no-username login flow. Missing for 10: explicit documentation of resident-key/discoverable-credential support, stated credential storage limits, and a hands-on demonstration of username-less WebAuthn sign-in.

                                                                  • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                                                  • [claimed-docs] Seamlessly support Windows Hello (Within an Azure AD).
                                                                  • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.
                                                                  • [claimed-docs] Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…
                                                                2. power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

                                                                  weight 2 · round to Feitian FIDO Keys
                                                                  Google Titan Security Keypartialcommunity5/10

                                                                  Google's own docs confirm broad FIDO/U2F and CTAP1 compatibility beyond Google services and even Advanced Protection use, implying standards-based interoperability, but no evidence explicitly names GitHub, Microsoft, or password-manager integrations. Community reports also flag real-world friction (e.g., 'You can only use Security Keys with Google Chrome' on Mac), showing cross-browser/service compatibility isn't seamless everywhere. missing for 10: explicit confirmation/testing with GitHub, Microsoft accounts, and specific password managers; resolution of the Chrome-only browser limitation reported by users.

                                                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                                                  • [claimed-docs] If you’re a journalist, activist, or someone else at risk of targeted online attacks, you can use Titan Security Keys with the Advanced Prot…
                                                                  • [claimed-docs] One security key can be used to sign in to work and personal services.
                                                                  • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                                                                  • [community] I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…
                                                                  • [community] The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.
                                                                  Feitian FIDO Keyspartialclaimed7/10

                                                                  First-party docs confirm W3C WebAuthn/U2F compliance and dedicated guides for GitHub (OpenSSH), Microsoft/Azure AD, and Google Advanced Protection, showing broad cross-service compatibility. Missing for 10: explicit password-manager (e.g., 1Password/Bitwarden) integration guidance and independent/hands-on verification beyond vendor documentation.

                                                                  • [claimed-docs] Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.
                                                                  • [claimed-docs] Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.
                                                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.
                                                                  • [claimed-docs] Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.
                                                                  • [claimed-docs] Introduction about how FEITIAN Security Keys works with Google advanced protection.

                                                                User verification

                                                                1. security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

                                                                  weight 2 · round to Feitian FIDO Keys
                                                                  Google Titan Security Keynone0/10

                                                                  The evidence pack describes Titan Security Keys as simple touch-based FIDO/U2F/FIDO2 keys (USB-A/NFC, USB-C/NFC, Bluetooth) with no mention of an on-device PIN pad or biometric sensor for user verification; all sign-in flows described are 'insert/tap key' without any PIN or biometric step. Missing for 10: any documentation of a FIDO2 PIN-setting flow, a fingerprint/biometric sensor, or independent confirmation of on-device user verification.

                                                                  • [claimed-docs] If you want to sign in with just your security key and skip your password when possible, you must create a passkey.
                                                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                                                  • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                                                                  • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                                                                  Feitian FIDO Keysfullclaimed7/10

                                                                  Feitian documents biometric (fingerprint) on-device user verification for BioPass keys, explicitly noting 'losing the key will cause no security risk at all,' and separately documents FIDO PIN management via iePassManager for PIN/credential operations, satisfying the on-device UV requirement. Missing for 10: independent/hands-on verification of PIN enforcement or biometric FAR/FRR, and no explicit CTAP2 'uv' flag documentation.

                                                                  • [claimed-docs] Biometric technology makes BioPass FIDO2 Security Key one of the most secure tokens.
                                                                  • [claimed-docs] The fingerprint module prevents any misuses of the token from people other than authorized user, and losing the key will cause no security r…
                                                                  • [claimed-docs] Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).
                                                                  • [claimed-docs] Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.

                                                                Not comparable on these axes

                                                                1. ai-native userPoint an agent at llms.txt or agent-oriented docs

                                                                  weight 2 · not comparable
                                                                  Google Titan Security Keyn/a

                                                                  Titan Security Key is a physical hardware authentication device, not an AI agent or documentation-serving platform; the concept of pointing an agent at llms.txt or agent-oriented docs is a category error for this product type.

                                                                    Feitian FIDO Keysnone0/10

                                                                    Feitian is a hardware FIDO key vendor with no evidence of an llms.txt or agent-oriented documentation; probes explicitly show 404s for llms.txt, markdown docs, and OpenAPI endpoints.

                                                                    • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                                                                    • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                                                                    • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…
                                                                  • ai-native userPlug MCP servers into this product so it can use their tools

                                                                    weight 3 · not comparable
                                                                    Google Titan Security Keyn/a

                                                                    Titan Security Key is a hardware authentication device, not an AI agent or platform capable of connecting to MCP servers or using tools; this axis is a category error for this product type.

                                                                      Feitian FIDO Keysn/a

                                                                      Feitian is a hardware FIDO security key/authentication device, not an AI agent or platform that consumes MCP tools; plugging in MCP servers is a wrong-axis question for this product category.

                                                                      • ai-native userConnect an agent via an official MCP server

                                                                        weight 3 · not comparable
                                                                        Google Titan Security Keyn/a

                                                                        Titan Security Key is a hardware authentication device, not an agent or platform that could expose an MCP server; connecting AI agents via MCP is outside its product category.

                                                                          Feitian FIDO Keysn/a

                                                                          Feitian FIDO Keys is a hardware security-key/authentication product, not an AI agent platform or service with an ecosystem for exposing tools to agents; MCP server connectivity is a wrong-axis question for this product category.

                                                                          • ai-native userIssue scoped/least-privilege API credentials for an agent

                                                                            weight 2 · not comparable
                                                                            Google Titan Security Keyn/a

                                                                            Titan Security Key is a hardware authentication device for human 2FA/passkey login, not an API credential or agent-identity management system; issuing scoped API credentials for autonomous agents is entirely outside its product category.

                                                                              Feitian FIDO Keysn/a

                                                                              Feitian is a hardware FIDO security key/authenticator product, not an API/credential-issuing platform or agent framework; issuing scoped API credentials for an AI agent is outside its product category.

                                                                              • ai-native userSubscribe to events via webhooks

                                                                                weight 2 · not comparable
                                                                                Google Titan Security Keyn/a

                                                                                Titan Security Key is a hardware authentication device, not a service or platform with event-driven APIs; webhook subscriptions are entirely outside its product category.

                                                                                  Feitian FIDO Keysn/a

                                                                                  Feitian FIDO Keys is a hardware authentication device, not a service or platform with event-driven architecture; webhooks are a wrong axis for a physical security key product.

                                                                                  • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                                                    weight 2 · not comparable
                                                                                    Google Titan Security Keyn/a

                                                                                    Titan Security Key is a hardware authentication device, not a data/insights product; AI-generated insights from user data is a category error for this product type.

                                                                                      Feitian FIDO Keysn/a

                                                                                      Feitian FIDO Keys is a hardware authentication device (security key) for FIDO2/WebAuthn login, not a data platform or analytics product; it has no data store or content for AI to generate insights from. This axis is a category error for a hardware security key.

                                                                                      • ai-native userSet up automations that run autonomously in the background

                                                                                        weight 2 · not comparable
                                                                                        Google Titan Security Keyn/a

                                                                                        Titan Security Key is a hardware authentication device, not an agent or automation platform; setting up autonomous background automations is outside its category.

                                                                                          Feitian FIDO Keysn/a

                                                                                          Feitian FIDO Keys are physical authentication hardware, not an automation/agent platform; autonomous background automations are entirely outside this product's category (wrong axis).

                                                                                          • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                                                            weight 3 · not comparable
                                                                                            Google Titan Security Keyn/a

                                                                                            Titan Security Key is a hardware authentication device, not an AI assistant or agent platform; delegating tasks to a built-in AI assistant is not a fair axis for this product category.

                                                                                              Feitian FIDO Keysn/a

                                                                                              Feitian FIDO Keys are hardware security/authentication tokens; they have no AI assistant functionality and the category itself is unrelated to AI task delegation.

                                                                                              • ai-native userOperate the product with natural-language commands

                                                                                                weight 2 · not comparable
                                                                                                Google Titan Security Keyn/a

                                                                                                Titan Security Key is a hardware authentication device, not an interface that accepts natural-language commands; this axis is a category error for this product type.

                                                                                                  Feitian FIDO Keysn/a

                                                                                                  Feitian FIDO Keys are physical hardware authentication tokens; natural-language/AI-agent command interaction is not a relevant axis for a hardware security key product.

                                                                                                  • ai-native userExplore an interactive API reference with runnable examples

                                                                                                    weight 2 · not comparable
                                                                                                    Google Titan Security Keyn/a

                                                                                                    Google Titan Security Key is a hardware authentication device, not a developer API/platform; interactive API references with runnable examples are not applicable to this product category.

                                                                                                      Feitian FIDO Keysn/a

                                                                                                      Feitian FIDO Keys are hardware authentication devices, not an API/SDK product; an interactive API reference with runnable examples is a category mismatch (wrong axis) rather than a missing feature.

                                                                                                      • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                                                                                                        weight 2 · not comparable
                                                                                                        Google Titan Security Keyn/a

                                                                                                        Titan Security Key is a hardware authentication device, not an API/service product; a machine-readable API spec is a category mismatch (wrong axis) for this kind of product.

                                                                                                          Feitian FIDO Keysnone0/10

                                                                                                          Feitian's FIDO key documentation covers WebAuthn/FIDO2 standards and setup guides but no OpenAPI/Swagger spec is published; explicit probes for llms.txt, docs-md, and openapi.json all returned 404.

                                                                                                          • [probe] PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt
                                                                                                          • [probe] PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md
                                                                                                          • [probe] PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…
                                                                                                        • ai-native userTest against a sandbox environment without touching production data

                                                                                                          weight 1 · not comparable
                                                                                                          Google Titan Security Keyn/a

                                                                                                          Titan Security Key is a physical hardware authentication device, not an AI/dev platform with a sandbox vs production environment concept; this story's axis does not apply to this product category.

                                                                                                            Feitian FIDO Keysn/a

                                                                                                            Feitian FIDO Keys is a hardware authentication device, not a software/API product with sandbox vs production environments; the sandbox-testing story is a category error for this product type.

                                                                                                            • ai-native userRely on versioned APIs with a documented deprecation policy

                                                                                                              weight 2 · not comparable
                                                                                                              Google Titan Security Keyn/a

                                                                                                              Titan Security Key is a hardware authentication device, not an API/SDK product; the concept of versioned APIs with deprecation policy is a category error for this product type.

                                                                                                                Feitian FIDO Keysn/a

                                                                                                                Feitian FIDO Keys are hardware authentication devices implementing the FIDO/WebAuthn standard, not a software service with an API surface for AI agents to consume; versioned APIs and deprecation policies are not a relevant axis for this product category.

                                                                                                                • ai-native userDefine rules that trigger actions automatically on events

                                                                                                                  weight 3 · not comparable
                                                                                                                  Google Titan Security Keyn/a

                                                                                                                  Titan Security Key is a hardware authentication device for 2FA/passkey sign-in; it has no automation/rules engine or event-trigger capability, and this axis is a category error for a physical security key.

                                                                                                                    Feitian FIDO Keysn/a

                                                                                                                    Feitian FIDO Keys are hardware authentication devices; defining automation rules triggered on events is a software/workflow automation capability entirely outside this product's category.

                                                                                                                    • ai-native userSchedule recurring jobs or workflows

                                                                                                                      weight 2 · not comparable
                                                                                                                      Google Titan Security Keyn/a

                                                                                                                      Titan Security Key is a hardware authentication device, not a workflow/automation or job-scheduling tool; scheduling recurring jobs is entirely outside its product category.

                                                                                                                        Feitian FIDO Keysn/a

                                                                                                                        Feitian FIDO Keys are hardware authentication tokens for identity verification, not workflow/automation tools; scheduling recurring jobs is entirely outside this product's category.

                                                                                                                        • ai-native userVersion, review, and roll back my automations

                                                                                                                          weight 1 · not comparable
                                                                                                                          Google Titan Security Keyn/a

                                                                                                                          Titan Security Key is a hardware authentication device, not an automation/workflow platform; versioning, reviewing, or rolling back automations is not a fair capability to expect from this product category.

                                                                                                                            Feitian FIDO Keysn/a

                                                                                                                            Feitian FIDO Keys are hardware authentication devices; versioning, reviewing, or rolling back automations is not a capability applicable to this product category.

                                                                                                                            • ai-native userChoose where my data is stored (region/residency)

                                                                                                                              weight 2 · not comparable
                                                                                                                              Google Titan Security Keyn/a

                                                                                                                              Titan Security Key is a physical hardware authentication device, not a data storage or cloud service; data residency/region choice is not an applicable axis for this product category.

                                                                                                                                Feitian FIDO Keysn/a

                                                                                                                                Feitian FIDO Keys are physical hardware authentication devices with no cloud data storage component; data residency/region choice is not applicable to a local hardware security key that stores no user data in a service backend.

                                                                                                                                • ai-native userPrevent my data from being used to train AI models

                                                                                                                                  weight 3 · not comparable
                                                                                                                                  Google Titan Security Keyn/a

                                                                                                                                  Titan Security Key is a hardware authentication device for account security; it has no relationship to AI training data usage or data governance controls, so this axis does not apply to this product category.

                                                                                                                                    Feitian FIDO Keysn/a

                                                                                                                                    Feitian FIDO Keys is a hardware authentication device (security key for FIDO2/U2F/WebAuthn), not an AI service or data platform that trains models on user data. The concept of 'preventing data from being used for AI training' is a category error for this product type.