Skip to content

Hardware Security Keys Arena

Google Titan Security Key vs Nitrokey

Nitrokey wins · 221 (13 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Nitrokey
    Google Titan Security Keynone0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

      Nitrokeypartialprobed4/10

      Nitrokey ships an official CLI (nitropy) that installs headlessly via pip/uvx and can be scripted, which is the closest evidence to CI-style automation (nitrokey-docs-14, nitrokey-probe-4, nitrokey-probe-rt-1). However, there is no documentation of CI pipelines, headless authentication flows, or automation guides, and the core use cases (FIDO2/OTP/PGP) inherently require physical touch presence, limiting true headless operation. Missing for 10: explicit CI/automation documentation, examples of nitropy used in pipelines, and clarification on how touch-required operations are handled headlessly.

      • [claimed-docs] nitropy - Nitrokey Documentation
      • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
    • ai-native userUse an official CLI

      weight 2 · round to Nitrokey
      Google Titan Security Keynone0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Nitrokeyfullprobed8/10

        Nitrokey ships an official, actively maintained CLI (nitropy) documented at docs.nitrokey.com and verified at runtime to install cleanly via PyPI/uvx and report its version, confirming it works as claimed for scripting/automation-style interaction with the device. Missing for 10: no evidence of AI-agent-specific integration, tool-calling support, or third-party corroboration of the CLI's use in agentic workflows.

        • [claimed-docs] nitropy - Nitrokey Documentation
        • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
        • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
      • ai-native userDrive the product through a documented public API

        weight 3 · round to Nitrokey
        Google Titan Security Keynone0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

          Nitrokeypartialprobed5/10

          Nitrokey ships a documented CLI/SDK (nitropy, pynitrokey) that lets scripts/agents drive the hardware token programmatically, confirmed by runtime probes showing it installs and runs from PyPI. However, there is no REST/OpenAPI-style public API — explicit probes for llms.txt, docs-md, and openapi.json all 404 — so an AI agent has no network-callable documented API, only a local CLI/SDK. Missing for 10: a documented HTTP/OpenAPI public API, machine-readable API spec, and any AI-agent-specific integration guidance.

          • [claimed-docs] nitropy - Nitrokey Documentation
          • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
          • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
          • [probe] PROBE llms.txt: HTTP 404 at https://docs.nitrokey.com/llms.txt
          • [probe] PROBE docs-md: HTTP 404 at https://docs.nitrokey.com/.md
          • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
        • ai-native userBuild against official SDKs

          weight 2 · round to Nitrokey
          Google Titan Security Keynone0/10

          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

            Nitrokeypartialprobed6/10

            Nitrokey publishes an official CLI (nitropy) and a Python SDK (pynitrokey) on PyPI, both confirmed working via runtime probes, and firmware/source are open on GitHub — giving developers a real path to build against official tooling. However there's no evidence of broader multi-language SDKs, API references beyond nitropy, or any AI/agent-specific integration surface (no OpenAPI, no llms.txt, probes for both 404). Missing for 10: multi-language/official SDKs beyond Python, formal API docs/OpenAPI spec, AI-agent-specific integration examples.

            • [claimed-docs] nitropy - Nitrokey Documentation
            • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
            • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
            • [github] The Nitrokey 3 firmware is written in Rust. It uses the Trussed firmware framework and is developed in collaboration with SoloKeys
            • [probe] PROBE llms.txt: HTTP 404 at https://docs.nitrokey.com/llms.txt
            • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…

          Automation depth — how much of the product can run unattendedAutomation depth

          How much of the product can run unattended

          1. ai-native userPerform bulk operations across many items at once

            weight 2 · round drawn
            Google Titan Security Keynone0/10

            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

              Nitrokeynone0/10

              Nitrokey ships a CLI (nitropy) and Python SDK that could in principle be scripted, but no evidence in the pack shows any documented bulk-operation workflow (e.g., batch provisioning, mass key management, scripted multi-device automation) for AI-native or automated bulk use. Only single-device/product feature lists and an 'Entra ID provisioning' mention appear, with no concrete bulk-operation documentation or example. missing for 10: documented bulk/batch API or CLI commands, evidence of managing many items/devices at once, automation examples for large-scale provisioning.

              • [claimed-docs] nitropy - Nitrokey Documentation
              • [claimed-docs] Nitrokey Provisioning for Entra ID
              • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…

            Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido

            What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

            Openpgp

            1. developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email

              weight 2 · round to Nitrokey
              Google Titan Security Keynone0/10

              Titan Security Key is a FIDO/U2F authenticator with no documented OpenPGP applet or smartcard support for git commit signing or encrypted email; evidence only covers FIDO2/U2F sign-in use cases.

              • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
              • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
              Nitrokeyfullclaimed8/10

              Nitrokey devices support the OpenPGP smart card standard with on-device key generation, touch confirmation, and documented integration with Thunderbird for encrypted email; the OpenPGP card standard is also the basis for git commit signing via GPG, which is a well-known standard use case for OpenPGP smart cards. Docs explicitly cover keygen-on-device, touch confirmation, and Thunderbird email use. Missing for 10: explicit first-party documentation naming 'git commit signing' as a use case, and independent hands-on corroboration of the OpenPGP-card signing workflow.

              • [claimed-docs] Windows Login and S/MIME Email Encryption with Active Directory
              • [claimed-docs] Touch Confirmation (Nitrokey 3 only)
              • [claimed-docs] Keygen on device
              • [claimed-docs] Thunderbird
              • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…

            Otp

            1. power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

              weight 2 · round to Nitrokey
              Google Titan Security Keynone0/10

              Titan Security Key is a FIDO/U2F/WebAuthn hardware authenticator; no evidence indicates it supports TOTP/HOTP seed storage or generic challenge-response slots for legacy OTP services. All documentation focuses on FIDO CTAP1/U2F/WebAuthn use cases only.

              • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
              • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
              Nitrokeypartialclaimed6/10

              Docs explicitly list 'Two Factor Authentication' and OTP support (login using OTP for Google/Facebook), and the Nitrokey 3 product page mentions 'one-time passwords' among combined features, indicating TOTP/HOTP slot support. However, no explicit mention of HOTP challenge-response mode, no detail on number of slots, no independent hands-on verification of OTP functionality, and community evidence focuses on other features (HSM, durability) without confirming OTP reliability. Missing for 10: explicit challenge-response documentation, slot-count/configuration details, independent hands-on confirmation of OTP/HOTP working as advertised.

              • [claimed-docs] Login to websites (e.g. Google, Facebook) using secure One Time Passwords (OTP), U2F or ordinary static passwords.
              • [claimed-docs] Two Factor Authentication
              • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…

            Piv

            1. it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

              weight 2 · round to Nitrokey
              Google Titan Security Keynone0/10

              Evidence only covers FIDO/U2F/FIDO2 authentication (Google Sign-In, CTAP1 sites, Advanced Protection) — no mention of PIV smart card mode, certificate-based login, workstation sign-in via smart card, VPN client certs, or code-signing use cases.

              • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
              • [claimed-docs] One security key can be used to sign in to work and personal services.
              • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
              Nitrokeypartialcommunity6/10

              Nitrokey documents PIV support explicitly (nitrokey-docs-11) plus Windows Login/AD, S/MIME, PAM (Linux), OpenVPN and on-device keygen with touch confirmation (nitrokey-docs-5,6,7,8,15), covering workstation login, VPN and code-signing-adjacent use cases with non-exportable keys. However, code-signing evidence is limited to CLI/attestation tooling rather than a dedicated PIV code-signing workflow, and community reports flag missing feature parity and cryptographic limitations (Ed25519 unsupported, non-standard attestation cert formats) versus competitors, plus slow/incomplete rollout of promised features. Missing for 10: dedicated PIV-specific code-signing documentation/integration guide, independent hands-on verification of PIV smart-card login working end-to-end, and confirmation that PIV certs are exportable/usable in enterprise CA workflows.

              • [claimed-docs] PIV (Personal Identity Verification)
              • [claimed-docs] Windows Login and S/MIME Email Encryption with Active Directory
              • [claimed-docs] Keygen on device
              • [claimed-docs] PAM (Linux)
              • [claimed-docs] OpenVPN
              • [community] I'm currently using both Nitrokeys and YubiHSMs on a client project. Nitrokeys can't do Ed25519, stuck with NSA Suite B for ECC. Attestation…
              • [community] I hesitated between both, but the nitrokey 3 has so many things listed as "planned" that I went for a Yubikey (bought a 5a NFC and a 5c NFC)…

            Ssh

            1. developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

              weight 2 · round to Nitrokey
              Google Titan Security Keynone0/10

              The evidence pack covers only FIDO2/U2F use for Google/web sign-in, Bluetooth pairing, NFC, and physical hardware details — there is no mention of sk-ssh, PIV, OpenPGP, or any SSH-key hardware-backing capability. missing for 10: sk-ssh/FIDO2 SSH key support, PIV applet, OpenPGP applet, any developer SSH workflow documentation.

                Nitrokeypartialcommunity6/10

                Docs confirm SSH login via certificates, PIV support, and OpenPGP card with touch confirmation, and a dedicated 'SSH Keys' page under the FIDO2 section suggests sk-ssh key support, aligning with the hardware-backed SSH story. However, there's no explicit walkthrough of FIDO2 sk-ssh key generation/usage, and community threads note the Nitrokey 3 has lagged in reaching feature parity with competitors, raising some doubt about full FIDO2 SSH robustness. Missing for 10: explicit sk-ssh setup documentation/examples, independent hands-on confirmation of FIDO2 SSH touch-to-authenticate working end-to-end.

                • [claimed-docs] SSH Keys
                • [claimed-docs] Login to computers and network services (e.g. SSH) using certificates.
                • [claimed-docs] Touch Confirmation (Nitrokey 3 only)
                • [claimed-docs] PIV (Personal Identity Verification)
                • [community] My Yubikey 5 NFC rocks. Just works. I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shi…

              Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling

              Building with and managing the key — CLIs, SDKs, attestation

              Agent audit

              1. ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

                weight 2 · round to Nitrokey
                Google Titan Security Keynone0/10

                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                  Nitrokeypartialprobed5/10

                  The official nitropy CLI (and Python SDK) can programmatically query device attributes such as version and connected devices (e.g., 'nitropy version', device listing), giving agents a scriptable way to pull serial/firmware info, and firmware update tooling is documented. However, there is no evidence of a documented way to enumerate 'enabled applications' or 'stored credentials' via CLI/API for fleet-wide security audits, and no fleet-management or structured (JSON/API) output is shown. Missing for 10: documented commands/output for enabled applications and stored credential enumeration, structured machine-readable output format, and any fleet-audit tooling or API/OpenAPI spec (probes show none exists).

                  • [claimed-docs] nitropy - Nitrokey Documentation
                  • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                  • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
                  • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…

                Attestation

                1. security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled

                  weight 2 · round to Nitrokey
                  Google Titan Security Keydisputedcontradicted3/10

                  Docs claim the key's hardware chip/firmware 'verifies that the keys haven't been tampered with' and provides 'cryptographic proof' of legitimate registration (google-titan-docs-12, docs-14, docs-20), which gestures at attestation, but there is no documentation or tooling aimed at security engineers for inspecting attestation certificates or enforcing an approved-model allowlist at registration. A hands-on report directly undercuts the 'genuine, approved model' framing: a user's non-Google Feitian MultiPass key (identical hardware to Titan) was accepted by Google's own replacement/registration system as if it were an official Titan key, showing the attestation/verification does not reliably distinguish genuine Titan units from rebranded third-party hardware (google-titan-comm-12, comm-14). Missing for 10: security-engineer-facing attestation verification API/metadata service, documented enforcement of approved key models, and any first-party/independent confirmation that model spoofing is prevented.

                  • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                  • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                  • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                  • [community] I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …
                  • [community] I got one of Google's Advanced Protection kits, which included two keys that look exactly like the Titan keys in the article. Both are Feiti…
                  Nitrokeypartialcommunity4/10

                  Nitrokey ships FIDO2 (which includes device attestation) and PIV, but there is no documentation of an attestation verification workflow for registration, and a hands-on report notes attestation certificates can't be exported via standard PKCS#11 and require a custom vendor tool plus a non-standard ASN.1 cert format, adding real friction for engineers building attestation checks. missing for 10: first-party docs on attestation cert format/verification API, standard PKCS#11/FIDO2 attestation export support, independent confirmation of a smooth registration-time attestation check.

                  • [claimed-docs] SSH Keys
                  • [community] I'm currently using both Nitrokeys and YubiHSMs on a client project. Nitrokeys can't do Ed25519, stuck with NSA Suite B for ECC. Attestation…

                Cli

                1. developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

                  weight 3 · round to Nitrokey
                  Google Titan Security Keynone0/10

                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                    Nitrokeyfullprobed8/10

                    Nitrokey ships an official CLI, nitropy, documented at docs.nitrokey.com/software/nitropy and verified installable/runnable via PyPI, described as a tool to interact with Nitrokey devices (identity/version checks, firmware updates, etc.), plus a companion Python SDK — this covers scriptable device configuration and management. Missing for 10: explicit documentation/examples in the evidence pack of specific subcommands for PIN-setting, slot management, and app enable/disable, and independent hands-on confirmation of full feature parity across all device operations.

                    • [claimed-docs] nitropy - Nitrokey Documentation
                    • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
                    • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                    • [claimed-docs] Firmware Update

                  Sdks

                  1. developerOfficial SDKs let me integrate the key into my own desktop and mobile apps

                    weight 2 · round to Nitrokey
                    Google Titan Security Keynone0/10

                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                      Nitrokeypartialprobed5/10

                      Nitrokey provides nitropy CLI and a Python 'nitrokey' SDK on PyPI plus PIV/OpenPGP/PKCS#11 support that developers can integrate into tooling, but there is no evidence of official mobile SDKs (iOS/Android app libraries) or desktop app integration SDKs beyond the low-level Python/CLI tooling. missing for 10: dedicated mobile (iOS/Android) SDKs, higher-level desktop app integration libraries (e.g. for Electron/Swift/Java), first-party sample apps or API docs showing SDK usage in third-party apps.

                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                      • [claimed-docs] nitropy - Nitrokey Documentation
                      • [claimed-docs] Android / NitroPhone

                    Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat

                    Where the key works — platforms, browsers, service compatibility catalogs

                    Agent approval

                    1. ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

                      weight 1 · round drawn
                      Google Titan Security Keynone0/10

                      Evidence only shows Titan Security Key being used for standard account sign-in / 2-Step Verification via FIDO/U2F, with no mention of any API, SDK, or workflow that lets an AI agent request a physical-touch approval gate for its own automated actions. Nothing in the docs or community discussion ties the key's touch requirement to agent-initiated or automated action approval.

                      • [claimed-docs] Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.
                      • [claimed-docs] Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…
                      • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                      Nitrokeynone0/10

                      Nitrokey documents generic touch-confirmation for OpenPGP/FIDO2 operations, but there is no evidence tying this to AI-agent or automated-action approval workflows, MCP, or any agentic tooling — the capability as described in the story is unevidenced.

                    Compatibility

                    1. power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services

                      weight 2 · round drawn
                      Google Titan Security Keydisputedcontradicted4/10

                      Google's docs claim broad cross-platform support (Android/iOS NFC, Linux setup via udev, FIDO CTAP1 compatibility with third-party sites) but there is no published catalog of specific supported services/sites—just a generic FIDO-standard compatibility statement. Community reports directly contradict smooth cross-browser/OS support: one user found keys 'only' worked with Chrome and failed on Mac despite official docs, while others reported success with Firefox on Linux and pairing issues on Mac, showing inconsistent real-world compatibility. missing for 10: an actual published list/catalog of compatible services, and confirmation that browser/OS support claims hold up without conflicting user reports.

                      • [claimed-docs] Works with compatible Android and iOS devices through NFC
                      • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                      • [claimed-docs] To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.
                      • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                      • [community] I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…
                      • [community] The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.
                      • [community] I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…

                      Docs scatter claims of broad compatibility (SSH, FIDO2, OTP, PIV, OpenPGP, Windows/AD, Office 365, Nextcloud, Thunderbird, OpenVPN) but there is no single published compatibility catalog/matrix of supported services or browsers. Community evidence concretely contradicts smooth cross-platform delivery: users report needing to allow unsigned driver installation on Windows, and multiple reports that Nitrokey 3 still lists many features as 'planned' and lags Yubikey in feature parity years after purchase. missing for 10: a unified compatibility matrix/catalog page, confirmation of parity across all claimed services, resolution of the Windows driver-signing friction.

                      • [claimed-docs] Login to websites (e.g. Google, Facebook) using secure One Time Passwords (OTP), U2F or ordinary static passwords.
                      • [claimed-docs] Forget your password to log in to Microsoft services (e.g. Office 365) and Nextcloud and use Nitrokey for passwordless login instead.
                      • [claimed-docs] Windows Login and S/MIME Email Encryption with Active Directory
                      • [community] To install the driver, you may need to allow the installation of unsigned drivers first. Nope, thanks.
                      • [community] My Yubikey 5 NFC rocks. Just works. I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shi…
                      • [community] I hesitated between both, but the nitrokey 3 has so many things listed as "planned" that I went for a Yubikey (bought a 5a NFC and a 5c NFC)…

                    Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery

                    Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

                    Recovery

                    1. security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

                      weight 3 · round to Google Titan Security Key
                      Google Titan Security Keypartialcommunity4/10

                      Google docs cover removing a lost key from an account (google-titan-docs-9) and enrolling a security key (google-titan-docs-15), and a community comment notes Google's own guidance to keep one key in daily use and store a backup safely (google-titan-comm-3), implying an informal backup-key strategy. However there is no first-party documentation laying out a full lockout-recovery plan (e.g., how to regain account access before removing the key, what happens if the only registered key is lost, or explicit backup-key enrollment steps). missing for 10: explicit vendor doc on account lockout scenarios, dedicated backup-key enrollment walkthrough, and clarity on what is/isn't recoverable if the sole key is lost

                      • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                      • [claimed-docs] Enroll your security key. You might need to sign in.
                      • [community] Is it possible to use the Bluetooth dongle with a desktop computer without a cable? Having to carry both on your keyring kind of defeats the…
                      • [community] Pretty cool, I like that it comes with two keys at the start so you have a backup, unlike Yubi where I have to buy two before I can even get…
                      Nitrokeynone0/10

                      No evidence pack item documents a vendor-provided lockout-recovery strategy (e.g., registering a backup Nitrokey, or what OpenPGP/FIDO2/PIV credentials are or are not recoverable if a key is lost). The closest mention is a third-party community comment about offline key escrow for the unrelated HSM product, not official documentation of recovery/backup-key enrollment.

                      • [community] Used the original Nitrokey HSM model on a code-signing server project. The applet running inside is not free/open source but dev tools and d…

                    Setup

                    1. power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

                      weight 2 · round drawn
                      Google Titan Security Keypartialcommunity5/10

                      Google's support docs give step-by-step guided enrollment (sign in, 'Enroll your security key', device detects it and walks through sign-in) and cover related setup nuances like Linux udev rules and NFC/Bluetooth pairing, but there is no dedicated setup app—just web help pages. Community reports also note friction during first-time use (Chrome-only compatibility issues, Bluetooth key not pairing with Mac), suggesting the guided flow isn't universally smooth across platforms/browsers. Missing for 10: a purpose-built setup wizard/app, cross-browser first-run guidance, and independent confirmation that the documented steps work smoothly on all platforms.

                      • [claimed-docs] Enroll your security key. You might need to sign in.
                      • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                      • [claimed-docs] Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.
                      • [claimed-docs] To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.
                      • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                      • [community] I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…
                      Nitrokeypartialprobed5/10

                      Nitrokey provides scattered feature-specific docs (SSH, PIV, OpenPGP, FIDO2, general instructions) and a CLI tool (nitropy) for device management, which can guide account registration for specific services, but there's no single unified setup wizard/app walking a user end-to-end through registering with major accounts. Community feedback also flags real setup friction (e.g., needing to allow unsigned driver installation) that undercuts a smooth guided experience. Missing for 10: a dedicated onboarding app/wizard, first-party account-registration walkthroughs (e.g., for Google/Microsoft/GitHub), and independent hands-on confirmation that setup is smooth.

                      • [claimed-docs] Two Factor Authentication
                      • [claimed-docs] General Instructions
                      • [claimed-docs] nitropy - Nitrokey Documentation
                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                      • [community] To install the driver, you may need to allow the installation of unsigned drivers first. Nope, thanks.

                    Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness

                    What runs on the device — open-source firmware, update policy, vulnerability response

                    Source

                    1. security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

                      weight 2 · round to Nitrokey
                      Google Titan Security Keynone0/10

                      Google explicitly states firmware is 'developed by Google' and used to verify tamper-resistance, but there is no evidence of open-source firmware or independent third-party audit reports; community evidence only discusses hardware manufacturing (Feitian OEM) and a Bluetooth vulnerability, not firmware transparency/auditing. missing for 10: any published audit report, open-source firmware repository, or independent verification of firmware code.

                      • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                      • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                      • [community] Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…
                      Nitrokeypartialprobed7/10

                      Nitrokey 3 firmware is confirmed open source (Rust, dual Apache2.0/MIT licensed, tagged releases on GitHub) which lets engineers inspect what runs on the device, but the HSM applet is explicitly noted as not open source, and there is no evidence of an independent third-party security audit of the firmware. missing for 10: independent audit report, confirmation that all product lines (not just Nitrokey 3) are open source, no audit mention for the closed HSM applet.

                      • [github] This software is fully open source.
                      • [github] The Nitrokey 3 firmware is written in Rust. It uses the Trussed firmware framework and is developed in collaboration with SoloKeys
                      • [github] All software, unless otherwise noted, is dual licensed under Apache 2.0 and MIT license.
                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey 3 firmware is open source in Rust WITH tagged, installable releases — https://github.com/Nitro…
                      • [community] Used the original Nitrokey HSM model on a code-signing server project. The applet running inside is not free/open source but dev tools and d…

                    Updates

                    1. security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

                      weight 2 · round drawn
                      Google Titan Security Keypartialcommunity4/10

                      There is concrete real-world evidence of one incident: a BLE pairing vulnerability was disclosed, Google emailed affected users ('Update on your Titan Security Key') and ran a replacement program rather than a firmware patch, showing some vulnerability-response process exists but it worked through physical device replacement, not an in-field firmware update, and users found the replacement process cumbersome. There is no published advisory list/CVE tracker or affected-model lookup tool in the evidence — docs only vaguely mention Google-engineered firmware for tamper verification. Missing for 10: a public security-advisory/CVE page, a documented affected-model/serial lookup tool, and an actual firmware-update delivery mechanism (evidence shows fixes require full device replacement, not a firmware push).

                      • [claimed-docs] A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.
                      • [claimed-docs] Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.
                      • [community] Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…
                      • [community] Not the most user-friendly replacement process here, Google. First I had to chat with a representative... Now I need to place a 'replacement…
                      • [community] The replacement site worked by sending me to a contact form where I had to chat with a representative then wait for an email to initiate an …
                      • [community] I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …
                      Nitrokeypartialprobed4/10

                      Nitrokey documents a firmware-update mechanism (dedicated firmware-update guide, nitropy CLI, tagged GitHub releases like v1.8.3) and open-source firmware for transparency, but there is no evidence of a formal security-advisory feed, CVE list, or affected-model lookup tool comparable to a vendor security bulletin process; a community post references a real key-extraction issue discussed ad hoc rather than via a documented advisory pipeline. Missing for 10: dedicated security advisories page, CVE/vulnerability database, affected-model/version lookup tool, and clear SLA for how fixes reach devices beyond generic update docs.

                      • [claimed-docs] Firmware Update
                      • [claimed-docs] nitropy - Nitrokey Documentation
                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey 3 firmware is open source in Rust WITH tagged, installable releases — https://github.com/Nitro…
                      • [community] Author here: extracting Nitrokey HSM RSA private keys is not a vulnerability per se - it requires the attacker to already have the keys to t…
                      • [github] This software is fully open source.

                    Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management

                    Keys at organization scale — bulk provisioning, delivery services, IdP policies

                    Agent provisioning

                    1. ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

                      weight 2 · round drawn
                      Google Titan Security Keynone0/10

                      This is a hardware security key with human-driven web console setup (enroll, pair, reset) via support docs; there is no evidence of any enterprise API for agent-driven ordering, assignment, or pre-registration of keys. missing for 10: documented provisioning/management API, evidence of programmatic ordering or fleet assignment, any agent/automation-facing endpoint.

                      • [claimed-docs] Enroll your security key. You might need to sign in.
                      • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                      • [claimed-docs] One security key can be used to sign in to work and personal services.
                      Nitrokeynone0/10

                      Nitrokey documents an nitropy CLI for on-device configuration and an Entra ID provisioning integration, but there is no evidence of a documented enterprise API supporting agent-driven ordering, assignment, or pre-registration workflows — OpenAPI/API probes all returned 404. missing for 10: documented REST/enterprise API for ordering and fleet assignment, evidence of programmatic pre-registration, any API reference beyond CLI tooling.

                      • [claimed-docs] Nitrokey Provisioning for Entra ID
                      • [claimed-docs] nitropy - Nitrokey Documentation
                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                      • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…

                    Delivery

                    1. it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

                      weight 2 · round drawn
                      Google Titan Security Keynone0/10

                      No evidence of any bulk-shipping logistics, distribution API, admin console, or fleet-provisioning workflow for shipping keys to distributed employees; evidence covers only individual key setup, replacement RMA process, and hardware/community feedback.

                        Nitrokeynone0/10

                        Evidence covers device features (FIDO2, OpenPGP, PIV), firmware/CLI tooling, and community feedback on hardware/support quality, but nothing addresses enterprise bulk-shipping/fleet logistics, an API/console for distributing keys directly to distributed employees, or any provisioning-and-delivery service comparable to fleet-management logistics.

                        Idp

                        1. it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

                          weight 2 · round to Nitrokey
                          Google Titan Security Keynone0/10

                          The evidence pack covers consumer/personal account setup, Bluetooth pairing, form factors, and hardware attestation, but contains no evidence of IT-admin-facing integration with identity providers like Okta, Entra ID, or Google Workspace admin console policy enforcement for hardware-key-only authentication. This is a fair axis for a hardware security key vendor to address (fleet policy enforcement via IdP), but no such capability or documentation is present.

                            Nitrokeypartialclaimed4/10

                            Nitrokey documents FIDO2/PIV/OpenPGP protocol support and a specific 'Nitrokey Provisioning for Entra ID' tool, showing some IdP integration, but there is no evidence of Okta or Google Workspace integration, nor any admin console/policy engine to enforce hardware-key-only authentication fleet-wide. Missing for 10: Okta integration, Google Workspace integration, centralized policy enforcement/fleet management console, documentation of admin-side enrollment/compliance workflows.

                          Provisioning

                          1. it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

                            weight 3 · round to Nitrokey
                            Google Titan Security Keynone0/10

                            Evidence covers individual end-user setup, pairing, resetting, and removing a single key, but nothing addresses IT-admin fleet capabilities like bulk pre-registration, centralized provisioning, or lifecycle/inventory tracking across an organization. Missing for 10: bulk enrollment tools/API, admin console integration for mass key registration, and lifecycle/inventory tracking dashboards.

                              Nitrokeypartialprobed3/10

                              Nitrokey ships an official CLI (nitropy) and Python SDK for scripting device operations, and docs reference 'Nitrokey Provisioning for Entra ID,' suggesting some enterprise provisioning path exists, but there is no evidence of bulk pre-registration workflows, centralized fleet dashboards, or lifecycle/audit tracking across many issued keys. missing for 10: bulk enrollment/pre-registration tooling, centralized admin console for fleet inventory, lifecycle/revocation tracking at scale, independent case studies of large deployments.

                              • [claimed-docs] nitropy - Nitrokey Documentation
                              • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                              • [claimed-docs] Nitrokey Provisioning for Entra ID

                            Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors

                            The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

                            Certifications

                            1. it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

                              weight 2 · round to Nitrokey
                              Google Titan Security Keynone0/10

                              The evidence pack contains no mention of FIPS 140 validation or Common Criteria certification for Titan Security Keys, nor documented water/crush resistance specs; in fact, one community report suggests the underlying Feitian hardware is fragile if dropped, contradicting any durability certification claim. missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, official durability/water-crush resistance specs.

                              • [community] The wireless key is the Feitian MultiPass FIDO Security Key. I'd caution people to read the Amazon reviews (specifically people found it unr…
                              Nitrokeypartialcommunity3/10

                              Nitrokey documents a Common Criteria EAL 6+ certified secure element in the Nitrokey 3 (nitrokey-docs-16), satisfying the certification half of the story, but there is no mention anywhere in the evidence of FIPS 140 validation, nor any documented water/crush-resistance or ruggedization specs. Community hands-on feedback actively undercuts the durability angle, describing the U2F key as feeling 'flimsy' compared to competitors (nitrokey-comm-3, nitrokey-comm-4). Missing for 10: FIPS 140 validation evidence, explicit IP/MIL-STD or water/crush durability specs, and independent corroboration of ruggedness rather than community complaints about build quality.

                              • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…
                              • [community] I wish they would make something that felt more durable. I bought the U2F key and the combination of plastic and not being sure where to pre…
                              • [community] Unlike some competitors, Nitrokey contains a complete and standard compliant USB plug... Here I am waiting for a Type-C from them. Yet they …

                            Connectors

                            1. power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

                              weight 2 · round drawn
                              Google Titan Security Keypartialcommunity4/10

                              Docs confirm two form factors—USB-A/NFC and USB-C/NFC—but there is no evidence of a keychain or nano low-profile model, and community feedback even calls the (Bluetooth) key large rather than low-profile. missing for 10: keychain form factor, nano/low-profile form factor, independent hands-on confirmation of size/portability across the full claimed lineup.

                              • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                              • [community] It's so big. Couldn't they have come up with a more subtle form factor?
                              Nitrokeypartialcommunity4/10

                              Evidence indirectly shows both USB-A and USB-C variants exist (the shop page references 'nk3an-nitrokey-3a-nfc' and a community comment mentions ordering a 'Nitrokey 3C NFC'), suggesting the lineup covers both port types. However, there is no evidence of keychain or nano low-profile form factors anywhere in the pack, and one community comment even complains about waiting years for a Type-C model, casting some doubt on breadth/availability. Missing for 10: explicit nano/keychain form-factor SKUs, confirmed current availability of USB-C models, first-party spec sheet comparing form factors.

                              • [claimed-docs] Forget your password to log in to Microsoft services (e.g. Office 365) and Nextcloud and use Nitrokey for passwordless login instead.
                              • [community] Unlike some competitors, Nitrokey contains a complete and standard compliant USB plug... Here I am waiting for a Type-C from them. Yet they …
                              • [community] My Yubikey 5 NFC rocks. Just works. I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shi…

                            Nfc

                            1. power userTap the key on my phone over NFC to authenticate in mobile browsers and apps

                              weight 2 · round to Google Titan Security Key
                              Google Titan Security Keyfullclaimed7/10

                              Docs confirm the USB-A/NFC and USB-C/NFC key models work over NFC with compatible Android and iOS devices (iOS 13.3+), covering mobile browser/app authentication. Missing for 10: independent hands-on confirmation of NFC tap-to-auth specifically in third-party mobile apps (community evidence focuses mainly on Bluetooth/desktop use, not NFC mobile app flows).

                              • [claimed-docs] Works with compatible Android and iOS devices through NFC
                              • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                              • [claimed-docs] iPhones with iOS version 13.3 or up | Yes | Yes
                              Nitrokeypartialclaimed4/10

                              Nitrokey sells an NFC-enabled model (Nitrokey 3A NFC) and documents FIDO2/U2F/OTP login flows and an Android/NitroPhone integration, implying NFC tap-to-auth is technically supported, but no evidence explicitly confirms tapping the key against a phone to authenticate in mobile browsers/apps, nor any hands-on report of this working. Missing for 10: explicit documentation or user testimony of NFC-based authentication on phones, coverage across major mobile browsers/apps, and confirmation it works as smoothly as competitors.

                              • [claimed-docs] Forget your password to log in to Microsoft services (e.g. Office 365) and Nextcloud and use Nitrokey for passwordless login instead.
                              • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…
                              • [claimed-docs] Android / NitroPhone
                              • [claimed-docs] Two Factor Authentication

                            Openness — open source, data portability, and self-hosting storiesOpenness

                            Open source, data portability, and self-hosting stories

                            1. ai-native userDo everything through the API that I can do in the UI

                              weight 2 · round to Nitrokey
                              Google Titan Security Keynone0/10

                              The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                Nitrokeypartialprobed4/10

                                Nitrokey ships an official CLI (nitropy) and Python SDK that can configure/manage devices programmatically, confirmed to install and run via PyPI, but there is no formal REST/OpenAPI interface (all API endpoint probes 404) and no explicit vendor claim of full UI/CLI feature parity for AI-native automation. Missing for 10: documented API/OpenAPI spec, explicit parity statement between GUI app and nitropy CLI, and independent verification that all UI-exposed features are scriptable via nitropy.

                                • [claimed-docs] nitropy - Nitrokey Documentation
                                • [probe] official CLI documented at https://docs.nitrokey.com/software/nitropy/
                                • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                                • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                              • ai-native userExport all of my data in open formats and leave

                                weight 3 · round to Nitrokey
                                Google Titan Security Keynone0/10

                                The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                  Nitrokey's firmware and licensing are open source (nitrokey-gh-1, nitrokey-gh-3) and it uses open standards like FIDO2/OpenPGP/PIV, which in principle avoid lock-in, but a hands-on user report describes the opposite of clean data portability: Nitrokey attestation certs 'can't be exported via PKCS#11' and require a 'custom vendor shell' with a non-standard ASN.1 cert container (nitrokey-comm-2) — directly contradicting an open, portable data-export claim. Missing for 10: any first-party documentation of a bulk/data export feature or standard export format for stored secrets, and no counter-evidence resolving the community-reported non-standard export path.

                                  • [github] This software is fully open source.
                                  • [github] All software, unless otherwise noted, is dual licensed under Apache 2.0 and MIT license.
                                  • [community] I'm currently using both Nitrokeys and YubiHSMs on a client project. Nitrokeys can't do Ed25519, stuck with NSA Suite B for ECC. Attestation…
                                • ai-native userRead the product's source under an open license

                                  weight 2 · round to Nitrokey
                                  Google Titan Security Keynone0/10

                                  The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                    Nitrokeyfullprobed8/10

                                    Nitrokey 3 firmware source is hosted on GitHub, explicitly stated to be fully open source, dual-licensed under Apache 2.0/MIT, with tagged releases confirming active open development. This directly satisfies reading source under an open license for the core firmware. Missing for 10: confirmation that all components (e.g., HSM applet, some proprietary parts noted in community evidence) are open, and no independent audit of license completeness beyond firmware repo.

                                    • [github] This software is fully open source.
                                    • [github] The Nitrokey 3 firmware is written in Rust. It uses the Trussed firmware framework and is developed in collaboration with SoloKeys
                                    • [github] All software, unless otherwise noted, is dual licensed under Apache 2.0 and MIT license.
                                    • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey 3 firmware is open source in Rust WITH tagged, installable releases — https://github.com/Nitro…
                                  • ai-native userSelf-host the core product

                                    weight 3 · round drawn
                                    Google Titan Security Keynone0/10

                                    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Nitrokeynone0/10

                                      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                      Privacy posture — data-handling and privacy storiesPrivacy posture

                                      Data-handling and privacy stories

                                      1. ai-native userControl data retention and deletion

                                        weight 2 · round drawn
                                        Google Titan Security Keynone0/10

                                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                          Nitrokeynone0/10

                                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                          • ai-native userOpt out of telemetry and usage tracking

                                            weight 2 · round drawn
                                            Google Titan Security Keynone0/10

                                            The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                                              Nitrokeynone0/10

                                              The evidence pack covers Nitrokey's hardware features (FIDO2, OpenPGP, PIV), its open-source firmware/CLI (nitropy), and community commentary on durability/support, but contains no mention of any telemetry, usage tracking, or opt-out settings for its software (nitropy CLI, firmware update service) or hardware. Since Nitrokey ships software tools that could in principle collect usage data, the axis applies, but there is no evidence either confirming or denying telemetry practices.

                                              Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage

                                              FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

                                              Credential management

                                              1. power userList and delete the passkeys stored on my key and know its credential capacity before it fills up

                                                weight 2 · round drawn
                                                Google Titan Security Keynone0/10

                                                The evidence covers removing a key from a Google account and unpairing Bluetooth, but there is no mention of an on-key credential management tool that lists or deletes individual passkeys stored on the Titan key itself, nor any documentation of the key's credential storage capacity or warnings about it filling up.

                                                • [claimed-docs] If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.
                                                • [claimed-docs] If you want to stop using a Bluetooth Titan Security Key with one or more devices, you can unpair the key.
                                                Nitrokeynone0/10

                                                While Nitrokey ships FIDO2 support and an official nitropy CLI, the evidence pack contains no documentation or mention of commands/features to list resident passkeys, delete individual credentials, or view credential storage capacity/limits. This is a fair capability to expect from a FIDO2 authenticator, but no evidence confirms it.

                                                Fido2

                                                1. security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

                                                  weight 3 · round to Nitrokey
                                                  Google Titan Security Keypartialclaimed5/10

                                                  Docs confirm passkey creation for Google Accounts (implying a discoverable, device-bound credential that lets sign-in without typing a password) via google-titan-docs-2, but the same docs explicitly describe third-party site support only via 'FIDO CTAP1 standards' (google-titan-docs-4), which does not guarantee resident-key/FIDO2 support broadly. No explicit mention of FIDO2/CTAP2 or 'discoverable credentials' terminology anywhere in the pack. Missing for 10: explicit FIDO2/CTAP2 protocol documentation, direct mention of resident/discoverable credentials, and independent verification of username-less sign-in across non-Google WebAuthn services.

                                                  • [claimed-docs] If you want to sign in with just your security key and skip your password when possible, you must create a passkey.
                                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                                  • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                                                  Nitrokeypartialcommunity6/10

                                                  Docs confirm FIDO2 support and explicitly market 'passwordless login' to Microsoft/Nextcloud (nitrokey-docs-4), which implies discoverable/resident-key credentials, and FIDO2 is listed as a core feature (nitrokey-docs-1, nitrokey-docs-16). However, no documentation explicitly names 'resident keys' or 'discoverable credentials,' and community reports note the Nitrokey 3 has lagged on FIDO2 feature parity with competitors (many features listed as 'planned'), raising doubt about completeness. Missing for 10: explicit resident-key/discoverable-credential documentation, independent hands-on verification of usernameless sign-in working end-to-end.

                                                  • [claimed-docs] SSH Keys
                                                  • [claimed-docs] Forget your password to log in to Microsoft services (e.g. Office 365) and Nextcloud and use Nitrokey for passwordless login instead.
                                                  • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…
                                                  • [community] My Yubikey 5 NFC rocks. Just works. I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shi…
                                                  • [community] I hesitated between both, but the nitrokey 3 has so many things listed as "planned" that I went for a Yubikey (bought a 5a NFC and a 5c NFC)…
                                                2. power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

                                                  weight 2 · round to Nitrokey
                                                  Google Titan Security Keypartialcommunity5/10

                                                  Google's own docs confirm broad FIDO/U2F and CTAP1 compatibility beyond Google services and even Advanced Protection use, implying standards-based interoperability, but no evidence explicitly names GitHub, Microsoft, or password-manager integrations. Community reports also flag real-world friction (e.g., 'You can only use Security Keys with Google Chrome' on Mac), showing cross-browser/service compatibility isn't seamless everywhere. missing for 10: explicit confirmation/testing with GitHub, Microsoft accounts, and specific password managers; resolution of the Chrome-only browser limitation reported by users.

                                                  • [claimed-docs] Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.
                                                  • [claimed-docs] If you’re a journalist, activist, or someone else at risk of targeted online attacks, you can use Titan Security Keys with the Advanced Prot…
                                                  • [claimed-docs] One security key can be used to sign in to work and personal services.
                                                  • [community] You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]
                                                  • [community] I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…
                                                  • [community] The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.
                                                  Nitrokeypartialcommunity6/10

                                                  Docs confirm FIDO2/U2F support and explicitly name Google/Facebook U2F login and Microsoft passwordless login, and general 'Two Factor Authentication' docs exist, but GitHub and password-manager compatibility are never explicitly evidenced. Community reports also note the Nitrokey 3 lagging in feature parity vs. competitors and having 'planned' rather than shipped features, raising some doubt about full protocol coverage. Missing for 10: explicit GitHub WebAuthn/U2F confirmation, password-manager (e.g. Bitwarden/1Password) compatibility evidence, and independent hands-on confirmation across these specific services.

                                                  • [claimed-docs] SSH Keys
                                                  • [claimed-docs] Login to websites (e.g. Google, Facebook) using secure One Time Passwords (OTP), U2F or ordinary static passwords.
                                                  • [claimed-docs] Forget your password to log in to Microsoft services (e.g. Office 365) and Nextcloud and use Nitrokey for passwordless login instead.
                                                  • [claimed-docs] Two Factor Authentication
                                                  • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…
                                                  • [community] My Yubikey 5 NFC rocks. Just works. I ordered a Nitrokey 3C NFC 2 years ago, never heard from them until a week ago where they said they shi…
                                                  • [community] I hesitated between both, but the nitrokey 3 has so many things listed as "planned" that I went for a Yubikey (bought a 5a NFC and a 5c NFC)…

                                                User verification

                                                1. security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

                                                  weight 2 · round drawn
                                                  Google Titan Security Keynone0/10

                                                  The evidence pack describes Titan Security Keys as simple touch-based FIDO/U2F/FIDO2 keys (USB-A/NFC, USB-C/NFC, Bluetooth) with no mention of an on-device PIN pad or biometric sensor for user verification; all sign-in flows described are 'insert/tap key' without any PIN or biometric step. Missing for 10: any documentation of a FIDO2 PIN-setting flow, a fingerprint/biometric sensor, or independent confirmation of on-device user verification.

                                                  • [claimed-docs] If you want to sign in with just your security key and skip your password when possible, you must create a passkey.
                                                  • [claimed-docs] Enroll your security key. You might need to sign in.
                                                  • [claimed-docs] Your device will detect that your account has a security key. Follow the steps to sign in using your key.
                                                  • [claimed-docs] Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.
                                                  Nitrokeynone0/10

                                                  Evidence confirms Nitrokey devices support FIDO2 and mentions 'Touch Confirmation' (a presence check), but nowhere does it document a FIDO2 PIN or biometric on-device user-verification mechanism that would block use by a mere possessor of a stolen key. Missing for 10: explicit documentation of FIDO2 PIN setup/enforcement, biometric sensor support, or any UV (user verification) flag being satisfied — only touch/presence confirmation is evidenced, which is a different, weaker security property.

                                                  • [claimed-docs] SSH Keys
                                                  • [claimed-docs] Touch Confirmation (Nitrokey 3 only)
                                                  • [claimed-docs] The Nitrokey 3 combines the features of previous Nitrokey models: FIDO2, one-time passwords, OpenPGP smart card, Curve25519, password manage…

                                                Not comparable on these axes

                                                1. ai-native userPoint an agent at llms.txt or agent-oriented docs

                                                  weight 2 · not comparable
                                                  Google Titan Security Keyn/a

                                                  Titan Security Key is a physical hardware authentication device, not an AI agent or documentation-serving platform; the concept of pointing an agent at llms.txt or agent-oriented docs is a category error for this product type.

                                                    Nitrokeynone0/10

                                                    Probes explicitly confirm no llms.txt or agent-oriented docs endpoint exists (404s), and no evidence of AI-native documentation is present anywhere in the pack.

                                                    • [probe] PROBE llms.txt: HTTP 404 at https://docs.nitrokey.com/llms.txt
                                                    • [probe] PROBE docs-md: HTTP 404 at https://docs.nitrokey.com/.md
                                                    • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                                                  • ai-native userPlug MCP servers into this product so it can use their tools

                                                    weight 3 · not comparable
                                                    Google Titan Security Keyn/a

                                                    Titan Security Key is a hardware authentication device, not an AI agent or platform capable of connecting to MCP servers or using tools; this axis is a category error for this product type.

                                                      Nitrokeyn/a

                                                      Nitrokey is a hardware security key/HSM device for authentication, encryption, and credential storage — it has no relevant role as an MCP client or agentic tool host, so plugging in MCP servers is a category error for this product.

                                                      • ai-native userConnect an agent via an official MCP server

                                                        weight 3 · not comparable
                                                        Google Titan Security Keyn/a

                                                        Titan Security Key is a hardware authentication device, not an agent or platform that could expose an MCP server; connecting AI agents via MCP is outside its product category.

                                                          Nitrokeyn/a

                                                          Nitrokey is a hardware security key/HSM device, not an AI agent or service platform that would expose an MCP server for agent connectivity; this axis is a category error for this product type.

                                                          • ai-native userIssue scoped/least-privilege API credentials for an agent

                                                            weight 2 · not comparable
                                                            Google Titan Security Keyn/a

                                                            Titan Security Key is a hardware authentication device for human 2FA/passkey login, not an API credential or agent-identity management system; issuing scoped API credentials for autonomous agents is entirely outside its product category.

                                                              Nitrokeyn/a

                                                              Nitrokey is a hardware security key/HSM product for authentication, encryption, and signing (FIDO2, OpenPGP, PIV, etc.), not an API/credential-issuing platform for AI agents. Issuing scoped API credentials for an agent is a category error for this product type.

                                                              • ai-native userSubscribe to events via webhooks

                                                                weight 2 · not comparable
                                                                Google Titan Security Keyn/a

                                                                Titan Security Key is a hardware authentication device, not a service or platform with event-driven APIs; webhook subscriptions are entirely outside its product category.

                                                                  Nitrokeyn/a

                                                                  Nitrokey is a hardware security key/HSM product; webhooks/event subscription is a SaaS/API integration concept that does not apply to this category of device.

                                                                  • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                                                    weight 2 · not comparable
                                                                    Google Titan Security Keyn/a

                                                                    Titan Security Key is a hardware authentication device, not a data/insights product; AI-generated insights from user data is a category error for this product type.

                                                                      Nitrokeyn/a

                                                                      Nitrokey is a hardware security key/authentication device (FIDO2, OpenPGP, PIV, encrypted storage); it has no data-analysis or AI-insight surface, so AI-generated insights from user data is a category error for this product type.

                                                                      • ai-native userSet up automations that run autonomously in the background

                                                                        weight 2 · not comparable
                                                                        Google Titan Security Keyn/a

                                                                        Titan Security Key is a hardware authentication device, not an agent or automation platform; setting up autonomous background automations is outside its category.

                                                                          Nitrokeyn/a

                                                                          Nitrokey is a hardware security key/HSM for authentication, encryption, and key storage — it has no automation/orchestration layer for background autonomous tasks; this axis is a category error for a security token product.

                                                                          • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                                            weight 3 · not comparable
                                                                            Google Titan Security Keyn/a

                                                                            Titan Security Key is a hardware authentication device, not an AI assistant or agent platform; delegating tasks to a built-in AI assistant is not a fair axis for this product category.

                                                                              Nitrokeyn/a

                                                                              Nitrokey is a hardware security key/HSM product for authentication, encryption, and secure key storage — it has no AI assistant feature, and delegating tasks to a built-in AI assistant is entirely outside its product category.

                                                                              • ai-native userOperate the product with natural-language commands

                                                                                weight 2 · not comparable
                                                                                Google Titan Security Keyn/a

                                                                                Titan Security Key is a hardware authentication device, not an interface that accepts natural-language commands; this axis is a category error for this product type.

                                                                                  Nitrokeyn/a

                                                                                  Nitrokey is a physical hardware security key/token operated via touch, PIN entry, and a technical CLI (nitropy) for configuration — natural-language command interaction is not a relevant axis for this class of authentication hardware.

                                                                                  • ai-native userExplore an interactive API reference with runnable examples

                                                                                    weight 2 · not comparable
                                                                                    Google Titan Security Keyn/a

                                                                                    Google Titan Security Key is a hardware authentication device, not a developer API/platform; interactive API references with runnable examples are not applicable to this product category.

                                                                                      Nitrokeynone0/10

                                                                                      Probes explicitly show no OpenAPI/interactive API reference exists (404s for openapi.json, swagger.json, etc.), and no docs mention runnable examples or an interactive API explorer despite Nitrokey having a CLI (nitropy) and Python SDK.

                                                                                      • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                                                                                      • [probe] PROBE llms.txt: HTTP 404 at https://docs.nitrokey.com/llms.txt
                                                                                      • [probe] PROBE docs-md: HTTP 404 at https://docs.nitrokey.com/.md
                                                                                      • [claimed-docs] nitropy - Nitrokey Documentation
                                                                                    • ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

                                                                                      weight 2 · not comparable
                                                                                      Google Titan Security Keyn/a

                                                                                      Titan Security Key is a hardware authentication device, not an API/service product; a machine-readable API spec is a category mismatch (wrong axis) for this kind of product.

                                                                                        Nitrokeynone0/10

                                                                                        Nitrokey is a hardware security key vendor; the probe explicitly checked for a machine-readable API spec (openapi.json, swagger.json, etc.) and all candidates returned 404, with no OpenAPI/Swagger spec documented anywhere in the evidence pack.

                                                                                        • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                                                                                      • ai-native userTest against a sandbox environment without touching production data

                                                                                        weight 1 · not comparable
                                                                                        Google Titan Security Keyn/a

                                                                                        Titan Security Key is a physical hardware authentication device, not an AI/dev platform with a sandbox vs production environment concept; this story's axis does not apply to this product category.

                                                                                          Nitrokeyn/a

                                                                                          Nitrokey is a hardware security key/HSM product for authentication, encryption, and key storage — not an AI agent, SaaS platform, or testing framework with sandbox/production data separation for AI workflows. This axis is a category error for this product type.

                                                                                          • ai-native userRely on versioned APIs with a documented deprecation policy

                                                                                            weight 2 · not comparable
                                                                                            Google Titan Security Keyn/a

                                                                                            Titan Security Key is a hardware authentication device, not an API/SDK product; the concept of versioned APIs with deprecation policy is a category error for this product type.

                                                                                              Nitrokeynone0/10

                                                                                              Nitrokey ships a versioned CLI (nitropy) and Python SDK, but there is no evidence of a documented API deprecation policy, versioned public API, or OpenAPI spec — probes explicitly show 404s for OpenAPI/llms.txt discovery. The axis applies since Nitrokey does provide developer tooling, but no deprecation-policy documentation exists in the evidence.

                                                                                              • [probe] PROBE openapi: all candidate paths 404 (https://docs.nitrokey.com/openapi.json, https://docs.nitrokey.com/swagger.json, https://docs.nitroke…
                                                                                              • [probe] PROBE llms.txt: HTTP 404 at https://docs.nitrokey.com/llms.txt
                                                                                              • [probe] PROBE runtime (recorded 2026-09-15): Nitrokey's official nitropy CLI installs keylessly from PyPI and identifies itself — `uvx --from pynitr…
                                                                                              • [claimed-docs] nitropy - Nitrokey Documentation
                                                                                            • ai-native userDefine rules that trigger actions automatically on events

                                                                                              weight 3 · not comparable
                                                                                              Google Titan Security Keyn/a

                                                                                              Titan Security Key is a hardware authentication device for 2FA/passkey sign-in; it has no automation/rules engine or event-trigger capability, and this axis is a category error for a physical security key.

                                                                                                Nitrokeyn/a

                                                                                                Nitrokey is a hardware security key/token for authentication, encryption, and key storage — not an automation/rules-engine product; defining event-triggered rules is outside its category of functionality.

                                                                                                • ai-native userSchedule recurring jobs or workflows

                                                                                                  weight 2 · not comparable
                                                                                                  Google Titan Security Keyn/a

                                                                                                  Titan Security Key is a hardware authentication device, not a workflow/automation or job-scheduling tool; scheduling recurring jobs is entirely outside its product category.

                                                                                                    Nitrokeyn/a

                                                                                                    Nitrokey is a hardware security key/token for authentication, encryption, and key storage; scheduling recurring jobs or workflows is entirely outside its product category as a physical security device.

                                                                                                    • ai-native userVersion, review, and roll back my automations

                                                                                                      weight 1 · not comparable
                                                                                                      Google Titan Security Keyn/a

                                                                                                      Titan Security Key is a hardware authentication device, not an automation/workflow platform; versioning, reviewing, or rolling back automations is not a fair capability to expect from this product category.

                                                                                                        Nitrokeyn/a

                                                                                                        Nitrokey is a hardware security key/HSM product for authentication, encryption, and key storage — it has no concept of 'automations' to version, review, or roll back; this axis belongs to workflow/agent orchestration tools, not a security token.

                                                                                                        • ai-native userChoose where my data is stored (region/residency)

                                                                                                          weight 2 · not comparable
                                                                                                          Google Titan Security Keyn/a

                                                                                                          Titan Security Key is a physical hardware authentication device, not a data storage or cloud service; data residency/region choice is not an applicable axis for this product category.

                                                                                                            Nitrokeyn/a

                                                                                                            Nitrokey is a physical hardware security key that stores secrets locally on-device; there is no cloud/regional data-residency concept applicable to this product category.

                                                                                                            • ai-native userPrevent my data from being used to train AI models

                                                                                                              weight 3 · not comparable
                                                                                                              Google Titan Security Keyn/a

                                                                                                              Titan Security Key is a hardware authentication device for account security; it has no relationship to AI training data usage or data governance controls, so this axis does not apply to this product category.

                                                                                                                Nitrokeyn/a

                                                                                                                Nitrokey is a hardware security key/HSM product for authentication, encryption, and credential storage; it has no relation to AI model training data usage or opting out of AI training, which is an entirely different product category axis.