Google Titan Security Key vs SoloKeys Solo 2
Google Titan Security Key
SoloKeys Solo 2
SoloKeys
SoloKeys Solo 2 wins · 4–17 (15 drawn)
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
Agent access
ai-native userRun the product headlessly / in CI for automation
weight 2 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2none0/10Solo 2 is a physical security key requiring human touch confirmation for every action, and while a CLI exists (solo2 list, admin commands), there's no documented support for headless/CI automation; a runtime probe shows the official CLI is bit-rotted (ImportError, incompatible fido2 dependency) with no firmware release in 4 years, further undermining any automation use case.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
ai-native userUse an official CLI
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2disputedcontradicted3/10GitHub docs show an official `solo2` CLI with scriptable commands (list, admin set led, monitor, wipe) suitable for automation, but a runtime probe found the official Solo CLI (solo-python) actually fails to run due to a dependency ImportError, and no Solo 2 firmware release has shipped in 4 years despite ongoing CI commits — concretely contradicting the claim of a working, maintained official CLI. Missing for 10: evidence of AI-agent-specific CLI usage/documentation, confirmation the solo2 (Rust) CLI itself runs cleanly, and independent corroboration beyond the vendor's own repo.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “solo monitor <serial-port>”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
ai-native userDrive the product through a documented public API
weight 3 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2none0/10Solo 2 exposes a hardware CLI (solo2 app/list) and standard protocols like FIDO2/PIV/OpenPGP, but there is no documented public REST/programmatic API for AI-driven control, and probes confirm no OpenAPI spec or llms.txt exists (404s) while the closest thing to an SDK (solo-python CLI) is reported bit-rotted and broken via ImportError. No evidence of a working, documented API surface an AI agent could drive.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
ai-native userBuild against official SDKs
weight 2 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2none0/10Evidence shows firmware-build tooling (Rust/cargo builds, solo2 CLI, customization docs) rather than an official SDK for third-party/AI-native application development, and the one CLI tool cited is reported bit-rotted and broken in 2026 (ImportError, no releases in 4 years). No client library, API reference, or SDK package is documented for developers to build against.
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] “rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
ai-native userPerform bulk operations across many items at once
weight 2 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Openpgp
developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10Titan Security Key is a FIDO/U2F authenticator with no documented OpenPGP applet or smartcard support for git commit signing or encrypted email; evidence only covers FIDO2/U2F sign-in use cases.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
SoloKeys Solo 2disputedcontradicted3/10The GitHub README lists OpenPGP as a supported protocol (solokeys-gh-1, solokeys-gh-8), which would enable git commit signing and encrypted email use cases, but community comments directly contradict this — users report 'it doesn't do OpenPGP' and 'I'm really hoping they bring GPG to the Solokey... but I'm starting to lose confidence' (solokeys-comm-2, solokeys-comm-4). There is no first-party documentation walking through GPG key generation, git signing setup, or email encryption workflows, and no independent hands-on confirmation that OpenPGP actually works on shipped hardware. Missing for 10: verified working OpenPGP applet on shipped Solo 2 units, official docs for GPG/git-signing setup, and independent confirmation resolving the community's contradicting reports.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [community] “Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …”
- [community] “I'm really hoping they bring GPG to the Solokey V1, but I'm starting to lose confidence”
Otp
power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10Titan Security Key is a FIDO/U2F/WebAuthn hardware authenticator; no evidence indicates it supports TOTP/HOTP seed storage or generic challenge-response slots for legacy OTP services. All documentation focuses on FIDO CTAP1/U2F/WebAuthn use cases only.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
GitHub docs explicitly state Solo 2 speaks OATH (TOTP/HOTP) in addition to FIDO2/WebAuthn, PIV, and OpenPGP, directly supporting legacy OTP slot functionality. However, missing for 10: no CLI/setup walkthrough for configuring TOTP/HOTP slots, no independent hands-on confirmation the OATH applet works reliably, and a runtime probe shows the official Solo CLI has bit-rotted (import errors) and firmware hasn't been updated in years, raising doubts about current usability.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Piv
it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10Evidence only covers FIDO/U2F/FIDO2 authentication (Google Sign-In, CTAP1 sites, Advanced Protection) — no mention of PIV smart card mode, certificate-based login, workstation sign-in via smart card, VPN client certs, or code-signing use cases.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
GitHub docs confirm Solo 2 'speaks... PIV' alongside FIDO2/OATH/OpenPGP, supporting the core claim that certificate-based smart-card auth is possible, but there is no vendor documentation on PIV provisioning, workstation/VPN sign-in setup, or code-signing workflows, and a runtime probe shows the official CLI is bit-rotted and firmware hasn't shipped a release in 4 years, raising doubt about current enterprise usability. Missing for 10: PIV certificate enrollment/management docs, workstation/VPN sign-in integration guides, code-signing workflow evidence, and confirmation the PIV applet still functions with current tooling.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Ssh
developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The evidence pack covers only FIDO2/U2F use for Google/web sign-in, Bluetooth pairing, NFC, and physical hardware details — there is no mention of sk-ssh, PIV, OpenPGP, or any SSH-key hardware-backing capability. missing for 10: sk-ssh/FIDO2 SSH key support, PIV applet, OpenPGP applet, any developer SSH workflow documentation.
SoloKeys Solo 2disputedcontradicted4/10GitHub docs assert the device 'speaks OATH (TOTP/HOTP), PIV, and OpenPGP' alongside its core FIDO2/WebAuthn support, which would in principle back sk-ssh (FIDO2), PIV, and GPG-based SSH keys — but a community commenter on the same Solo2 announcement explicitly states 'it doesn't do OpenPGP,' and an independent runtime probe shows the official solo-python CLI is broken (ImportError with current python-fido2) and firmware hasn't shipped since 2022, casting doubt that these advertised protocols are actually usable today for SSH auth. Missing for 10: explicit sk-ssh/PIV/OpenPGP SSH-key setup documentation, working current CLI/firmware evidence, and resolution of the OpenPGP support contradiction.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [community] “Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
Agent audit
ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
The Solo 2 CLI exposes some device-state commands (`solo2 list` for connected devices/serials, `solo2 app admin ...` for config) suggesting basic programmatic querying, but there is no evidence of commands to enumerate firmware version, enabled applications, or stored credentials for fleet auditing. A runtime probe also shows the official Python CLI tooling (solo-python) is broken due to dependency incompatibility, undermining reliability of programmatic access. missing for 10: documented API/CLI output for firmware version and enabled-app enumeration, credential enumeration, a working/maintained CLI tool, any structured/machine-readable output format for fleet-scale auditing.
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Attestation
security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled
weight 2 · round to SoloKeys Solo 2Google Titan Security Keydisputedcontradicted3/10Docs claim the key's hardware chip/firmware 'verifies that the keys haven't been tampered with' and provides 'cryptographic proof' of legitimate registration (google-titan-docs-12, docs-14, docs-20), which gestures at attestation, but there is no documentation or tooling aimed at security engineers for inspecting attestation certificates or enforcing an approved-model allowlist at registration. A hands-on report directly undercuts the 'genuine, approved model' framing: a user's non-Google Feitian MultiPass key (identical hardware to Titan) was accepted by Google's own replacement/registration system as if it were an official Titan key, showing the attestation/verification does not reliably distinguish genuine Titan units from rebranded third-party hardware (google-titan-comm-12, comm-14). Missing for 10: security-engineer-facing attestation verification API/metadata service, documented enforcement of approved key models, and any first-party/independent confirmation that model spoofing is prevented.
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …”
- [community] “I got one of Google's Advanced Protection kits, which included two keys that look exactly like the Titan keys in the article. Both are Feiti…”
The docs confirm Solo 2 ships with a factory attestation key and even allow customizing/generating your own attestation key pair for bulk deployment, implying WebAuthn/FIDO2 attestation is present in principle. However there is no documentation of a FIDO Alliance MDS listing, stable AAGUID, or any RP-side verification workflow that a security engineer could use to confirm the device model at registration — and the ability to swap the attestation key yourself could actually undermine trust in a fixed identity. missing for 10: MDS/AAGUID metadata for RP verification, documented attestation-cert chain details, guidance for enterprises on enforcing genuine-model checks, independent confirmation that registration-time attestation works as expected.
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
Cli
developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
weight 3 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2disputedcontradicted3/10Docs and GitHub show a `solo2` CLI with some admin commands (`solo2 list`, `solo2 app admin set led`, firmware `update`) but no documented commands for setting PINs or managing slots, and reading device state relies on generic third-party `fido2-token` rather than a Solo-specific command. A runtime probe found the official Solo CLI (solo-python) actually fails to even run (`ImportError: cannot import name CTAP1`) due to incompatibility with current fido2 2.x, and firmware hasn't been released in 4 years — concrete evidence the tooling has bit-rotted rather than delivering the claimed scriptable management. missing for 10: working PIN-setting command, slot management, device-state reporting, and a CLI that runs without import errors on current dependencies.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Sdks
developerOfficial SDKs let me integrate the key into my own desktop and mobile apps
weight 2 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2none0/10Evidence shows only a device-management CLI (solo2 app admin/list) and firmware-building/customization tooling for the key itself, not any SDK for embedding the key into third-party desktop or mobile applications. The runtime probe even shows the existing Solo Python CLI is broken/bit-rotted, and no library/SDK for app integration is documented anywhere in the pack.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Agent approval
ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
weight 1 · round to SoloKeys Solo 2Google Titan Security Keynone0/10Evidence only shows Titan Security Key being used for standard account sign-in / 2-Step Verification via FIDO/U2F, with no mention of any API, SDK, or workflow that lets an AI agent request a physical-touch approval gate for its own automated actions. Nothing in the docs or community discussion ties the key's touch requirement to agent-initiated or automated action approval.
- [claimed-docs] “Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.”
- [claimed-docs] “Titan Security Keys provide cryptographic proof that users are interacting with the legitimate service that they originally registered their…”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
Solo 2 documents a generic touch-to-confirm step for WebAuthn/FIDO2 authentication (solokeys-docs-1), which could theoretically gate any human-in-the-loop confirmation, but there is no evidence tying this to AI-agent-initiated action approval flows, agentic tool integrations, or any AI-native ecosystem support. Additionally, runtime evidence shows the official CLI is broken/bit-rotted and firmware hasn't shipped in 4 years, raising doubts about active ecosystem maintenance. Missing for 10: any documentation or integration example of using Solo 2 touch confirmation as an approval gate for AI/agent workflows, evidence of SDK/API hooks for agent tooling, and independent confirmation of this use case.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Compatibility
power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services
weight 2 · round to SoloKeys Solo 2Google Titan Security Keydisputedcontradicted4/10Google's docs claim broad cross-platform support (Android/iOS NFC, Linux setup via udev, FIDO CTAP1 compatibility with third-party sites) but there is no published catalog of specific supported services/sites—just a generic FIDO-standard compatibility statement. Community reports directly contradict smooth cross-browser/OS support: one user found keys 'only' worked with Chrome and failed on Mac despite official docs, while others reported success with Firefox on Linux and pairing issues on Mac, showing inconsistent real-world compatibility. missing for 10: an actual published list/catalog of compatible services, and confirmation that browser/OS support claims hold up without conflicting user reports.
- [claimed-docs] “Works with compatible Android and iOS devices through NFC”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…”
- [community] “The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.”
- [community] “I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…”
Solo 2 claims broad compatibility (any USB port, no drivers, FIDO2/passkey standard, NFC for Android/iOS, OATH/PIV/OpenPGP) but there is no published compatibility catalog listing specific supported services/sites, and a runtime probe shows the official CLI tooling has bit-rotted and firmware hasn't been updated in years, raising doubts about maintained cross-platform support. Missing for 10: a published service/site compatibility list, browser-specific compatibility documentation, and evidence the tooling/firmware is actively maintained to keep pace with OS/browser changes.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Recovery
security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
weight 3 · round to Google Titan Security KeyGoogle docs cover removing a lost key from an account (google-titan-docs-9) and enrolling a security key (google-titan-docs-15), and a community comment notes Google's own guidance to keep one key in daily use and store a backup safely (google-titan-comm-3), implying an informal backup-key strategy. However there is no first-party documentation laying out a full lockout-recovery plan (e.g., how to regain account access before removing the key, what happens if the only registered key is lost, or explicit backup-key enrollment steps). missing for 10: explicit vendor doc on account lockout scenarios, dedicated backup-key enrollment walkthrough, and clarity on what is/isn't recoverable if the sole key is lost
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [community] “Is it possible to use the Bluetooth dongle with a desktop computer without a cable? Having to carry both on your keyring kind of defeats the…”
- [community] “Pretty cool, I like that it comes with two keys at the start so you have a backup, unlike Yubi where I have to buy two before I can even get…”
Setup
power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
weight 2 · round to Google Titan Security KeyGoogle's support docs give step-by-step guided enrollment (sign in, 'Enroll your security key', device detects it and walks through sign-in) and cover related setup nuances like Linux udev rules and NFC/Bluetooth pairing, but there is no dedicated setup app—just web help pages. Community reports also note friction during first-time use (Chrome-only compatibility issues, Bluetooth key not pairing with Mac), suggesting the guided flow isn't universally smooth across platforms/browsers. Missing for 10: a purpose-built setup wizard/app, cross-browser first-run guidance, and independent confirmation that the documented steps work smoothly on all platforms.
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
- [claimed-docs] “Security keys can be used with 2-Step Verification to help you keep hackers out of your Google Account.”
- [claimed-docs] “To set up a Titan Security Key on a computer running a Linux-based operating system, you may need to add a new udev rule.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I have the Feitan BLE key... You'd think you could wirelessly use the Bluetooth key with a laptop, but you can't. You need to connect a Micr…”
Docs mention simple plug-and-play basics ('insert into USB port, no software required', 'touch sensor to confirm') but there is no evidence of a dedicated setup app or step-by-step account-registration walkthrough; the FIDO2 side of onboarding is essentially per-website. Additionally, a runtime probe shows the official companion CLI is bit-rotted (import errors) and firmware hasn't been updated in years, undermining confidence in any first-time-setup tooling. Missing for 10: a documented onboarding wizard/app, account-registration walkthrough for accounts, working companion CLI/tooling.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Source
security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10Google explicitly states firmware is 'developed by Google' and used to verify tamper-resistance, but there is no evidence of open-source firmware or independent third-party audit reports; community evidence only discusses hardware manufacturing (Feitian OEM) and a Bluetooth vulnerability, not firmware transparency/auditing. missing for 10: any published audit report, open-source firmware repository, or independent verification of firmware code.
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…”
The Solo 2 firmware is openly published on GitHub, buildable from source, and the 'Hacker' variant explicitly supports flashing custom firmware, letting anyone inspect and verify what runs on the device; this is corroborated by community commentary confirming 'it's open source firmware, not open source hardware.' Updates are also SHA-256 verified before flashing, adding transparency to the update process. missing for 10: no formal independent third-party security audit is cited, and runtime evidence shows the firmware/tooling has not been updated since 2022, raising questions about ongoing maintenance of the open codebase.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [github] “`update` downloads the signed release, **verifies its SHA-256**, and flashes it.”
- [community] “This is an LPC55S69. So it's open source firmware, not open source hardware.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Updates
security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
weight 2 · round to Google Titan Security KeyThere is concrete real-world evidence of one incident: a BLE pairing vulnerability was disclosed, Google emailed affected users ('Update on your Titan Security Key') and ran a replacement program rather than a firmware patch, showing some vulnerability-response process exists but it worked through physical device replacement, not an in-field firmware update, and users found the replacement process cumbersome. There is no published advisory list/CVE tracker or affected-model lookup tool in the evidence — docs only vaguely mention Google-engineered firmware for tamper verification. Missing for 10: a public security-advisory/CVE page, a documented affected-model/serial lookup tool, and an actual firmware-update delivery mechanism (evidence shows fixes require full device replacement, not a firmware push).
- [claimed-docs] “A hardware chip that includes firmware developed by Google helps to verify that the keys haven’t been tampered with.”
- [claimed-docs] “Titan Security Keys are built with a hardware chip that includes firmware engineered by Google to verify the key’s integrity.”
- [community] “Security issue: Once paired, an attacker in close physical proximity could use their device to masquerade as your affected Bluetooth securit…”
- [community] “Not the most user-friendly replacement process here, Google. First I had to chat with a representative... Now I need to place a 'replacement…”
- [community] “The replacement site worked by sending me to a contact form where I had to chat with a representative then wait for an email to initiate an …”
- [community] “I use the Feitian Multipass that I bought from Amazon before Titan Keys were available... This morning I received the 'Update on your Titan …”
SoloKeys Solo 2disputedcontradicted3/10The GitHub docs describe a signed, SHA-256-verified update mechanism (solokeys-gh-2), but there is no evidence of published security advisories or an affected-model lookup, and a runtime probe shows the official CLI is bit-rotted (ImportError against current fido2 lib) and no firmware release has shipped in ~4 years despite ongoing dependency commits — directly undercutting the claim that fixes reliably reach devices. missing for 10: security advisory feed/CVE list, affected-model/version lookup tool, evidence of recent firmware releases actually reaching users, working update tooling.
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Agent provisioning
ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
weight 2 · round drawnGoogle Titan Security Keynone0/10This is a hardware security key with human-driven web console setup (enroll, pair, reset) via support docs; there is no evidence of any enterprise API for agent-driven ordering, assignment, or pre-registration of keys. missing for 10: documented provisioning/management API, evidence of programmatic ordering or fleet assignment, any agent/automation-facing endpoint.
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
SoloKeys Solo 2none0/10There is no evidence of any enterprise/fleet management API for ordering, assignment, or pre-registration of keys — the CLI is a local hardware management tool (list, flash, LED), and probe evidence shows no OpenAPI/API docs exist and the CLI itself is bit-rotted. This is a consumer/hacker hardware key product with no enterprise provisioning system at all.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
Delivery
it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
weight 2 · round drawnGoogle Titan Security Keynone0/10No evidence of any bulk-shipping logistics, distribution API, admin console, or fleet-provisioning workflow for shipping keys to distributed employees; evidence covers only individual key setup, replacement RMA process, and hardware/community feedback.
SoloKeys Solo 2none0/10No evidence of any enterprise provisioning/shipping API, console, or fleet-deployment logistics integration; SoloKeys is a consumer hardware key sold via a Shopify store with no fleet-management tooling documented, and CLI/API evidence is limited to device-local admin commands and firmware building. Probes even show bit-rot in the CLI and no API/OpenAPI documentation exists.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [claimed-docs] “Pack of colored cases for Solo 2”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
Idp
it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
weight 2 · round drawnGoogle Titan Security Keynone0/10The evidence pack covers consumer/personal account setup, Bluetooth pairing, form factors, and hardware attestation, but contains no evidence of IT-admin-facing integration with identity providers like Okta, Entra ID, or Google Workspace admin console policy enforcement for hardware-key-only authentication. This is a fair axis for a hardware security key vendor to address (fleet policy enforcement via IdP), but no such capability or documentation is present.
SoloKeys Solo 2none0/10No evidence anywhere in the pack mentions IdP integrations (Okta, Entra ID, Google Workspace), fleet enrollment/management tools, or policy enforcement for hardware-key authentication; evidence only covers WebAuthn/FIDO2 protocol support, firmware building, and hardware details. This is a plausible axis for a security key vendor (many competitors offer admin/fleet consoles), but SoloKeys shows nothing to support it.
Provisioning
it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
weight 3 · round drawnGoogle Titan Security Keynone0/10Evidence covers individual end-user setup, pairing, resetting, and removing a single key, but nothing addresses IT-admin fleet capabilities like bulk pre-registration, centralized provisioning, or lifecycle/inventory tracking across an organization. Missing for 10: bulk enrollment tools/API, admin console integration for mass key registration, and lifecycle/inventory tracking dashboards.
SoloKeys Solo 2none0/10Evidence covers individual key setup, CLI device listing/config (`solo2 list`, `admin set led`), and custom attestation-key generation, with one offhand mention of building attestation keys 'for maybe 100,000 devices'—but there is no documented bulk-enrollment workflow, admin console, pre-registration pipeline, or lifecycle/issuance tracking system for organizations. Runtime probes further show the official CLI is broken (ImportError) and no firmware has shipped in 4 years, undercutting any claim of active enterprise tooling.
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certifications
it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
weight 2 · round drawnGoogle Titan Security Keynone0/10The evidence pack contains no mention of FIPS 140 validation or Common Criteria certification for Titan Security Keys, nor documented water/crush resistance specs; in fact, one community report suggests the underlying Feitian hardware is fragile if dropped, contradicting any durability certification claim. missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, official durability/water-crush resistance specs.
- [community] “The wireless key is the Feitian MultiPass FIDO Security Key. I'd caution people to read the Amazon reviews (specifically people found it unr…”
SoloKeys Solo 2none0/10No evidence of FIPS 140 validation or Common Criteria certification anywhere in the pack; only a community comment mentions 'water resistant' informally (solokeys-comm-7), and another comment casts doubt on tamper-resistance claims (solokeys-comm-1). No documented crush resistance or regulated-environment certification exists.
- [community] “Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…”
- [community] “I'm still curious how the key is tamper resistent when filling it with transparent epoxy... it should be fairly easy to remove the epoxy and…”
Connectors
power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
weight 2 · round to Google Titan Security KeyDocs confirm two form factors—USB-A/NFC and USB-C/NFC—but there is no evidence of a keychain or nano low-profile model, and community feedback even calls the (Bluetooth) key large rather than low-profile. missing for 10: keychain form factor, nano/low-profile form factor, independent hands-on confirmation of size/portability across the full claimed lineup.
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
- [community] “It's so big. Couldn't they have come up with a more subtle form factor?”
SoloKeys Solo 2none0/10Evidence shows Solo 2 exists as a security key with NFC variant and generic USB port compatibility, and community comments mention a 'reversible USB-A'/'reversible usb plug', but there is no evidence of a broader lineup with distinct USB-C vs USB-A SKUs or keychain vs low-profile nano form factors — only a single case/color accessory line is mentioned.
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [community] “"Reversible USB-A" now there's a feature I wish we'd see more often!”
- [community] “Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…”
- [claimed-docs] “Pack of colored cases for Solo 2”
Nfc
power userTap the key on my phone over NFC to authenticate in mobile browsers and apps
weight 2 · round drawnDocs confirm the USB-A/NFC and USB-C/NFC key models work over NFC with compatible Android and iOS devices (iOS 13.3+), covering mobile browser/app authentication. Missing for 10: independent hands-on confirmation of NFC tap-to-auth specifically in third-party mobile apps (community evidence focuses mainly on Bluetooth/desktop use, not NFC mobile app flows).
- [claimed-docs] “Works with compatible Android and iOS devices through NFC”
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
- [claimed-docs] “iPhones with iOS version 13.3 or up | Yes | Yes”
SoloKeys explicitly markets NFC tap-to-authenticate for compatible Android and iOS devices as a feature of Solo 2, supporting WebAuthn/passkeys which work across mobile browsers/apps. Missing for 10: no independent hands-on confirmation of NFC mobile browser/app compatibility, and community discussion focuses on other aspects (tamper resistance, OpenPGP) rather than validating NFC mobile use.
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
ai-native userDo everything through the API that I can do in the UI
weight 2 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userExport all of my data in open formats and leave
weight 3 · round drawnGoogle Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
SoloKeys Solo 2none0/10The evidence pack shows Solo 2 supports open standards (WebAuthn, OATH, PIV, OpenPGP) and lets users customize/replace the attestation key or wipe the device, but there is no documentation of any way to export stored credentials/private key material in open formats to migrate elsewhere — by design, FIDO2/PIV/OpenPGP keys generated on-device are non-extractable. missing for 10: any documented data-export/migration path, evidence of extractable key material, or open-format backup/portability tooling.
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
ai-native userRead the product's source under an open license
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
The firmware source is hosted openly on GitHub (solokeys/solo2), with build instructions, hackable firmware flashing, and even a dedicated 'Hacker' key edition explicitly for reading/modifying source and firmware end-to-end. Community confirms firmware is open source (though hardware/chip is not), corroborating the licensing model. Missing for 10: no explicit license file/name cited, and no independent audit of license terms beyond community mention that firmware (not hardware) is open.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [community] “This is an LPC55S69. So it's open source firmware, not open source hardware.”
ai-native userSelf-host the core product
weight 3 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
The Solo 2 'Hacker' edition ships with fully open-source firmware that users can build, flash, and customize themselves (own attestation keys, own firmware, full toolchain via Rust/cargo), which is the closest analogue to 'self-hosting' for a hardware security key — no cloud dependency by design. However, runtime evidence shows the surrounding tooling has bit-rotted (solo-python CLI fails on current fido2 libs) and no firmware release has shipped in 4 years, undermining confidence that self-building/self-hosting the core product is currently practical. Missing for 10: a working, up-to-date official build/flash pipeline, and independent confirmation that a user can successfully self-build current firmware today.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] “rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [claimed-docs] “cargo build --release --features board-lpcxpresso55,develop”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
ai-native userControl data retention and deletion
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Evidence shows credentials are stored only on-device rather than in a vendor cloud (solokeys-docs-2), and a device wipe is possible via the third-party `fido2-token -R` command (solokeys-docs-10), giving users some control over deletion. However, this is not a first-party, documented retention/deletion feature — it's a generic FIDO2 tool tip buried in a GitHub releases page, with no official SoloKeys documentation on data retention policy or granular per-credential deletion. Missing for 10: native SoloKeys CLI/tool for credential management and wipe, official retention policy documentation, and independent confirmation the wipe command works reliably.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
ai-native userOpt out of telemetry and usage tracking
weight 2 · round to SoloKeys Solo 2Google Titan Security Keynone0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Solo 2 is explicitly marketed as working entirely locally ('stays on your key, not their cloud', no software/drivers required), which implies no cloud usage-tracking to opt out of, but there is no explicit telemetry policy, settings, or opt-out control documented for the CLI/companion tooling. missing for 10: explicit telemetry/privacy policy statement, any opt-out toggle or setting, confirmation that the solo2 CLI/companion app sends no usage analytics.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “No more sticky notes. No more forgotten passwords. No more texts with six digit codes.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Credential management
power userList and delete the passkeys stored on my key and know its credential capacity before it fills up
weight 2 · round drawnGoogle Titan Security Keynone0/10The evidence covers removing a key from a Google account and unpairing Bluetooth, but there is no mention of an on-key credential management tool that lists or deletes individual passkeys stored on the Titan key itself, nor any documentation of the key's credential storage capacity or warnings about it filling up.
- [claimed-docs] “If you lose your key or decide you don’t want to use it anymore, you can remove it from your account.”
- [claimed-docs] “If you want to stop using a Bluetooth Titan Security Key with one or more devices, you can unpair the key.”
SoloKeys Solo 2none0/10No evidence describes per-passkey listing, deletion, or credential-capacity reporting; the only related CLI ops shown are `solo2 list` (lists connected devices, not credentials) and `fido2-token -R` (wipes the entire key, not selective deletion). Additionally, a runtime probe shows the official CLI is now broken (ImportError against modern fido2 libs), further undermining any credential-management workflow.
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Fido2
security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
weight 3 · round to SoloKeys Solo 2Docs confirm passkey creation for Google Accounts (implying a discoverable, device-bound credential that lets sign-in without typing a password) via google-titan-docs-2, but the same docs explicitly describe third-party site support only via 'FIDO CTAP1 standards' (google-titan-docs-4), which does not guarantee resident-key/FIDO2 support broadly. No explicit mention of FIDO2/CTAP2 or 'discoverable credentials' terminology anywhere in the pack. Missing for 10: explicit FIDO2/CTAP2 protocol documentation, direct mention of resident/discoverable credentials, and independent verification of username-less sign-in across non-Google WebAuthn services.
- [claimed-docs] “If you want to sign in with just your security key and skip your password when possible, you must create a passkey.”
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
Solo 2 is marketed explicitly as a passkey/WebAuthn security key that stores credentials on-device rather than in a cloud, and general FIDO2 passkey support inherently implies discoverable/resident credentials for usernameless sign-in ([solokeys-docs-2], [solokeys-docs-9], [solokeys-gh-1]). Missing for 10: explicit documentation of resident-key storage limits/technical FIDO2 conformance details, and independent hands-on confirmation of a usernameless login flow (only marketing copy corroborates this).
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “No more sticky notes. No more forgotten passwords. No more texts with six digit codes.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
weight 2 · round to SoloKeys Solo 2Google's own docs confirm broad FIDO/U2F and CTAP1 compatibility beyond Google services and even Advanced Protection use, implying standards-based interoperability, but no evidence explicitly names GitHub, Microsoft, or password-manager integrations. Community reports also flag real-world friction (e.g., 'You can only use Security Keys with Google Chrome' on Mac), showing cross-browser/service compatibility isn't seamless everywhere. missing for 10: explicit confirmation/testing with GitHub, Microsoft accounts, and specific password managers; resolution of the Chrome-only browser limitation reported by users.
- [claimed-docs] “Along with Google and Google Cloud services, you can use Titan Security Keys on other sites that support FIDO CTAP1 standards.”
- [claimed-docs] “If you’re a journalist, activist, or someone else at risk of targeted online attacks, you can use Titan Security Keys with the Advanced Prot…”
- [claimed-docs] “One security key can be used to sign in to work and personal services.”
- [community] “You can only use your Security Keys with Google Chrome. [error trying to authenticate Google account with U2F keys on Mac]”
- [community] “I got these at a Google thing at DEF CON. Both work with Firefox on Linux, without any Google software. Haven't yet found non-Google softwar…”
- [community] “The Feitian works just fine with the latest Firefox builds. The bluetooth functionality is great if you have an iPhone.”
Solo 2 is a standard WebAuthn/FIDO2/U2F device that would work with any relying party supporting those standards (Google, GitHub, Microsoft, many password managers), and vendor docs confirm FIDO2/passkey and U2F-style support plus broad protocol coverage (OATH, PIV, OpenPGP). However there is no explicit first-party or independent testing evidence confirming compatibility with each named service, and a runtime probe shows the companion CLI tooling has bit-rotted with no firmware update in 4 years, raising doubts about ongoing maintenance/compatibility. Missing for 10: explicit per-service (Google/GitHub/Microsoft/password manager) compatibility confirmation, independent hands-on verification across these services, and evidence of active firmware maintenance to keep pace with protocol changes.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
User verification
security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
weight 2 · round drawnGoogle Titan Security Keynone0/10The evidence pack describes Titan Security Keys as simple touch-based FIDO/U2F/FIDO2 keys (USB-A/NFC, USB-C/NFC, Bluetooth) with no mention of an on-device PIN pad or biometric sensor for user verification; all sign-in flows described are 'insert/tap key' without any PIN or biometric step. Missing for 10: any documentation of a FIDO2 PIN-setting flow, a fingerprint/biometric sensor, or independent confirmation of on-device user verification.
- [claimed-docs] “If you want to sign in with just your security key and skip your password when possible, you must create a passkey.”
- [claimed-docs] “Enroll your security key. You might need to sign in.”
- [claimed-docs] “Your device will detect that your account has a security key. Follow the steps to sign in using your key.”
- [claimed-docs] “Titan Security Keys are available in two form factors: USB-A/NFC and USB-C/NFC.”
SoloKeys Solo 2none0/10Evidence only shows a capacitive touch sensor for user presence confirmation (solokeys-docs-1), which is a presence test, not FIDO2 user verification via PIN or biometric. No documentation or community evidence mentions a settable FIDO2 PIN or biometric sensor on Solo 2, so the specific 'stolen key alone cannot authenticate' verification story is unevidenced.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
Not comparable on these axes
ai-native userPoint an agent at llms.txt or agent-oriented docs
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a physical hardware authentication device, not an AI agent or documentation-serving platform; the concept of pointing an agent at llms.txt or agent-oriented docs is a category error for this product type.
SoloKeys Solo 2none0/10Explicit probes confirm docs.solokeys.dev has no llms.txt (404) and no openapi/markdown-alternative endpoints; the only llms.txt found is a generic Shopify shopping-agent file unrelated to technical/product documentation, so there is no agent-oriented documentation to point an AI agent at.
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
ai-native userPlug MCP servers into this product so it can use their tools
weight 3 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an AI agent or platform capable of connecting to MCP servers or using tools; this axis is a category error for this product type.
ai-native userConnect an agent via an official MCP server
weight 3 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an agent or platform that could expose an MCP server; connecting AI agents via MCP is outside its product category.
ai-native userIssue scoped/least-privilege API credentials for an agent
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device for human 2FA/passkey login, not an API credential or agent-identity management system; issuing scoped API credentials for autonomous agents is entirely outside its product category.
ai-native userSubscribe to events via webhooks
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not a service or platform with event-driven APIs; webhook subscriptions are entirely outside its product category.
ai-native userGet AI-generated insights and suggestions from my data inside the product
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not a data/insights product; AI-generated insights from user data is a category error for this product type.
ai-native userSet up automations that run autonomously in the background
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an agent or automation platform; setting up autonomous background automations is outside its category.
ai-native userDelegate tasks to a built-in AI assistant inside the product
weight 3 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an AI assistant or agent platform; delegating tasks to a built-in AI assistant is not a fair axis for this product category.
ai-native userOperate the product with natural-language commands
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an interface that accepts natural-language commands; this axis is a category error for this product type.
ai-native userExplore an interactive API reference with runnable examples
weight 2 · not comparableGoogle Titan Security Keyn/aGoogle Titan Security Key is a hardware authentication device, not a developer API/platform; interactive API references with runnable examples are not applicable to this product category.
SoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key with a CLI/firmware toolchain, not an API/SaaS product; there is no API surface for which an interactive reference with runnable examples would be a meaningful offering. The probes confirm no OpenAPI/API docs exist, but this reflects the product category, not a missing capability.
ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an API/service product; a machine-readable API spec is a category mismatch (wrong axis) for this kind of product.
SoloKeys Solo 2none0/10SoloKeys is a hardware security key with a CLI and firmware documentation, not an API/web service; a machine-readable OpenAPI spec would be a fair thing to ask for if it exposed a network API, but probes explicitly show no OpenAPI/swagger spec exists at any candidate path and no llms.txt for the technical docs.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
ai-native userTest against a sandbox environment without touching production data
weight 1 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a physical hardware authentication device, not an AI/dev platform with a sandbox vs production environment concept; this story's axis does not apply to this product category.
ai-native userRely on versioned APIs with a documented deprecation policy
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an API/SDK product; the concept of versioned APIs with deprecation policy is a category error for this product type.
SoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key that implements standard protocols (FIDO2/WebAuthn, OATH, PIV, OpenPGP); it is not an API-driven service or SDK for which a versioned API deprecation policy would be a meaningful axis. This story is a category error for this product type.
ai-native userDefine rules that trigger actions automatically on events
weight 3 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device for 2FA/passkey sign-in; it has no automation/rules engine or event-trigger capability, and this axis is a category error for a physical security key.
ai-native userSchedule recurring jobs or workflows
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not a workflow/automation or job-scheduling tool; scheduling recurring jobs is entirely outside its product category.
ai-native userVersion, review, and roll back my automations
weight 1 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device, not an automation/workflow platform; versioning, reviewing, or rolling back automations is not a fair capability to expect from this product category.
ai-native userChoose where my data is stored (region/residency)
weight 2 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a physical hardware authentication device, not a data storage or cloud service; data residency/region choice is not an applicable axis for this product category.
SoloKeys Solo 2n/aSolo 2 is a local hardware security key whose keys never leave the device ('stays on your key, not their cloud') — there is no cloud data storage or region selection concept applicable to this product category.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
ai-native userPrevent my data from being used to train AI models
weight 3 · not comparableGoogle Titan Security Keyn/aTitan Security Key is a hardware authentication device for account security; it has no relationship to AI training data usage or data governance controls, so this axis does not apply to this product category.