SoloKeys Solo 2 vs Feitian FIDO Keys
SoloKeys Solo 2
SoloKeys
Feitian FIDO Keys
Feitian Technologies
SoloKeys Solo 2 wins · 12–11 (15 drawn)
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
Agent access
ai-native userPoint an agent at llms.txt or agent-oriented docs
weight 2 · round drawnSoloKeys Solo 2none0/10Explicit probes confirm docs.solokeys.dev has no llms.txt (404) and no openapi/markdown-alternative endpoints; the only llms.txt found is a generic Shopify shopping-agent file unrelated to technical/product documentation, so there is no agent-oriented documentation to point an AI agent at.
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
Feitian FIDO Keysnone0/10Feitian is a hardware FIDO key vendor with no evidence of an llms.txt or agent-oriented documentation; probes explicitly show 404s for llms.txt, markdown docs, and OpenAPI endpoints.
ai-native userRun the product headlessly / in CI for automation
weight 2 · round drawnSoloKeys Solo 2none0/10Solo 2 is a physical security key requiring human touch confirmation for every action, and while a CLI exists (solo2 list, admin commands), there's no documented support for headless/CI automation; a runtime probe shows the official CLI is bit-rotted (ImportError, incompatible fido2 dependency) with no firmware release in 4 years, further undermining any automation use case.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
ai-native userUse an official CLI
weight 2 · round to SoloKeys Solo 2SoloKeys Solo 2disputedcontradicted3/10GitHub docs show an official `solo2` CLI with scriptable commands (list, admin set led, monitor, wipe) suitable for automation, but a runtime probe found the official Solo CLI (solo-python) actually fails to run due to a dependency ImportError, and no Solo 2 firmware release has shipped in 4 years despite ongoing CI commits — concretely contradicting the claim of a working, maintained official CLI. Missing for 10: evidence of AI-agent-specific CLI usage/documentation, confirmation the solo2 (Rust) CLI itself runs cleanly, and independent corroboration beyond the vendor's own repo.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “solo monitor <serial-port>”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
ai-native userDrive the product through a documented public API
weight 3 · round drawnSoloKeys Solo 2none0/10Solo 2 exposes a hardware CLI (solo2 app/list) and standard protocols like FIDO2/PIV/OpenPGP, but there is no documented public REST/programmatic API for AI-driven control, and probes confirm no OpenAPI spec or llms.txt exists (404s) while the closest thing to an SDK (solo-python CLI) is reported bit-rotted and broken via ImportError. No evidence of a working, documented API surface an AI agent could drive.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
Feitian FIDO Keysnone0/10Feitian FIDO Keys are hardware authentication devices with no documented public API for programmatic/agentic control; probes for llms.txt, docs-md, and OpenAPI specs all returned 404, and no evidence describes any API surface for AI agents to drive.
ai-native userBuild against official SDKs
weight 2 · round drawnSoloKeys Solo 2none0/10Evidence shows firmware-build tooling (Rust/cargo builds, solo2 CLI, customization docs) rather than an official SDK for third-party/AI-native application development, and the one CLI tool cited is reported bit-rotted and broken in 2026 (ImportError, no releases in 4 years). No client library, API reference, or SDK package is documented for developers to build against.
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] “rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
Api quality
ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)
weight 2 · round drawnSoloKeys Solo 2none0/10SoloKeys is a hardware security key with a CLI and firmware documentation, not an API/web service; a machine-readable OpenAPI spec would be a fair thing to ask for if it exposed a network API, but probes explicitly show no OpenAPI/swagger spec exists at any candidate path and no llms.txt for the technical docs.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt”
- [probe] “PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…”
Feitian FIDO Keysnone0/10Feitian's FIDO key documentation covers WebAuthn/FIDO2 standards and setup guides but no OpenAPI/Swagger spec is published; explicit probes for llms.txt, docs-md, and openapi.json all returned 404.
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
ai-native userPerform bulk operations across many items at once
weight 2 · round drawnSoloKeys Solo 2none0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido
What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH
Openpgp
developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email
weight 2 · round to SoloKeys Solo 2SoloKeys Solo 2disputedcontradicted3/10The GitHub README lists OpenPGP as a supported protocol (solokeys-gh-1, solokeys-gh-8), which would enable git commit signing and encrypted email use cases, but community comments directly contradict this — users report 'it doesn't do OpenPGP' and 'I'm really hoping they bring GPG to the Solokey... but I'm starting to lose confidence' (solokeys-comm-2, solokeys-comm-4). There is no first-party documentation walking through GPG key generation, git signing setup, or email encryption workflows, and no independent hands-on confirmation that OpenPGP actually works on shipped hardware. Missing for 10: verified working OpenPGP applet on shipped Solo 2 units, official docs for GPG/git-signing setup, and independent confirmation resolving the community's contradicting reports.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [community] “Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …”
- [community] “I'm really hoping they bring GPG to the Solokey V1, but I'm starting to lose confidence”
Otp
power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn
weight 2 · round to SoloKeys Solo 2GitHub docs explicitly state Solo 2 speaks OATH (TOTP/HOTP) in addition to FIDO2/WebAuthn, PIV, and OpenPGP, directly supporting legacy OTP slot functionality. However, missing for 10: no CLI/setup walkthrough for configuring TOTP/HOTP slots, no independent hands-on confirmation the OATH applet works reliably, and a runtime probe shows the official Solo CLI has bit-rotted (import errors) and firmware hasn't been updated in years, raising doubts about current usability.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian documents HOTP functionality that emulates HID keyboard to auto-type OTP values, plus an OTP Tool to switch protocols and an SK Manager to manage OTP/PIV/FIDO functions, confirming legacy OTP slot support beyond WebAuthn. However, there's no detail on TOTP support, challenge-response mode, or number of OTP slots available. Missing for 10: TOTP-specific documentation, challenge-response mode details, slot capacity/configuration specifics, and independent hands-on verification.
- [claimed-docs] “The HOTP function of FEITIAN FIDO Security Key emulates HID Keyboard protocol to enable automatically type the value in.”
- [claimed-docs] “Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
Piv
it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device
weight 2 · round to Feitian FIDO KeysGitHub docs confirm Solo 2 'speaks... PIV' alongside FIDO2/OATH/OpenPGP, supporting the core claim that certificate-based smart-card auth is possible, but there is no vendor documentation on PIV provisioning, workstation/VPN sign-in setup, or code-signing workflows, and a runtime probe shows the official CLI is bit-rotted and firmware hasn't shipped a release in 4 years, raising doubt about current enterprise usability. Missing for 10: PIV certificate enrollment/management docs, workstation/VPN sign-in integration guides, code-signing workflow evidence, and confirmation the PIV applet still functions with current tooling.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian documents PIV smart card functionality via the SK Manager tool, including macOS PIV smart card logon configuration and general PIV/FIDO/OTP management, supporting workstation sign-in use cases. However, evidence does not explicitly confirm VPN certificate-based authentication or code signing use cases with PIV, nor detail Windows/Active Directory PIV smart card logon specifically. Missing for 10: explicit VPN certificate-auth documentation, code-signing workflow evidence, Windows PIV smart card logon docs, and independent/third-party validation of PIV compliance.
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.”
Ssh
developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch
weight 2 · round to Feitian FIDO KeysSoloKeys Solo 2disputedcontradicted4/10GitHub docs assert the device 'speaks OATH (TOTP/HOTP), PIV, and OpenPGP' alongside its core FIDO2/WebAuthn support, which would in principle back sk-ssh (FIDO2), PIV, and GPG-based SSH keys — but a community commenter on the same Solo2 announcement explicitly states 'it doesn't do OpenPGP,' and an independent runtime probe shows the official solo-python CLI is broken (ImportError with current python-fido2) and firmware hasn't shipped since 2022, casting doubt that these advertised protocols are actually usable today for SSH auth. Missing for 10: explicit sk-ssh/PIV/OpenPGP SSH-key setup documentation, working current CLI/firmware evidence, and resolution of the OpenPGP support contradiction.
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [github] “also speaks OATH (TOTP/HOTP), PIV, and OpenPGP”
- [community] “Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian docs explicitly cover FIDO2 sk-ssh usage for OpenSSH/GitHub/Linux server login (feitian-docs-6) and PIV smart-card functionality including macOS PIV logon via SK Manager (feitian-docs-9, feitian-docs-10), supporting hardware-backed SSH auth with physical touch. However, no OpenPGP-based SSH key support is documented anywhere in the pack. Missing for 10: explicit OpenPGP applet/SSH support, independent/hands-on verification of sk-ssh workflow, and unified documentation tying all three methods together.
- [claimed-docs] “Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.”
Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling
Building with and managing the key — CLIs, SDKs, attestation
Agent audit
ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet
weight 2 · round to SoloKeys Solo 2The Solo 2 CLI exposes some device-state commands (`solo2 list` for connected devices/serials, `solo2 app admin ...` for config) suggesting basic programmatic querying, but there is no evidence of commands to enumerate firmware version, enabled applications, or stored credentials for fleet auditing. A runtime probe also shows the official Python CLI tooling (solo-python) is broken due to dependency incompatibility, undermining reliability of programmatic access. missing for 10: documented API/CLI output for firmware version and enabled-app enumeration, credential enumeration, a working/maintained CLI tool, any structured/machine-readable output format for fleet-scale auditing.
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian FIDO Keysnone0/10There is a SK Manager GUI tool for managing FIDO/PIV/OTP functions, but no evidence of any programmatic API, CLI output, or SDK exposing serial, firmware version, enabled applications, or credential state for automated fleet auditing by an agent; probes for API/docs endpoints all returned 404.
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [probe] “PROBE llms.txt: HTTP 404 at https://fido.ftsafe.com/llms.txt”
- [probe] “PROBE docs-md: HTTP 404 at https://fido.ftsafe.com/.md”
- [probe] “PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…”
Attestation
security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled
weight 2 · round to SoloKeys Solo 2The docs confirm Solo 2 ships with a factory attestation key and even allow customizing/generating your own attestation key pair for bulk deployment, implying WebAuthn/FIDO2 attestation is present in principle. However there is no documentation of a FIDO Alliance MDS listing, stable AAGUID, or any RP-side verification workflow that a security engineer could use to confirm the device model at registration — and the ability to swap the attestation key yourself could actually undermine trust in a fixed identity. missing for 10: MDS/AAGUID metadata for RP verification, documented attestation-cert chain details, guidance for enterprises on enforcing genuine-model checks, independent confirmation that registration-time attestation works as expected.
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
Feitian FIDO Keysnone0/10No evidence in the pack discusses FIDO attestation, AAGUID verification, metadata service (MDS) support, or any mechanism for security engineers to validate genuine Feitian key models at registration; the docs cover general FIDO compatibility, interfaces, and setup guides only.
Cli
developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably
weight 3 · round to Feitian FIDO KeysSoloKeys Solo 2disputedcontradicted3/10Docs and GitHub show a `solo2` CLI with some admin commands (`solo2 list`, `solo2 app admin set led`, firmware `update`) but no documented commands for setting PINs or managing slots, and reading device state relies on generic third-party `fido2-token` rather than a Solo-specific command. A runtime probe found the official Solo CLI (solo-python) actually fails to even run (`ImportError: cannot import name CTAP1`) due to incompatibility with current fido2 2.x, and firmware hasn't been released in 4 years — concrete evidence the tooling has bit-rotted rather than delivering the claimed scriptable management. missing for 10: working PIN-setting command, slot management, device-state reporting, and a CLI that runs without import errors on current dependencies.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian offers GUI tools (SK Manager, iePassManager, OTP Tool) for managing FIDO/PIV/OTP functions, PINs, and slots, but these are graphical utilities, not documented as scriptable CLIs. No evidence of a command-line interface, scripting API, or automation-friendly tooling for enabling apps, setting PINs, or reading device state. missing for 10: dedicated CLI tool, scripting/automation documentation, examples of headless/scriptable configuration workflows.
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.”
- [claimed-docs] “Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).”
- [claimed-docs] “Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.”
Sdks
developerOfficial SDKs let me integrate the key into my own desktop and mobile apps
weight 2 · round drawnSoloKeys Solo 2none0/10Evidence shows only a device-management CLI (solo2 app admin/list) and firmware-building/customization tooling for the key itself, not any SDK for embedding the key into third-party desktop or mobile applications. The runtime probe even shows the existing Solo Python CLI is broken/bit-rotted, and no library/SDK for app integration is documented anywhere in the pack.
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian FIDO Keysnone0/10Evidence covers WebAuthn/FIDO2 standard support, OS integrations (Windows Hello, Azure AD, OpenSSH), and firmware provisioning via Google's OpenSK repo, but nothing indicates Feitian ships its own official SDK for developers to embed key support into custom desktop/mobile apps. Probe results also confirm no API/docs discoverability artifacts. This is an applicable axis for a hardware key vendor (SDKs are common in this space) but no evidence of one existing.
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
- [probe] “PROBE openapi: all candidate paths 404 (https://fido.ftsafe.com/openapi.json, https://fido.ftsafe.com/swagger.json, https://fido.ftsafe.com/…”
Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat
Where the key works — platforms, browsers, service compatibility catalogs
Agent approval
ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions
weight 1 · round to Feitian FIDO KeysSolo 2 documents a generic touch-to-confirm step for WebAuthn/FIDO2 authentication (solokeys-docs-1), which could theoretically gate any human-in-the-loop confirmation, but there is no evidence tying this to AI-agent-initiated action approval flows, agentic tool integrations, or any AI-native ecosystem support. Additionally, runtime evidence shows the official CLI is broken/bit-rotted and firmware hasn't shipped in 4 years, raising doubts about active ecosystem maintenance. Missing for 10: any documentation or integration example of using Solo 2 touch confirmation as an approval gate for AI/agent workflows, evidence of SDK/API hooks for agent tooling, and independent confirmation of this use case.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian keys are standard FIDO2/WebAuthn/U2F hardware tokens that inherently require a physical touch to complete authentication (feitian-docs-1, feitian-docs-4, feitian-docs-18), which is the underlying mechanism that could be wired into an agent's approval flow via WebAuthn. However, there is no evidence of any AI-agent-specific integration, SDK, or documented workflow showing the key used as a human-approval gate for agent-initiated actions. Missing for 10: explicit AI-agent/automation integration examples, documentation of using the key as an approval gate in agentic pipelines, and any third-party corroboration of this use case.
- [claimed-docs] “Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.”
- [claimed-docs] “USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.”
- [claimed-docs] “USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…”
Compatibility
power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services
weight 2 · round to Feitian FIDO KeysSolo 2 claims broad compatibility (any USB port, no drivers, FIDO2/passkey standard, NFC for Android/iOS, OATH/PIV/OpenPGP) but there is no published compatibility catalog listing specific supported services/sites, and a runtime probe shows the official CLI tooling has bit-rotted and firmware hasn't been updated in years, raising doubts about maintained cross-platform support. Missing for 10: a published service/site compatibility list, browser-specific compatibility documentation, and evidence the tooling/firmware is actively maintained to keep pace with OS/browser changes.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian documents cross-platform compatibility (Windows, macOS, Linux, Android/iOS) and integration guides for specific platforms (Windows Hello, Azure AD, GitHub/OpenSSH, Google Advanced Protection, PIV/macOS), and multi-interface support (USB/NFC/BLE) which implies broad OS/browser reach. However there is no published, centralized compatibility catalog or matrix listing supported browsers/services, and no independent verification of claims. Missing for 10: a formal published compatibility catalog/matrix of supported services and browsers, independent/hands-on verification of cross-platform claims.
- [claimed-docs] “Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.”
- [claimed-docs] “Seamlessly support Windows Hello (Within an Azure AD).”
- [claimed-docs] “Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.”
- [claimed-docs] “MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.”
- [claimed-docs] “Recognized as a HID device, no driver is needed for MultiPass FIDO® Security Key to work on Microsoft Windows, macOS and Linux via USB.”
- [claimed-docs] “Introduction about how FEITIAN Security Keys works with Google advanced protection.”
Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery
Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery
Recovery
security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost
weight 3 · round to Feitian FIDO KeysSoloKeys Solo 2none0/10No evidence in the pack discusses backup key enrollment, multi-key registration strategies, or what is/isn't recoverable if a Solo 2 is lost — documentation covers setup, building, and CLI usage but never addresses lockout/recovery planning.
FAQ entries state that a lost key can be worked around by logging in with a backup security key or another method, then disabling the lost key and provisioning a new one, which is a real but minimal statement of a lockout-recovery strategy (feitian-docs-14, feitian-docs-24). However, there is no dedicated recovery guide explaining what is and isn't recoverable (e.g., per-relying-party re-registration necessity, loss of resident/discoverable credentials, biometric enrollment data) beyond this brief FAQ mention. Missing for 10: a structured recovery/lockout doc, explicit treatment of what is NOT recoverable (credentials tied to lost key), and guidance on enrolling multiple backup keys per service rather than just a generic FAQ answer.
- [claimed-docs] “The dedicated users can still logon to the account by using back-up security key or other method.”
- [claimed-docs] “The dedicated users can still logon to the account by using back-up security key or other method. Then user can disable the lost security ke…”
Setup
power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts
weight 2 · round to Feitian FIDO KeysDocs mention simple plug-and-play basics ('insert into USB port, no software required', 'touch sensor to confirm') but there is no evidence of a dedicated setup app or step-by-step account-registration walkthrough; the FIDO2 side of onboarding is essentially per-website. Additionally, a runtime probe shows the official companion CLI is bit-rotted (import errors) and firmware hasn't been updated in years, undermining confidence in any first-time-setup tooling. Missing for 10: a documented onboarding wizard/app, account-registration walkthrough for accounts, working companion CLI/tooling.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian provides first-party guided documentation for pairing keys (BLE setup guide), registering with specific platforms (Windows, Azure AD, Microsoft, GitHub/Linux via OpenSSH), and a dedicated SK Manager desktop app for configuring FIDO/PIV/OTP functions, which together resemble a guided enrollment flow for a power user. However, missing for 10: independent/hands-on user reports confirming the setup experience is clear in practice, and no single unified 'wizard' walkthrough spanning consumer-account registration (e.g., Google/Microsoft account UI) rather than platform/OS-level docs.
- [claimed-docs] “Learn how to pair your FEITIAN Bluetooth FIDO2 security key to your device.”
- [claimed-docs] “Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your personal Windows.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.”
Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness
What runs on the device — open-source firmware, update policy, vulnerability response
Source
security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device
weight 2 · round to SoloKeys Solo 2The Solo 2 firmware is openly published on GitHub, buildable from source, and the 'Hacker' variant explicitly supports flashing custom firmware, letting anyone inspect and verify what runs on the device; this is corroborated by community commentary confirming 'it's open source firmware, not open source hardware.' Updates are also SHA-256 verified before flashing, adding transparency to the update process. missing for 10: no formal independent third-party security audit is cited, and runtime evidence shows the firmware/tooling has not been updated since 2022, raising questions about ongoing maintenance of the open codebase.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [github] “`update` downloads the signed release, **verifies its SHA-256**, and flashes it.”
- [community] “This is an LPC55S69. So it's open source firmware, not open source hardware.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian offers a specific OpenSK hardware variant where users can build firmware from Google's open-source OpenSK repo and flash it themselves, directly addressing the transparency concern for that model. However, the flagship BioPass and MultiPass FIDO keys firmware is not documented as open source or independently audited, and no third-party security audit reports are cited anywhere in the pack. missing for 10: independent firmware audit reports for mainstream product lines, confirmation that BioPass and MultiPass firmware not just the niche OpenSK SKU is open or audited, and hands-on verification that shipped OpenSK devices match the public source
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
Updates
security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices
weight 2 · round to SoloKeys Solo 2SoloKeys Solo 2disputedcontradicted3/10The GitHub docs describe a signed, SHA-256-verified update mechanism (solokeys-gh-2), but there is no evidence of published security advisories or an affected-model lookup, and a runtime probe shows the official CLI is bit-rotted (ImportError against current fido2 lib) and no firmware release has shipped in ~4 years despite ongoing dependency commits — directly undercutting the claim that fixes reliably reach devices. missing for 10: security advisory feed/CVE list, affected-model/version lookup tool, evidence of recent firmware releases actually reaching users, working update tooling.
Feitian FIDO Keysnone0/10No evidence of security advisories, CVE tracking, affected-model lookup tools, or a documented firmware update delivery mechanism; only general product/setup docs and an OpenSK build guide are present, none of which address vulnerability response or patch distribution.
Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management
Keys at organization scale — bulk provisioning, delivery services, IdP policies
Agent provisioning
ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console
weight 2 · round drawnSoloKeys Solo 2none0/10There is no evidence of any enterprise/fleet management API for ordering, assignment, or pre-registration of keys — the CLI is a local hardware management tool (list, flash, LED), and probe evidence shows no OpenAPI/API docs exist and the CLI itself is bit-rotted. This is a consumer/hacker hardware key product with no enterprise provisioning system at all.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
Feitian FIDO Keysnone0/10No evidence of any enterprise API for provisioning, ordering, or assignment of keys — all documentation is consumer/end-user setup guides, and probes for API/docs endpoints returned 404s.
Delivery
it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics
weight 2 · round drawnSoloKeys Solo 2none0/10No evidence of any enterprise provisioning/shipping API, console, or fleet-deployment logistics integration; SoloKeys is a consumer hardware key sold via a Shopify store with no fleet-management tooling documented, and CLI/API evidence is limited to device-local admin commands and firmware building. Probes even show bit-rot in the CLI and no API/OpenAPI documentation exists.
- [probe] “PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
- [claimed-docs] “Pack of colored cases for Solo 2”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
Feitian FIDO Keysnone0/10No evidence of any API, console, or enterprise fulfillment/logistics/shipping-management capability; probes confirm no API/docs exist for this. Evidence covers only device features (FIDO2, biometrics, NFC/BLE/USB) and setup guides, nothing about distributed shipping orchestration.
Idp
it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication
weight 2 · round to Feitian FIDO KeysSoloKeys Solo 2none0/10No evidence anywhere in the pack mentions IdP integrations (Okta, Entra ID, Google Workspace), fleet enrollment/management tools, or policy enforcement for hardware-key authentication; evidence only covers WebAuthn/FIDO2 protocol support, firmware building, and hardware details. This is a plausible axis for a security key vendor (many competitors offer admin/fleet consoles), but SoloKeys shows nothing to support it.
Feitian keys are documented as fully W3C WebAuthn/FIDO2-compliant HID devices with explicit setup guides for Azure AD-joined Windows, Microsoft applications, and Google Advanced Protection, which implies interoperability with major identity providers. However, there is no explicit documentation or guide for Okta or Google Workspace integration, nor any mention of admin-side policy enforcement (e.g., requiring hardware-key-only auth) within these IdPs. Missing for 10: Okta-specific integration guide, Google Workspace-specific setup docs, and evidence of IdP admin policy controls enforcing hardware-key requirements.
- [claimed-docs] “Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.”
- [claimed-docs] “Introduction about how FEITIAN Security Keys works with Google advanced protection.”
- [claimed-docs] “Seamlessly support Windows Hello (Within an Azure AD).”
Provisioning
it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys
weight 3 · round drawnSoloKeys Solo 2none0/10Evidence covers individual key setup, CLI device listing/config (`solo2 list`, `admin set led`), and custom attestation-key generation, with one offhand mention of building attestation keys 'for maybe 100,000 devices'—but there is no documented bulk-enrollment workflow, admin console, pre-registration pipeline, or lifecycle/issuance tracking system for organizations. Runtime probes further show the official CLI is broken (ImportError) and no firmware has shipped in 4 years, undercutting any claim of active enterprise tooling.
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [github] “solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
Feitian FIDO Keysnone0/10Evidence only shows per-device configuration tools (SK Manager, iePassManager) for individual FIDO/PIV/OTP settings, not organization-wide bulk provisioning, pre-registration workflows, or lifecycle/inventory tracking across a fleet of keys. No admin console, CSV/bulk import, or enterprise deployment tooling is documented.
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use FEITIAN SK Manager to configure macOS PIV smart card log on.”
- [claimed-docs] “Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).”
- [claimed-docs] “Learn how to use OTP Tool to switch protocol with FEITIAN FIDO security key.”
Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors
The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models
Certifications
it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)
weight 2 · round drawnSoloKeys Solo 2none0/10No evidence of FIPS 140 validation or Common Criteria certification anywhere in the pack; only a community comment mentions 'water resistant' informally (solokeys-comm-7), and another comment casts doubt on tamper-resistance claims (solokeys-comm-1). No documented crush resistance or regulated-environment certification exists.
- [community] “Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…”
- [community] “I'm still curious how the key is tamper resistent when filling it with transparent epoxy... it should be fairly easy to remove the epoxy and…”
Feitian FIDO Keysnone0/10The evidence pack contains no mention of FIPS 140 validation, Common Criteria certification, or durability testing (water/crush resistance) for any Feitian key; all citations focus on protocol compatibility, interfaces, and setup guides. Missing for 10: FIPS 140 validation documentation, Common Criteria certification documentation, water/crush resistance durability specs.
Connectors
power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors
weight 2 · round drawnSoloKeys Solo 2none0/10Evidence shows Solo 2 exists as a security key with NFC variant and generic USB port compatibility, and community comments mention a 'reversible USB-A'/'reversible usb plug', but there is no evidence of a broader lineup with distinct USB-C vs USB-A SKUs or keychain vs low-profile nano form factors — only a single case/color accessory line is mentioned.
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [community] “"Reversible USB-A" now there's a feature I wish we'd see more often!”
- [community] “Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…”
- [claimed-docs] “Pack of colored cases for Solo 2”
Nfc
power userTap the key on my phone over NFC to authenticate in mobile browsers and apps
weight 2 · round to SoloKeys Solo 2SoloKeys explicitly markets NFC tap-to-authenticate for compatible Android and iOS devices as a feature of Solo 2, supporting WebAuthn/passkeys which work across mobile browsers/apps. Missing for 10: no independent hands-on confirmation of NFC mobile browser/app compatibility, and community discussion focuses on other aspects (tamper resistance, OpenPGP) rather than validating NFC mobile use.
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
MultiPass FIDO Security Key explicitly supports NFC as one of three interfaces and is documented compatible with Android/iOS platforms, implying tap-to-authenticate via NFC on mobile; however, evidence doesn't explicitly confirm NFC (vs BLE) works with specific mobile browsers/apps or provide hands-on confirmation. missing for 10: explicit mobile browser/app NFC tap walkthrough, independent hands-on verification of NFC mobile authentication.
- [claimed-docs] “USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces.”
- [claimed-docs] “USB, NFC, and BLE, MultiPass FIDO® Security Key employs three communication interfaces. Users can use any of these interfaces to complete FI…”
- [claimed-docs] “MultiPass FIDO® Security Key is also compatible with any Android / iOS platforms with Bluetooth v4.0+.”
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
ai-native userDo everything through the API that I can do in the UI
weight 2 · round drawnSoloKeys Solo 2none0/10The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)
ai-native userExport all of my data in open formats and leave
weight 3 · round drawnSoloKeys Solo 2none0/10The evidence pack shows Solo 2 supports open standards (WebAuthn, OATH, PIV, OpenPGP) and lets users customize/replace the attestation key or wipe the device, but there is no documentation of any way to export stored credentials/private key material in open formats to migrate elsewhere — by design, FIDO2/PIV/OpenPGP keys generated on-device are non-extractable. missing for 10: any documented data-export/migration path, evidence of extractable key material, or open-format backup/portability tooling.
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)”
ai-native userRead the product's source under an open license
weight 2 · round to SoloKeys Solo 2The firmware source is hosted openly on GitHub (solokeys/solo2), with build instructions, hackable firmware flashing, and even a dedicated 'Hacker' key edition explicitly for reading/modifying source and firmware end-to-end. Community confirms firmware is open source (though hardware/chip is not), corroborating the licensing model. Missing for 10: no explicit license file/name cited, and no independent audit of license terms beyond community mention that firmware (not hardware) is open.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [community] “This is an LPC55S69. So it's open source firmware, not open source hardware.”
Feitian ships a specific 'OpenSK' hardware variant that can run firmware built from Google's open-source OpenSK repository, giving some access to readable/open-licensed source for that SKU, but this is a third-party (Google) codebase, not Feitian's own firmware for its mainstream BioPass/MultiPass keys, which remain closed. Missing for 10: evidence that Feitian's own primary product firmware/source is published under an open license, and no indication of a public source repo, license file, or docs-as-markdown/API spec for the broader product line.
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
ai-native userSelf-host the core product
weight 3 · round drawnThe Solo 2 'Hacker' edition ships with fully open-source firmware that users can build, flash, and customize themselves (own attestation keys, own firmware, full toolchain via Rust/cargo), which is the closest analogue to 'self-hosting' for a hardware security key — no cloud dependency by design. However, runtime evidence shows the surrounding tooling has bit-rotted (solo-python CLI fails on current fido2 libs) and no firmware release has shipped in 4 years, undermining confidence that self-building/self-hosting the core product is currently practical. Missing for 10: a working, up-to-date official build/flash pipeline, and independent confirmation that a user can successfully self-build current firmware today.
- [github] “Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…”
- [github] “On a **Hacker** key you can build and flash your own firmware.”
- [claimed-docs] “If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.”
- [claimed-docs] “To build, develop and debug the firmware for the STM32L432.”
- [claimed-docs] “rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools”
- [claimed-docs] “cargo build --release --features board-lpcxpresso55,develop”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
The FIDO key is inherently a local, on-device hardware authenticator (not a hosted service), and Feitian explicitly documents that users can build firmware from Google's open-source OpenSK repository and provision it onto the hardware themselves, giving genuine control over the 'core product' without vendor cloud dependency. This is a reasonable analog to self-hosting for a hardware device, but it's not a full self-hostable software stack with deployment docs, and there's no evidence of self-hosted backend/server components (e.g., FIDO server, attestation service) that would round out a complete self-hosting story. Missing for 10: documentation of self-hosting any server-side/relying-party components, deployment guides beyond firmware flashing, and independent confirmation of OpenSK build success.
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
ai-native userControl data retention and deletion
weight 2 · round to SoloKeys Solo 2Evidence shows credentials are stored only on-device rather than in a vendor cloud (solokeys-docs-2), and a device wipe is possible via the third-party `fido2-token -R` command (solokeys-docs-10), giving users some control over deletion. However, this is not a first-party, documented retention/deletion feature — it's a generic FIDO2 tool tip buried in a GitHub releases page, with no official SoloKeys documentation on data retention policy or granular per-credential deletion. Missing for 10: native SoloKeys CLI/tool for credential management and wipe, official retention policy documentation, and independent confirmation the wipe command works reliably.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
ai-native userOpt out of telemetry and usage tracking
weight 2 · round to SoloKeys Solo 2Solo 2 is explicitly marketed as working entirely locally ('stays on your key, not their cloud', no software/drivers required), which implies no cloud usage-tracking to opt out of, but there is no explicit telemetry policy, settings, or opt-out control documented for the CLI/companion tooling. missing for 10: explicit telemetry/privacy policy statement, any opt-out toggle or setting, confirmation that the solo2 CLI/companion app sends no usage analytics.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “No more sticky notes. No more forgotten passwords. No more texts with six digit codes.”
- [claimed-docs] “Insert your Solo 2 into any USB port. No software or drivers required.”
Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage
FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management
Credential management
power userList and delete the passkeys stored on my key and know its credential capacity before it fills up
weight 2 · round to Feitian FIDO KeysSoloKeys Solo 2none0/10No evidence describes per-passkey listing, deletion, or credential-capacity reporting; the only related CLI ops shown are `solo2 list` (lists connected devices, not credentials) and `fido2-token -R` (wipes the entire key, not selective deletion). Additionally, a runtime probe shows the official CLI is now broken (ImportError against modern fido2 libs), further undermining any credential-management workflow.
- [github] “solo2 list # list connected devices (alias: solo2 ls)”
- [claimed-docs] “You can "wipe" a device using `fido2-token -R`”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
FEITIAN provides tools (SK Manager, iePassManager) described as managing 'FIDO PIN and credential related operations' on the key, implying some list/delete capability, and one product page claims 'no limit to accounts' for the MultiPass key. However, there is no explicit documentation of a list/delete-passkey UI, no discussion of credential capacity limits for other models, and no guidance on capacity awareness before a key fills up. missing for 10: explicit list/delete UI screenshots or steps, documented per-model credential capacity limits, and warnings/behavior when storage is full.
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
- [claimed-docs] “Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).”
- [claimed-docs] “There is no limit to the number of accounts registered in MultiPass FIDO® Security Key.”
Fido2
security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username
weight 3 · round to SoloKeys Solo 2Solo 2 is marketed explicitly as a passkey/WebAuthn security key that stores credentials on-device rather than in a cloud, and general FIDO2 passkey support inherently implies discoverable/resident credentials for usernameless sign-in ([solokeys-docs-2], [solokeys-docs-9], [solokeys-gh-1]). Missing for 10: explicit documentation of resident-key storage limits/technical FIDO2 conformance details, and independent hands-on confirmation of a usernameless login flow (only marketing copy corroborates this).
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [claimed-docs] “No more sticky notes. No more forgotten passwords. No more texts with six digit codes.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
Feitian's keys are explicitly W3C WebAuthn/FIDO2 compliant and marketed for passwordless sign-in scenarios like Windows Hello and Google Advanced Protection, which typically rely on discoverable credentials, but the evidence never explicitly names 'resident keys' or 'discoverable credentials' or confirms a specific stored-credential capacity/no-username login flow. Missing for 10: explicit documentation of resident-key/discoverable-credential support, stated credential storage limits, and a hands-on demonstration of username-less WebAuthn sign-in.
- [claimed-docs] “Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.”
- [claimed-docs] “Seamlessly support Windows Hello (Within an Azure AD).”
- [claimed-docs] “Introduction about how FEITIAN Security Keys works with Google advanced protection.”
- [claimed-docs] “Users can build firmware from the source code of Google OpenSK Github repository without changing anything, provision it to this OpenSK hard…”
power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers
weight 2 · round to Feitian FIDO KeysSolo 2 is a standard WebAuthn/FIDO2/U2F device that would work with any relying party supporting those standards (Google, GitHub, Microsoft, many password managers), and vendor docs confirm FIDO2/passkey and U2F-style support plus broad protocol coverage (OATH, PIV, OpenPGP). However there is no explicit first-party or independent testing evidence confirming compatibility with each named service, and a runtime probe shows the companion CLI tooling has bit-rotted with no firmware update in 4 years, raising doubts about ongoing maintenance/compatibility. Missing for 10: explicit per-service (Google/GitHub/Microsoft/password manager) compatibility confirmation, independent hands-on verification across these services, and evidence of active firmware maintenance to keep pace with protocol changes.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [probe] “PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…”
First-party docs confirm W3C WebAuthn/U2F compliance and dedicated guides for GitHub (OpenSSH), Microsoft/Azure AD, and Google Advanced Protection, showing broad cross-service compatibility. Missing for 10: explicit password-manager (e.g., 1Password/Bitwarden) integration guidance and independent/hands-on verification beyond vendor documentation.
- [claimed-docs] “Fully compatible to W3C's Web Authentication Standard with HID interface. Plug in and secure your web applications easily.”
- [claimed-docs] “Learn how to apply FEITIAN FIDO security keys with OpenSSH connections including remotely connecting Github and Linux server.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Azure AD joined Windows 10.”
- [claimed-docs] “Learn how to use your FEITIAN FIDO2 security key to protect your Microsoft application.”
- [claimed-docs] “Introduction about how FEITIAN Security Keys works with Google advanced protection.”
User verification
security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate
weight 2 · round to Feitian FIDO KeysSoloKeys Solo 2none0/10Evidence only shows a capacitive touch sensor for user presence confirmation (solokeys-docs-1), which is a presence test, not FIDO2 user verification via PIN or biometric. No documentation or community evidence mentions a settable FIDO2 PIN or biometric sensor on Solo 2, so the specific 'stolen key alone cannot authenticate' verification story is unevidenced.
- [claimed-docs] “When prompted, touch the capacitive sensor on your Solo 2 to confirm.”
- [github] “It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.”
- [claimed-docs] “Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.”
Feitian documents biometric (fingerprint) on-device user verification for BioPass keys, explicitly noting 'losing the key will cause no security risk at all,' and separately documents FIDO PIN management via iePassManager for PIN/credential operations, satisfying the on-device UV requirement. Missing for 10: independent/hands-on verification of PIN enforcement or biometric FAR/FRR, and no explicit CTAP2 'uv' flag documentation.
- [claimed-docs] “Biometric technology makes BioPass FIDO2 Security Key one of the most secure tokens.”
- [claimed-docs] “The fingerprint module prevents any misuses of the token from people other than authorized user, and losing the key will cause no security r…”
- [claimed-docs] “Learn how to use iePassManager at Android OS to manage your FIDO devices(including FIDO PIN and credential related operations).”
- [claimed-docs] “Learn how to use FEITIAN SK Manager tool to manager your security key 's functions including FIDO, PIV, OTP.”
Not comparable on these axes
ai-native userPlug MCP servers into this product so it can use their tools
weight 3 · not comparableSoloKeys Solo 2n/aSolo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator), not an AI agent or platform with tool-use capability; MCP server integration is not a fair axis for this product category.
ai-native userConnect an agent via an official MCP server
weight 3 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/OATH/PIV/OpenPGP authenticator); it has no product role as an agent tool server and no evidence of an MCP server offering. Connecting AI agents via MCP is outside this product's category.
ai-native userIssue scoped/least-privilege API credentials for an agent
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator); it has no concept of API credentials or agent-scoped access tokens, which is entirely outside its product category.
ai-native userSubscribe to events via webhooks
weight 2 · not comparableSoloKeys Solo 2n/aSolo 2 is a hardware security key (USB/NFC FIDO2 device); webhooks/event subscriptions are not a fair capability for this product category, which has no server-side or event-driven architecture.
ai-native userGet AI-generated insights and suggestions from my data inside the product
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OATH/PIV/OpenPGP); it does not process or store user data in a way that would support AI-generated insights or suggestions. This axis is a category error for an authentication hardware token.
ai-native userSet up automations that run autonomously in the background
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OTP); it has no automation/workflow-orchestration capability and the concept of 'background autonomous automations' does not apply to a physical security token requiring touch confirmation.
ai-native userDelegate tasks to a built-in AI assistant inside the product
weight 3 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key for FIDO2/WebAuthn authentication, not an AI assistant or agentic platform; delegating tasks to a built-in AI assistant is a category error for this product type.
ai-native userOperate the product with natural-language commands
weight 2 · not comparableSoloKeys Solo 2n/aSolo 2 is a hardware security key/authenticator; operating it is inherently physical (touch sensor, insert USB, tap NFC) or via CLI commands, not natural-language interaction. This is a category error—natural-language operation is not a fair axis for a hardware auth token.
ai-native userExplore an interactive API reference with runnable examples
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key with a CLI/firmware toolchain, not an API/SaaS product; there is no API surface for which an interactive reference with runnable examples would be a meaningful offering. The probes confirm no OpenAPI/API docs exist, but this reflects the product category, not a missing capability.
ai-native userTest against a sandbox environment without touching production data
weight 1 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a physical hardware security key; the concept of a 'sandbox environment vs production data' for AI-native testing does not apply to this product category.
ai-native userRely on versioned APIs with a documented deprecation policy
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key that implements standard protocols (FIDO2/WebAuthn, OATH, PIV, OpenPGP); it is not an API-driven service or SDK for which a versioned API deprecation policy would be a meaningful axis. This story is a category error for this product type.
ai-native userDefine rules that trigger actions automatically on events
weight 3 · not comparableSoloKeys Solo 2n/aSolo 2 is a hardware security key (FIDO2/passkey/OATH/PIV authenticator); it has no rules/automation engine or event-trigger system, and this axis is a category error for an authentication hardware token.
ai-native userSchedule recurring jobs or workflows
weight 2 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key for authentication; scheduling recurring jobs/workflows is not a capability that applies to this product category.
ai-native userVersion, review, and roll back my automations
weight 1 · not comparableSoloKeys Solo 2n/aSoloKeys Solo 2 is a hardware security key/authenticator; 'automations' with version/review/rollback is not a concept applicable to this product category.
ai-native userChoose where my data is stored (region/residency)
weight 2 · not comparableSoloKeys Solo 2n/aSolo 2 is a local hardware security key whose keys never leave the device ('stays on your key, not their cloud') — there is no cloud data storage or region selection concept applicable to this product category.
- [claimed-docs] “Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.”
ai-native userPrevent my data from being used to train AI models
weight 3 · not comparableSoloKeys Solo 2n/aSolo 2 is a hardware security key (FIDO2/passkey/OATH/PIV/OpenPGP authenticator); it has no relationship to AI model training data or consent controls over such use. This story is a category error for this product type.