Skip to content

Hardware Security Keys Arena

SoloKeys Solo 2 vs Token2

Token2 wins · 919 (10 drawn)

Agenticness — how well agents can access and operate the productAgenticness

How well agents can access and operate the product

Agent access

  1. ai-native userPoint an agent at llms.txt or agent-oriented docs

    weight 2 · round drawn
    SoloKeys Solo 2none0/10

    Explicit probes confirm docs.solokeys.dev has no llms.txt (404) and no openapi/markdown-alternative endpoints; the only llms.txt found is a generic Shopify shopping-agent file unrelated to technical/product documentation, so there is no agent-oriented documentation to point an AI agent at.

    • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://docs.solokeys.dev/.md
    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…
    Token2none0/10

    Direct probes show no llms.txt (404) and no markdown-accessible docs (404), and no OpenAPI/agent-oriented documentation exists; Token2 is a hardware security key vendor with no evidence of agent-discoverable docs.

    • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md
    • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
  2. ai-native userRun the product headlessly / in CI for automation

    weight 2 · round to Token2
    SoloKeys Solo 2none0/10

    Solo 2 is a physical security key requiring human touch confirmation for every action, and while a CLI exists (solo2 list, admin commands), there's no documented support for headless/CI automation; a runtime probe shows the official CLI is bit-rotted (ImportError, incompatible fido2 dependency) with no firmware release in 4 years, further undermining any automation use case.

    • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
    • [github] solo2 list # list connected devices (alias: solo2 ls)
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    Token2partialprobed4/10

    Token2 ships a PowerShell bulk-enrollment script (fido2_bulkenroll_entraid) that could in principle be scripted/automated, and fido2-manage exposes some command-line-style operations (PIN, SSH key management) beyond its Python/tkinter GUI, suggesting some automation potential. However, the flagship tool is explicitly GUI-based and requires physical FIDO2 hardware interaction over USB/NFC, and there is no documented headless mode, CI integration, or automation-focused CLI/API (no OpenAPI, no llms.txt, no CI examples). Missing for 10: dedicated headless/CI-mode documentation, evidence of non-interactive scripted runs without physical key presence, and any CI/pipeline integration guide.

    • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
    • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
    • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
    • [probe] official CLI documented at https://github.com/token2/fido2-manage
    • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
    • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
  3. ai-native userUse an official CLI

    weight 2 · round to Token2
    SoloKeys Solo 2disputedcontradicted3/10

    GitHub docs show an official `solo2` CLI with scriptable commands (list, admin set led, monitor, wipe) suitable for automation, but a runtime probe found the official Solo CLI (solo-python) actually fails to run due to a dependency ImportError, and no Solo 2 firmware release has shipped in 4 years despite ongoing CI commits — concretely contradicting the claim of a working, maintained official CLI. Missing for 10: evidence of AI-agent-specific CLI usage/documentation, confirmation the solo2 (Rust) CLI itself runs cleanly, and independent corroboration beyond the vendor's own repo.

    • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
    • [github] solo2 list # list connected devices (alias: solo2 ls)
    • [claimed-docs] solo monitor <serial-port>
    • [claimed-docs] You can "wipe" a device using `fido2-token -R`
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    Token2partialprobed5/10

    Token2 publishes official open-source tools (fido2-manage, fido2_bulkenroll_entraid) that expose scriptable command operations (list/delete/generate/upload for keys, PIN, biometrics, SSH) usable from the command line, and the PowerShell bulk-enroll tool is inherently a CLI-style utility, but neither is explicitly branded or documented as an 'official CLI' for AI-native/agentic workflows — the flagship fido2-manage tool is described primarily as a GUI (Python/tkinter) application with underlying scriptable functions rather than a dedicated documented CLI interface. Missing for 10: explicit CLI documentation/binary/flags, examples of scripting/automation for AI agents, and independent confirmation the tool is used headlessly.

    • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
    • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
    • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
    • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
    • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
    • [probe] official CLI documented at https://github.com/token2/fido2-manage
  4. ai-native userDrive the product through a documented public API

    weight 3 · round drawn
    SoloKeys Solo 2none0/10

    Solo 2 exposes a hardware CLI (solo2 app/list) and standard protocols like FIDO2/PIV/OpenPGP, but there is no documented public REST/programmatic API for AI-driven control, and probes confirm no OpenAPI spec or llms.txt exists (404s) while the closest thing to an SDK (solo-python CLI) is reported bit-rotted and broken via ImportError. No evidence of a working, documented API surface an AI agent could drive.

    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…
    Token2none0/10

    Token2 is a hardware security key vendor; probes explicitly show no public API, no OpenAPI/Swagger spec, and no llms.txt (404s across all checked endpoints). Its tools (fido2-manage CLI, GUI, browser demos) are device-management utilities over USB/NFC/WebAuthn, not a documented public API for programmatic/agentic control.

    • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
    • [probe] PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md
    • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
    • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
  5. ai-native userBuild against official SDKs

    weight 2 · round drawn
    SoloKeys Solo 2none0/10

    Evidence shows firmware-build tooling (Rust/cargo builds, solo2 CLI, customization docs) rather than an official SDK for third-party/AI-native application development, and the one CLI tool cited is reported bit-rotted and broken in 2026 (ImportError, no releases in 4 years). No client library, API reference, or SDK package is documented for developers to build against.

    • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
    • [claimed-docs] rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
    • [github] On a **Hacker** key you can build and flash your own firmware.
    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
    • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
    Token2none0/10

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

    Api quality

    1. ai-native userDownload a machine-readable API spec (OpenAPI or equivalent)

      weight 2 · round drawn
      SoloKeys Solo 2none0/10

      SoloKeys is a hardware security key with a CLI and firmware documentation, not an API/web service; a machine-readable OpenAPI spec would be a fair thing to ask for if it exposed a network API, but probes explicitly show no OpenAPI/swagger spec exists at any candidate path and no llms.txt for the technical docs.

      • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
      • [probe] PROBE llms.txt: HTTP 404 at https://docs.solokeys.dev/llms.txt
      • [probe] PROBE runtime (recorded 2026-09-15): solokeys.com serves an llms.txt ('# Agent Instructions — SoloKeys'), but it is Shopify's platform-gener…
      Token2none0/10

      Token2 is a hardware security key vendor with desktop/browser tools and a CLI, but there is no evidence of a machine-readable API spec; explicit probes for OpenAPI/Swagger endpoints and llms.txt all returned 404.

      • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
      • [probe] PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md
      • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…

    Automation depth — how much of the product can run unattendedAutomation depth

    How much of the product can run unattended

    1. ai-native userPerform bulk operations across many items at once

      weight 2 · round to Token2
      SoloKeys Solo 2none0/10

      The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Token2partialprobed6/10

        Token2 provides fido2_bulkenroll_entraid, a dedicated PowerShell tool for bulk-provisioning FIDO2 keys into Entra ID, and fido2-manage is a scriptable CLI (list/delete/edit passkeys, PIN and bio-template management, SSH key handling) that can be run in loops/scripts to act across many devices. This is real automation-depth for security-key/credential management but is narrow in scope (security keys/passkeys, one specific IdP integration) rather than a general bulk-operations API. Missing for 10: a general-purpose bulk API/SDK, documented batch endpoints beyond the Entra-specific script, and independent evidence of large-scale bulk use in production.

        • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
        • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
        • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
        • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
        • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

      Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido

      What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

      Openpgp

      1. developerKeep OpenPGP keys on the device and use them for git commit signing and encrypted email

        weight 2 · round to SoloKeys Solo 2
        SoloKeys Solo 2disputedcontradicted3/10

        The GitHub README lists OpenPGP as a supported protocol (solokeys-gh-1, solokeys-gh-8), which would enable git commit signing and encrypted email use cases, but community comments directly contradict this — users report 'it doesn't do OpenPGP' and 'I'm really hoping they bring GPG to the Solokey... but I'm starting to lose confidence' (solokeys-comm-2, solokeys-comm-4). There is no first-party documentation walking through GPG key generation, git signing setup, or email encryption workflows, and no independent hands-on confirmation that OpenPGP actually works on shipped hardware. Missing for 10: verified working OpenPGP applet on shipped Solo 2 units, official docs for GPG/git-signing setup, and independent confirmation resolving the community's contradicting reports.

        • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
        • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
        • [community] Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …
        • [community] I'm really hoping they bring GPG to the Solokey V1, but I'm starting to lose confidence
        Token2none0/10

        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

        Otp

        1. power userThe key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

          weight 2 · round to SoloKeys Solo 2
          SoloKeys Solo 2fullprobed6/10

          GitHub docs explicitly state Solo 2 speaks OATH (TOTP/HOTP) in addition to FIDO2/WebAuthn, PIV, and OpenPGP, directly supporting legacy OTP slot functionality. However, missing for 10: no CLI/setup walkthrough for configuring TOTP/HOTP slots, no independent hands-on confirmation the OATH applet works reliably, and a runtime probe shows the official Solo CLI has bit-rotted (import errors) and firmware hasn't been updated in years, raising doubts about current usability.

          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
          • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2none0/10

          The evidence only shows a browser-based TOTP toolset (docs-4, docs-6) and Entra ID seed export, unrelated to the FIDO2 security key itself carrying TOTP/HOTP slots or challenge-response capability; no documentation shows the hardware key supports legacy OTP protocols. Missing for 10: any spec sheet or docs stating the key itself implements TOTP/HOTP slots, challenge-response mode, or dual-protocol firmware.

          • [claimed-docs] Generate and verify TOTP codes entirely in your browser. Algorithm: SHA-1. All computation happens locally — no seed is ever sent to a serve…
          • [claimed-docs] Export the current seed as an Entra ID hardware-token import file (CSV or JSON).

        Piv

        1. it adminThe key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

          weight 2 · round to Token2
          SoloKeys Solo 2partialprobed4/10

          GitHub docs confirm Solo 2 'speaks... PIV' alongside FIDO2/OATH/OpenPGP, supporting the core claim that certificate-based smart-card auth is possible, but there is no vendor documentation on PIV provisioning, workstation/VPN sign-in setup, or code-signing workflows, and a runtime probe shows the official CLI is bit-rotted and firmware hasn't shipped a release in 4 years, raising doubt about current enterprise usability. Missing for 10: PIV certificate enrollment/management docs, workstation/VPN sign-in integration guides, code-signing workflow evidence, and confirmation the PIV applet still functions with current tooling.

          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
          • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2partialclaimed5/10

          Token2 documents PIV support via a Windows miniDriver and macOS Companion App enabling smartcard-based certificate enrollment and login with on-prem AD, which covers workstation sign-in use cases. However, there is no evidence for VPN integration or code signing use cases specifically, nor independent/hands-on verification of PIV certificate workflows beyond vendor docs. missing for 10: VPN certificate-auth evidence, code-signing use case evidence, independent/hands-on validation of PIV smartcard login, detail on key non-exportability guarantees for PIV certs.

          • [claimed-docs] Using the Windows miniDriver, users can manage essential PIV functions such as PIN setup, PIN changes, and basic card configuration.
          • [claimed-docs] the miniDriver is needed to configure smartcard-based certificate enrollment and login with Windows on-premises Active Directory.
          • [claimed-docs] PIV features can be configured using our all-in-one management tool, the Companion App, which is now also available on macOS.

        Ssh

        1. developerMy SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

          weight 2 · round to Token2
          SoloKeys Solo 2disputedcontradicted4/10

          GitHub docs assert the device 'speaks OATH (TOTP/HOTP), PIV, and OpenPGP' alongside its core FIDO2/WebAuthn support, which would in principle back sk-ssh (FIDO2), PIV, and GPG-based SSH keys — but a community commenter on the same Solo2 announcement explicitly states 'it doesn't do OpenPGP,' and an independent runtime probe shows the official solo-python CLI is broken (ImportError with current python-fido2) and firmware hasn't shipped since 2022, casting doubt that these advertised protocols are actually usable today for SSH auth. Missing for 10: explicit sk-ssh/PIV/OpenPGP SSH-key setup documentation, working current CLI/firmware evidence, and resolution of the OpenPGP support contradiction.

          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
          • [github] also speaks OATH (TOTP/HOTP), PIV, and OpenPGP
          • [community] Nice, I'd love this as an open source yubikey replacement. But it doesn't do OpenPGP, I rely on that way too much sadly... If they add that …
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2partialprobed6/10

          Token2's fido2-manage tool explicitly supports SSH security keys (generate, list resident, download/rehydrate, ssh-copy-id, add to local ssh-agent), directly evidencing FIDO2 sk-ssh hardware-backed key workflows. PIV is also supported via the Windows miniDriver and Companion App for smartcard-based certificate enrollment, but there is no mention of OpenPGP support for SSH auth. missing for 10: OpenPGP-based SSH key support, independent/hands-on verification of the sk-ssh workflow, and cross-platform PIV parity beyond Windows/macOS.

          • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
          • [claimed-docs] Using the Windows miniDriver, users can manage essential PIV functions such as PIN setup, PIN changes, and basic card configuration.
          • [claimed-docs] the miniDriver is needed to configure smartcard-based certificate enrollment and login with Windows on-premises Active Directory.
          • [claimed-docs] PIV features can be configured using our all-in-one management tool, the Companion App, which is now also available on macOS.
          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

        Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling

        Building with and managing the key — CLIs, SDKs, attestation

        Agent audit

        1. ai-native userAn agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

          weight 2 · round to Token2
          SoloKeys Solo 2partialprobed3/10

          The Solo 2 CLI exposes some device-state commands (`solo2 list` for connected devices/serials, `solo2 app admin ...` for config) suggesting basic programmatic querying, but there is no evidence of commands to enumerate firmware version, enabled applications, or stored credentials for fleet auditing. A runtime probe also shows the official Python CLI tooling (solo-python) is broken due to dependency incompatibility, undermining reliability of programmatic access. missing for 10: documented API/CLI output for firmware version and enabled-app enumeration, credential enumeration, a working/maintained CLI tool, any structured/machine-readable output format for fleet-scale auditing.

          • [github] solo2 list # list connected devices (alias: solo2 ls)
          • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2partialprobed5/10

          Token2's open-source fido2-manage CLI/GUI tool (scriptable over USB/NFC) can view device information, list resident credentials (passkeys) with user handle, manage PINs, and enumerate biometric templates — giving an agent a scriptable path to audit key state across a fleet. However, no evidence documents reading serial numbers, firmware version, or 'enabled applications' specifically, nor is there a structured/JSON API, OpenAPI spec, or llms.txt for machine-readable output (confirmed 404s), so agent-friendly programmatic access is only partially evidenced. Missing for 10: documented serial/firmware-version fields, explicit 'enabled applications' enumeration, and a structured machine-readable output/API for agent consumption.

          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
          • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
          • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
          • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
          • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

        Attestation

        1. security engineerVerify device attestation at registration to enforce that only genuine, approved key models are enrolled

          weight 2 · round drawn
          SoloKeys Solo 2partialclaimed3/10

          The docs confirm Solo 2 ships with a factory attestation key and even allow customizing/generating your own attestation key pair for bulk deployment, implying WebAuthn/FIDO2 attestation is present in principle. However there is no documentation of a FIDO Alliance MDS listing, stable AAGUID, or any RP-side verification workflow that a security engineer could use to confirm the device model at registration — and the ability to swap the attestation key yourself could actually undermine trust in a fixed identity. missing for 10: MDS/AAGUID metadata for RP verification, documented attestation-cert chain details, guidance for enterprises on enforcing genuine-model checks, independent confirmation that registration-time attestation works as expected.

          • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
          • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
          Token2partialclaimed3/10

          Token2 provides an AAGUID lookup tool to identify certified authenticators and a WebAuthn registration demo, which touch on device identification, but there is no documented mechanism for verifying attestation certificates or enforcing an allow-list of approved key models at registration. missing for 10: attestation certificate chain validation, FIDO Metadata Service integration, documented enterprise enrollment policy enforcement.

          • [claimed-docs] Look up any certified authenticator by name or AAGUID — no key required.
          • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
          • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.

        Cli

        1. developerConfigure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

          weight 3 · round to Token2
          SoloKeys Solo 2disputedcontradicted3/10

          Docs and GitHub show a `solo2` CLI with some admin commands (`solo2 list`, `solo2 app admin set led`, firmware `update`) but no documented commands for setting PINs or managing slots, and reading device state relies on generic third-party `fido2-token` rather than a Solo-specific command. A runtime probe found the official Solo CLI (solo-python) actually fails to even run (`ImportError: cannot import name CTAP1`) due to incompatibility with current fido2 2.x, and firmware hasn't been released in 4 years — concrete evidence the tooling has bit-rotted rather than delivering the claimed scriptable management. missing for 10: working PIN-setting command, slot management, device-state reporting, and a CLI that runs without import errors on current dependencies.

          • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
          • [github] solo2 list # list connected devices (alias: solo2 ls)
          • [claimed-docs] You can "wipe" a device using `fido2-token -R`
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2partialprobed6/10

          fido2-manage is an official open-source Token2 tool that supports PIN set/change, resident-credential (passkey) and biometric slot management, and device info viewing, and a probe confirms it is documented as a CLI, giving genuine scriptable control over FIDO2 keys. However most docs describe it primarily as a Python/tkinter GUI rather than a dedicated CLI, and there's no explicit mention of an 'enable applications' feature or comprehensive CLI usage examples/API reference. missing for 10: explicit CLI command reference/examples, 'enable applications' capability, independent hands-on CLI scripting confirmation.

          • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
          • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
          • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
          • [probe] official CLI documented at https://github.com/token2/fido2-manage
          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

        Sdks

        1. developerOfficial SDKs let me integrate the key into my own desktop and mobile apps

          weight 2 · round drawn
          SoloKeys Solo 2none0/10

          Evidence shows only a device-management CLI (solo2 app admin/list) and firmware-building/customization tooling for the key itself, not any SDK for embedding the key into third-party desktop or mobile applications. The runtime probe even shows the existing Solo Python CLI is broken/bit-rotted, and no library/SDK for app integration is documented anywhere in the pack.

          • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
          • [github] solo2 list # list connected devices (alias: solo2 ls)
          • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2none0/10

          Evidence shows only management/admin tools (fido2-manage GUI/CLI, bulk enrollment for Entra ID, browser-based WebAuthn demo) rather than an official SDK or library for embedding the key's authentication into a developer's own desktop/mobile applications. No mention of a downloadable SDK, API bindings, or mobile library is found anywhere in the pack.

          • [claimed-docs] Open-source cross-platform desktop companion application for managing FIDO2 security keys.
          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
          • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
          • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
          • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
          • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
          • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
          • [probe] official CLI documented at https://github.com/token2/fido2-manage

        Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat

        Where the key works — platforms, browsers, service compatibility catalogs

        Agent approval

        1. ai-native userRequire a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

          weight 1 · round to SoloKeys Solo 2
          SoloKeys Solo 2partialprobed3/10

          Solo 2 documents a generic touch-to-confirm step for WebAuthn/FIDO2 authentication (solokeys-docs-1), which could theoretically gate any human-in-the-loop confirmation, but there is no evidence tying this to AI-agent-initiated action approval flows, agentic tool integrations, or any AI-native ecosystem support. Additionally, runtime evidence shows the official CLI is broken/bit-rotted and firmware hasn't shipped in 4 years, raising doubts about active ecosystem maintenance. Missing for 10: any documentation or integration example of using Solo 2 touch confirmation as an approval gate for AI/agent workflows, evidence of SDK/API hooks for agent tooling, and independent confirmation of this use case.

          • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2none0/10

          Token2's evidence covers FIDO2 key management, PIV, TOTP tools, and WebAuthn demos, but nothing shows integration with AI agents or automated workflows that would use a physical touch as an approval gate for agent-initiated actions. Missing for 10: any documentation of agent/automation integration, an approval-step API or SDK, or a workflow example tying physical touch to AI-agent action authorization.

          • [claimed-docs] Open-source cross-platform desktop companion application for managing FIDO2 security keys.
          • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
          • [claimed-docs] This manufacturer-agnostic tool works with any FIDO2.1 device.

        Compatibility

        1. power userThe key works across my operating systems and browsers, with a published compatibility catalog of supported services

          weight 2 · round to Token2
          SoloKeys Solo 2partialprobed3/10

          Solo 2 claims broad compatibility (any USB port, no drivers, FIDO2/passkey standard, NFC for Android/iOS, OATH/PIV/OpenPGP) but there is no published compatibility catalog listing specific supported services/sites, and a runtime probe shows the official CLI tooling has bit-rotted and firmware hasn't been updated in years, raising doubts about maintained cross-platform support. Missing for 10: a published service/site compatibility list, browser-specific compatibility documentation, and evidence the tooling/firmware is actively maintained to keep pace with OS/browser changes.

          • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
          • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
          • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
          Token2partialclaimed5/10

          Evidence shows solid cross-OS/browser support (Windows control panel, Chromium browsers, macOS/Linux companion app, PIV miniDriver) and manufacturer-agnostic FIDO2.1 tooling, but there is no published catalog listing which third-party services/relying parties are certified compatible with Token2 keys. missing for 10: a published service/RP compatibility catalog, independent cross-browser/OS corroboration beyond vendor docs.

          • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
          • [claimed-docs] If you are using macOS or Linux, you can manage your FIDO2 keys using the tool integrated into the latest Chromium based browsers, such as G…
          • [claimed-docs] You can use the standard Windows control panel tool to manage your key, as long as you run Windows 10 build 1903 or later.
          • [claimed-docs] PIV features can be configured using our all-in-one management tool, the Companion App, which is now also available on macOS.
          • [claimed-docs] This manufacturer-agnostic tool works with any FIDO2.1 device.
          • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management

        Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery

        Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

        Recovery

        1. security engineerThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

          weight 3 · round to Token2
          SoloKeys Solo 2none0/10

          No evidence in the pack discusses backup key enrollment, multi-key registration strategies, or what is/isn't recoverable if a Solo 2 is lost — documentation covers setup, building, and CLI usage but never addresses lockout/recovery planning.

            Token2partialclaimed3/10

            Token2's FAQ includes a 'How Do I Set Up a Backup Key?' entry, indicating some guidance exists, but the evidence pack contains no actual content on what is/isn't recoverable if a key is lost (e.g., resident credentials, PINs, biometrics, or TOTP seeds). Missing for 10: detailed recovery/lockout policy content, explicit statement of non-recoverable data (e.g., resident key private keys), and any independent corroboration of the backup-key workflow.

          Setup

          1. power userFirst-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

            weight 2 · round to Token2
            SoloKeys Solo 2partialprobed3/10

            Docs mention simple plug-and-play basics ('insert into USB port, no software required', 'touch sensor to confirm') but there is no evidence of a dedicated setup app or step-by-step account-registration walkthrough; the FIDO2 side of onboarding is essentially per-website. Additionally, a runtime probe shows the official companion CLI is bit-rotted (import errors) and firmware hasn't been updated in years, undermining confidence in any first-time-setup tooling. Missing for 10: a documented onboarding wizard/app, account-registration walkthrough for accounts, working companion CLI/tooling.

            • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
            • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
            • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
            Token2partialclaimed6/10

            Token2 provides multiple avenues for onboarding: a browser-based FIDO2/passkey demo to test registration (token2-docs-5, token2-docs-16), OS-native guidance for macOS/Linux/Chrome and Windows control panel (token2-docs-13/14/15), a companion GUI app for device/passkey management (token2-docs-1/7/8), and an FAQ entry on setting up a backup key (token2-docs-17). This gives a reasonably guided path but is scattered across docs/tools rather than a single cohesive first-time setup wizard that walks a user through registering with specific real-world accounts (e.g., Google, Microsoft, GitHub). Missing for 10: a unified step-by-step onboarding flow/app tailored to major account providers, and independent user reports confirming ease of first-time setup.

            • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
            • [claimed-docs] Explore FIDO2 and passkey authentication hands-on. Register a security key or passkey, then log in with it — all in your browser using the W…
            • [claimed-docs] No special tool installation is needed to start using the FIDO keys, as most modern browsers will prompt to set a PIN when required
            • [claimed-docs] If you are using macOS or Linux, you can manage your FIDO2 keys using the tool integrated into the latest Chromium based browsers, such as G…
            • [claimed-docs] You can use the standard Windows control panel tool to manage your key, as long as you run Windows 10 build 1903 or later.
            • [claimed-docs] How Do I Set Up a Backup Key?
            • [claimed-docs] Open-source cross-platform desktop companion application for managing FIDO2 security keys.
            • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
            • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…

          Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness

          What runs on the device — open-source firmware, update policy, vulnerability response

          Source

          1. security engineerThe firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

            weight 2 · round to SoloKeys Solo 2
            SoloKeys Solo 2fullprobed8/10

            The Solo 2 firmware is openly published on GitHub, buildable from source, and the 'Hacker' variant explicitly supports flashing custom firmware, letting anyone inspect and verify what runs on the device; this is corroborated by community commentary confirming 'it's open source firmware, not open source hardware.' Updates are also SHA-256 verified before flashing, adding transparency to the update process. missing for 10: no formal independent third-party security audit is cited, and runtime evidence shows the firmware/tooling has not been updated since 2022, raising questions about ongoing maintenance of the open codebase.

            • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
            • [github] On a **Hacker** key you can build and flash your own firmware.
            • [github] `update` downloads the signed release, **verifies its SHA-256**, and flashes it.
            • [community] This is an LPC55S69. So it's open source firmware, not open source hardware.
            • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
            Token2none0/10

            All evidence concerns open-source host-side management tools (fido2-manage GUI, companion app, bulk-enrollment scripts) that run on a computer to manage the keys — none of it addresses whether the actual device firmware running on the Token2 hardware key itself is open source or has undergone independent security audit.

            Updates

            1. security engineerThe vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

              weight 2 · round to SoloKeys Solo 2
              SoloKeys Solo 2disputedcontradicted3/10

              The GitHub docs describe a signed, SHA-256-verified update mechanism (solokeys-gh-2), but there is no evidence of published security advisories or an affected-model lookup, and a runtime probe shows the official CLI is bit-rotted (ImportError against current fido2 lib) and no firmware release has shipped in ~4 years despite ongoing dependency commits — directly undercutting the claim that fixes reliably reach devices. missing for 10: security advisory feed/CVE list, affected-model/version lookup tool, evidence of recent firmware releases actually reaching users, working update tooling.

              • [github] `update` downloads the signed release, **verifies its SHA-256**, and flashes it.
              • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
              Token2none0/10

              Evidence covers key management tools (PIN, passkeys, PIV, SSH) but contains no security advisories, CVE/vulnerability disclosure process, affected-model lookup tool, or firmware update delivery mechanism for Token2 devices.

              Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management

              Keys at organization scale — bulk provisioning, delivery services, IdP policies

              Agent provisioning

              1. ai-native userAn agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

                weight 2 · round to Token2
                SoloKeys Solo 2none0/10

                There is no evidence of any enterprise/fleet management API for ordering, assignment, or pre-registration of keys — the CLI is a local hardware management tool (list, flash, LED), and probe evidence shows no OpenAPI/API docs exist and the CLI itself is bit-rotted. This is a consumer/hacker hardware key product with no enterprise provisioning system at all.

                • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
                • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                • [github] solo2 list # list connected devices (alias: solo2 ls)
                Token2partialprobed3/10

                Token2 ships an open-source CLI (fido2-manage) for local device configuration and a PowerShell bulk-enrollment script that automates pre-registering keys into Microsoft Entra ID via Microsoft's Graph API — some scriptable, agent-drivable provisioning exists. However, there is no evidence of Token2's own documented enterprise API for ordering or assigning keys to users, and probes confirm no OpenAPI/swagger spec exists on their site. missing for 10: a Token2-owned ordering API, an assignment/fleet-management API, and any documented enterprise API surface beyond third-party (Microsoft) integration scripts.

                • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
                • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
                • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
                • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

              Delivery

              1. it adminAn enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

                weight 2 · round drawn
                SoloKeys Solo 2none0/10

                No evidence of any enterprise provisioning/shipping API, console, or fleet-deployment logistics integration; SoloKeys is a consumer hardware key sold via a Shopify store with no fleet-management tooling documented, and CLI/API evidence is limited to device-local admin commands and firmware building. Probes even show bit-rot in the CLI and no API/OpenAPI documentation exists.

                • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
                • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                • [claimed-docs] Pack of colored cases for Solo 2
                • [github] solo2 list # list connected devices (alias: solo2 ls)
                Token2none0/10

                Evidence covers device management, bulk enrollment, and provisioning tools but nothing about a logistics/delivery service (e.g., automated shipping of physical keys to distributed employees) driven by API or console. No fulfillment, shipping, or distribution capability is documented anywhere in the evidence pack.

                Idp

                1. it adminThe key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

                  weight 2 · round to Token2
                  SoloKeys Solo 2none0/10

                  No evidence anywhere in the pack mentions IdP integrations (Okta, Entra ID, Google Workspace), fleet enrollment/management tools, or policy enforcement for hardware-key authentication; evidence only covers WebAuthn/FIDO2 protocol support, firmware building, and hardware details. This is a plausible axis for a security key vendor (many competitors offer admin/fleet consoles), but SoloKeys shows nothing to support it.

                    Token2partialprobed4/10

                    Token2 documents a dedicated Entra ID bulk-enrollment tool leveraging the Graph API, showing concrete IdP integration for one provider, and its keys are standard FIDO2 devices that any IdP could require via WebAuthn policy. However, there is no evidence of Okta or Google Workspace-specific integration tooling, nor documentation of admin-side policy enforcement (e.g., conditional access rules mandating hardware-key auth) — these are typically the IdP's own settings, not something Token2 documents supporting or configuring. Missing for 10: Okta integration evidence, Google Workspace integration evidence, and any documentation of fleet-wide policy enforcement/reporting.

                    • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
                    • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                    • [claimed-docs] the miniDriver is needed to configure smartcard-based certificate enrollment and login with Windows on-premises Active Directory.

                  Provisioning

                  1. it adminProvision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

                    weight 3 · round to Token2
                    SoloKeys Solo 2none0/10

                    Evidence covers individual key setup, CLI device listing/config (`solo2 list`, `admin set led`), and custom attestation-key generation, with one offhand mention of building attestation keys 'for maybe 100,000 devices'—but there is no documented bulk-enrollment workflow, admin console, pre-registration pipeline, or lifecycle/issuance tracking system for organizations. Runtime probes further show the official CLI is broken (ImportError) and no firmware has shipped in 4 years, undercutting any claim of active enterprise tooling.

                    • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
                    • [github] solo2 list # list connected devices (alias: solo2 ls)
                    • [github] solo2 app admin set led 007f7f 00007f # set led to teal (idle) / blue (active) - use 000000 to turn the led off
                    • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                    Token2partialprobed5/10

                    Token2 offers a PowerShell-based bulk enrollment tool for Entra ID (fido2_bulkenroll_entraid) and an open-source fido2-manage CLI/GUI for per-key PIN, biometric, and passkey configuration, which supports pre-registration and bulk configuration workflows. However, there is no evidence of an organization-wide inventory, dashboard, or lifecycle-tracking system for issued keys beyond individual device management and Entra-specific scripting. Missing for 10: centralized fleet inventory/dashboard, cross-platform (non-Entra ID) bulk provisioning, and lifecycle status tracking (issued/revoked/expired) across an organization.

                    • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
                    • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                    • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
                    • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                    • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…

                  Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors

                  The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

                  Certifications

                  1. it adminCertified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

                    weight 2 · round drawn
                    SoloKeys Solo 2none0/10

                    No evidence of FIPS 140 validation or Common Criteria certification anywhere in the pack; only a community comment mentions 'water resistant' informally (solokeys-comm-7), and another comment casts doubt on tamper-resistance claims (solokeys-comm-1). No documented crush resistance or regulated-environment certification exists.

                    • [community] Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…
                    • [community] I'm still curious how the key is tamper resistent when filling it with transparent epoxy... it should be fairly easy to remove the epoxy and…
                    Token2none0/10

                    The evidence pack covers management tools and software (companion apps, FIDO2 demo, PIV miniDriver) but contains no mention of FIPS 140 validation, Common Criteria certification, or physical durability specifications (water/crush resistance) for any Token2 hardware devices. missing for 10: FIPS 140 validation certificates, Common Criteria certification listings, IP rating or crush-resistance test documentation for hardware keys.

                    Connectors

                    1. power userThe lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

                      weight 2 · round drawn
                      SoloKeys Solo 2none0/10

                      Evidence shows Solo 2 exists as a security key with NFC variant and generic USB port compatibility, and community comments mention a 'reversible USB-A'/'reversible usb plug', but there is no evidence of a broader lineup with distinct USB-C vs USB-A SKUs or keychain vs low-profile nano form factors — only a single case/color accessory line is mentioned.

                      • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
                      • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
                      • [community] "Reversible USB-A" now there's a feature I wish we'd see more often!
                      • [community] Solo v2 is much more robust, water resistant, has stronger NFC & reversible usb plug. The micro is a NXP LPC55S6x with extra security featur…
                      • [claimed-docs] Pack of colored cases for Solo 2
                      Token2none0/10

                      The evidence pack focuses entirely on software tools (FIDO2 management apps, TOTP toolset, PIV drivers) and never describes Token2's physical hardware lineup, connector types (USB-C/USB-A), or form factors (keychain, nano). No mention of product SKUs, dimensions, or port types is present, so there's no basis to confirm coverage of power-user form-factor variety. Missing for 10: hardware product listings, connector-type specs, form-factor descriptions (nano/keychain), any comparison chart of models.

                      Nfc

                      1. power userTap the key on my phone over NFC to authenticate in mobile browsers and apps

                        weight 2 · round to SoloKeys Solo 2
                        SoloKeys Solo 2fullclaimed7/10

                        SoloKeys explicitly markets NFC tap-to-authenticate for compatible Android and iOS devices as a feature of Solo 2, supporting WebAuthn/passkeys which work across mobile browsers/apps. Missing for 10: no independent hands-on confirmation of NFC mobile browser/app compatibility, and community discussion focuses on other aspects (tamper resistance, OpenPGP) rather than validating NFC mobile use.

                        • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
                        • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                        • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                        Token2partialclaimed4/10

                        Token2's own tooling confirms its FIDO2 keys support NFC as a communication transport (used by the fido2-manage companion app to manage keys over USB or NFC), which implies NFC-capable hardware, but there is no explicit documentation stating that users can tap the key on a phone to authenticate within mobile browsers or apps via WebAuthn/CTAP2 NFC. Missing for 10: explicit end-user documentation or demo of phone-NFC-based authentication in mobile browsers/apps, and any independent confirmation of this specific mobile use case.

                        • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
                        • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
                        • [claimed-docs] This manufacturer-agnostic tool works with any FIDO2.1 device.

                      Openness — open source, data portability, and self-hosting storiesOpenness

                      Open source, data portability, and self-hosting stories

                      1. ai-native userDo everything through the API that I can do in the UI

                        weight 2 · round to Token2
                        SoloKeys Solo 2none0/10

                        The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          Token2partialprobed4/10

                          Token2 ships an open-source CLI (fido2-manage) that overlaps with much of the companion GUI's functionality — resident credential/passkey management, PIN setup, biometric template management, and SSH key operations can all be scripted — giving some AI-native/automation parity with the desktop UI. However, there is no true REST/HTTP API (probes confirm openapi.json/swagger.json all 404), and several UI-only web tools (TOTP toolset, WebAuthn browser demo, factory reset) have no documented programmatic equivalent. Missing for 10: a formal API surface (REST/OpenAPI) covering all UI functions, CLI/API parity for the web-based demo and TOTP tools, and independent confirmation that CLI coverage is fully equivalent to the GUI.

                          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                          • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
                          • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
                          • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
                          • [claimed-docs] Generate and verify TOTP codes entirely in your browser. Algorithm: SHA-1. All computation happens locally — no seed is ever sent to a serve…
                          • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
                          • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
                          • [probe] official CLI documented at https://github.com/token2/fido2-manage
                          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                        • ai-native userExport all of my data in open formats and leave

                          weight 3 · round to Token2
                          SoloKeys Solo 2none0/10

                          The evidence pack shows Solo 2 supports open standards (WebAuthn, OATH, PIV, OpenPGP) and lets users customize/replace the attestation key or wipe the device, but there is no documentation of any way to export stored credentials/private key material in open formats to migrate elsewhere — by design, FIDO2/PIV/OpenPGP keys generated on-device are non-extractable. missing for 10: any documented data-export/migration path, evidence of extractable key material, or open-format backup/portability tooling.

                          • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                          • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
                          • [claimed-docs] Now to generate & sign the attestation key pair that will go on your device, or maybe 100,000 devices :)
                          Token2partialprobed5/10

                          Token2 supports exporting TOTP seeds as open CSV/JSON files for Entra ID import, and its open-source fido2-manage tool lets users list, download, and rehydrate resident credentials and SSH keys from FIDO2 devices, plus it's explicitly manufacturer-agnostic (works with any FIDO2.1 key), supporting migration away from Token2 hardware without lock-in. However, this covers only specific data types (TOTP seeds, credentials, SSH keys) rather than a full account/data export, and there's no unified 'export everything' feature or documentation. Missing for 10: comprehensive account-wide data export, first-party documentation framing this as a full data portability/exit feature, independent verification of export completeness.

                          • [claimed-docs] Export the current seed as an Entra ID hardware-token import file (CSV or JSON).
                          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                          • [github] SSH security keys: generate, list resident, download (rehydrate), upload to a remote (`ssh-copy-id`), add to the local ssh-agent
                          • [claimed-docs] This manufacturer-agnostic tool works with any FIDO2.1 device.
                          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                        • ai-native userRead the product's source under an open license

                          weight 2 · round to SoloKeys Solo 2
                          SoloKeys Solo 2fullcommunity8/10

                          The firmware source is hosted openly on GitHub (solokeys/solo2), with build instructions, hackable firmware flashing, and even a dedicated 'Hacker' key edition explicitly for reading/modifying source and firmware end-to-end. Community confirms firmware is open source (though hardware/chip is not), corroborating the licensing model. Missing for 10: no explicit license file/name cited, and no independent audit of license terms beyond community mention that firmware (not hardware) is open.

                          • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
                          • [github] On a **Hacker** key you can build and flash your own firmware.
                          • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                          • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
                          • [community] This is an LPC55S69. So it's open source firmware, not open source hardware.
                          Token2partialprobed6/10

                          Token2 open-sources some companion tooling on GitHub (fido2-manage, fido2_bulkenroll_entraid) with real activity (112 stars, recent pushes), letting an AI-native user inspect that code, but the core hardware product/firmware and several web tools (TOTP toolset, FIDO2 demo) are not shown to have public source, and no explicit license file/type is cited. Missing for 10: confirmed OSI license text, source availability for the full product line (not just auxiliary management tools).

                          • [claimed-docs] Open-source cross-platform desktop companion application for managing FIDO2 security keys.
                          • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                          • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
                          • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
                          • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                        • ai-native userSelf-host the core product

                          weight 3 · round to SoloKeys Solo 2
                          SoloKeys Solo 2partialprobed5/10

                          The Solo 2 'Hacker' edition ships with fully open-source firmware that users can build, flash, and customize themselves (own attestation keys, own firmware, full toolchain via Rust/cargo), which is the closest analogue to 'self-hosting' for a hardware security key — no cloud dependency by design. However, runtime evidence shows the surrounding tooling has bit-rotted (solo-python CLI fails on current fido2 libs) and no firmware release has shipped in 4 years, undermining confidence that self-building/self-hosting the core product is currently practical. Missing for 10: a working, up-to-date official build/flash pipeline, and independent confirmation that a user can successfully self-build current firmware today.

                          • [github] Solo 2 Hacker — the same hardware, unlocked. Flash your own firmware, experiment with new features, and learn how a security key works end t…
                          • [github] On a **Hacker** key you can build and flash your own firmware.
                          • [claimed-docs] If you don't want to use the default attestation key that Solo builds with, you can create your own and program it.
                          • [claimed-docs] To build, develop and debug the firmware for the STM32L432.
                          • [claimed-docs] rustup target install thumbv8m.main-none-eabi cargo install flip-link cargo install cargo-binutils cargo install probe-rs-tools
                          • [claimed-docs] cargo build --release --features board-lpcxpresso55,develop
                          • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                          Token2none0/10

                          The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na". (na/none harmonized at arena bring-up — see pipeline/scripts/na-harmonize.ts.)

                          Privacy posture — data-handling and privacy storiesPrivacy posture

                          Data-handling and privacy stories

                          1. ai-native userControl data retention and deletion

                            weight 2 · round to Token2
                            SoloKeys Solo 2partialclaimed4/10

                            Evidence shows credentials are stored only on-device rather than in a vendor cloud (solokeys-docs-2), and a device wipe is possible via the third-party `fido2-token -R` command (solokeys-docs-10), giving users some control over deletion. However, this is not a first-party, documented retention/deletion feature — it's a generic FIDO2 tool tip buried in a GitHub releases page, with no official SoloKeys documentation on data retention policy or granular per-credential deletion. Missing for 10: native SoloKeys CLI/tool for credential management and wipe, official retention policy documentation, and independent confirmation the wipe command works reliably.

                            • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                            • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                            Token2partialclaimed5/10

                            Token2's tools give users direct control to delete data stored on their own security keys — resident credentials/passkeys can be listed, edited, and deleted, biometric templates can be deleted, and factory resets are supported (token2-gh-1, token2-gh-3, token2-docs-7). This covers device-level data deletion but there is no documentation of server-side retention policies, account-level data deletion, or how long any cloud-side telemetry/data is retained. Missing for 10: server-side/account data retention policy documentation, explicit data-deletion request process for any cloud-stored data, independent confirmation of retention practices.

                            • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                            • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
                            • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
                            • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
                          2. ai-native userOpt out of telemetry and usage tracking

                            weight 2 · round to SoloKeys Solo 2
                            SoloKeys Solo 2partialclaimed3/10

                            Solo 2 is explicitly marketed as working entirely locally ('stays on your key, not their cloud', no software/drivers required), which implies no cloud usage-tracking to opt out of, but there is no explicit telemetry policy, settings, or opt-out control documented for the CLI/companion tooling. missing for 10: explicit telemetry/privacy policy statement, any opt-out toggle or setting, confirmation that the solo2 CLI/companion app sends no usage analytics.

                            • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                            • [claimed-docs] No more sticky notes. No more forgotten passwords. No more texts with six digit codes.
                            • [claimed-docs] Insert your Solo 2 into any USB port. No software or drivers required.
                            Token2none0/10

                            The evidence pack contains no mention of telemetry, analytics, or usage tracking, nor any settings to opt out of such tracking, for Token2's desktop companion app, fido2-manage tool, or web tools. missing for 10: any documentation of data collection practices, a privacy policy reference, or a telemetry opt-out mechanism.

                            Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage

                            FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

                            Credential management

                            1. power userList and delete the passkeys stored on my key and know its credential capacity before it fills up

                              weight 2 · round to Token2
                              SoloKeys Solo 2none0/10

                              No evidence describes per-passkey listing, deletion, or credential-capacity reporting; the only related CLI ops shown are `solo2 list` (lists connected devices, not credentials) and `fido2-token -R` (wipes the entire key, not selective deletion). Additionally, a runtime probe shows the official CLI is now broken (ImportError against modern fido2 libs), further undermining any credential-management workflow.

                              • [github] solo2 list # list connected devices (alias: solo2 ls)
                              • [claimed-docs] You can "wipe" a device using `fido2-token -R`
                              • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                              Token2partialprobed7/10

                              fido2-manage (with GUI and CLI) lists resident credentials/passkeys with user handle, allows delete and edit metadata, and works over USB/NFC for any FIDO2.1 device, directly covering list/delete of passkeys stored on the key. However, there is no explicit evidence of a feature reporting remaining credential capacity or slot count before the key fills up. Missing for 10: explicit credential-capacity/slots-remaining reporting, independent hands-on confirmation of listing/deleting behavior.

                              • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                              • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
                              • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
                              • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
                              • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
                              • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

                            Fido2

                            1. security engineerThe key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

                              weight 3 · round to Token2
                              SoloKeys Solo 2fullclaimed7/10

                              Solo 2 is marketed explicitly as a passkey/WebAuthn security key that stores credentials on-device rather than in a cloud, and general FIDO2 passkey support inherently implies discoverable/resident credentials for usernameless sign-in ([solokeys-docs-2], [solokeys-docs-9], [solokeys-gh-1]). Missing for 10: explicit documentation of resident-key storage limits/technical FIDO2 conformance details, and independent hands-on confirmation of a usernameless login flow (only marketing copy corroborates this).

                              • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                              • [claimed-docs] No more sticky notes. No more forgotten passwords. No more texts with six digit codes.
                              • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                              Token2fullprobed8/10

                              Token2 sells FIDO2 hardware keys explicitly supporting resident/discoverable credentials (passkeys), with documentation and an open-source companion tool (fido2-manage) that lists, edits, and manages resident credentials including user handles, plus a browser-based demo to register and authenticate via WebAuthn without typing a username. Independent GitHub evidence corroborates the resident-key management feature set (list with user handle, delete, edit metadata). missing for 10: no explicit third-party/independent test confirming passwordless username-less sign-in flow in production RP scenarios, and no FIDO Alliance certification citation for discoverable credential compliance.

                              • [github] Resident credentials (passkeys): list (with user handle), delete, edit metadata
                              • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management
                              • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
                              • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
                              • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
                              • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…
                            2. power userThe key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

                              weight 2 · round drawn
                              SoloKeys Solo 2partialprobed6/10

                              Solo 2 is a standard WebAuthn/FIDO2/U2F device that would work with any relying party supporting those standards (Google, GitHub, Microsoft, many password managers), and vendor docs confirm FIDO2/passkey and U2F-style support plus broad protocol coverage (OATH, PIV, OpenPGP). However there is no explicit first-party or independent testing evidence confirming compatibility with each named service, and a runtime probe shows the companion CLI tooling has bit-rotted with no firmware update in 4 years, raising doubts about ongoing maintenance/compatibility. Missing for 10: explicit per-service (Google/GitHub/Microsoft/password manager) compatibility confirmation, independent hands-on verification across these services, and evidence of active firmware maintenance to keep pace with protocol changes.

                              • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                              • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                              • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
                              • [probe] PROBE runtime negative (recorded 2026-09-15): the official Solo CLI has bit-rotted — `uvx --from solo-python solo version` fails with 'Impor…
                              Token2partialclaimed6/10

                              Token2 provides standards-based FIDO2/WebAuthn/U2F hardware keys with strong first-party tooling for Microsoft Entra ID enrollment and a general WebAuthn demo/testing tool, implying broad cross-service compatibility as a certified FIDO2.1 device. However, there is no direct documentation or independent confirmation of successful registration/use with Google, GitHub, or specific password managers. Missing for 10: explicit vendor or third-party evidence of working as a 2FA/passkey with Google, GitHub, and named password managers.

                              • [claimed-docs] This tool streamlines the process of registering FIDO2 security keys in Microsoft Entra ID by leveraging the FIDO2 Provisioning Graph API.
                              • [claimed-docs] Register a security key or passkey, then log in with it — all in your browser using the WebAuthn API.
                              • [claimed-docs] This manufacturer-agnostic tool works with any FIDO2.1 device.
                              • [claimed-docs] Explore FIDO2 and passkey authentication hands-on. Register a security key or passkey, then log in with it — all in your browser using the W…
                              • [github] fido2-manage is a tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management

                            User verification

                            1. security engineerThe key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

                              weight 2 · round to Token2
                              SoloKeys Solo 2none0/10

                              Evidence only shows a capacitive touch sensor for user presence confirmation (solokeys-docs-1), which is a presence test, not FIDO2 user verification via PIN or biometric. No documentation or community evidence mentions a settable FIDO2 PIN or biometric sensor on Solo 2, so the specific 'stolen key alone cannot authenticate' verification story is unevidenced.

                              • [claimed-docs] When prompted, touch the capacitive sensor on your Solo 2 to confirm.
                              • [github] It's a USB+NFC device that protects your accounts with passkeys/WebAuthn, and also speaks OATH (TOTP/HOTP), PIV, and OpenPGP.
                              • [claimed-docs] Everything in Solo 2 plus NFC tap-to-authenticate for compatible Android and iOS devices.
                              Token2fullprobed8/10

                              Evidence confirms FIDO2 PIN setup/change and biometric template enrollment/management via the companion tool and fido2-manage (PIN management, min PIN length, biometric templates: list, rename, delete, enroll), and browsers/OS natively prompt for PIN when required, satisfying on-device user verification against theft. missing for 10: no independent/hands-on third-party testing confirming UV enforcement during actual authentication ceremonies, and no explicit CTAP2 'uv' flag/attestation documentation.

                              • [github] PIN management: set, change, set minimum PIN length, min-PIN-length RP allow-list... Biometric templates (bio models): list, rename, delete,…
                              • [claimed-docs] It provides a simple interface to view device information, manage passkeys, change PINs, and perform factory resets.
                              • [claimed-docs] No special tool installation is needed to start using the FIDO keys, as most modern browsers will prompt to set a PIN when required
                              • [claimed-docs] fido2-manage is an open-source tool allowing to manage FIDO2.1 devices over USB or NFC, including Passkey (resident keys) management. It als…
                              • [probe] PROBE runtime (recorded 2026-09-15): Token2's open-source fido2-manage — 'An open-source FIDO2.1 key management tool (with a GUI) under diff…

                            Not comparable on these axes

                            1. ai-native userPlug MCP servers into this product so it can use their tools

                              weight 3 · not comparable
                              SoloKeys Solo 2n/a

                              Solo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator), not an AI agent or platform with tool-use capability; MCP server integration is not a fair axis for this product category.

                                Token2n/a

                                Token2 is a hardware security key/authentication vendor with FIDO2/PIV management tools; MCP server integration for AI tool-use is entirely outside its product category.

                                • ai-native userConnect an agent via an official MCP server

                                  weight 3 · not comparable
                                  SoloKeys Solo 2n/a

                                  SoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/OATH/PIV/OpenPGP authenticator); it has no product role as an agent tool server and no evidence of an MCP server offering. Connecting AI agents via MCP is outside this product's category.

                                    Token2n/a

                                    Token2 is a hardware security key vendor with management tools (desktop apps, CLI, browser demos), not an AI agent or a platform that could plausibly expose an MCP server for agent connectivity; this axis is a category error for this product type.

                                    • ai-native userIssue scoped/least-privilege API credentials for an agent

                                      weight 2 · not comparable
                                      SoloKeys Solo 2n/a

                                      SoloKeys Solo 2 is a hardware security key (FIDO2/WebAuthn/PIV/OpenPGP authenticator); it has no concept of API credentials or agent-scoped access tokens, which is entirely outside its product category.

                                        Token2n/a

                                        Token2 is a hardware security key (FIDO2/TOTP/PIV) vendor with management tools for keys and passkeys; it has no concept of API credentials or agent-scoped access tokens. Issuing scoped least-privilege API credentials for an AI agent is outside this product's category entirely.

                                        • ai-native userSubscribe to events via webhooks

                                          weight 2 · not comparable
                                          SoloKeys Solo 2n/a

                                          Solo 2 is a hardware security key (USB/NFC FIDO2 device); webhooks/event subscriptions are not a fair capability for this product category, which has no server-side or event-driven architecture.

                                            Token2n/a

                                            Token2 is a hardware security key/FIDO2 vendor with device management tools; webhooks for event subscription are not a fit for this product category, which involves no event-driven API or service to subscribe to.

                                            • ai-native userGet AI-generated insights and suggestions from my data inside the product

                                              weight 2 · not comparable
                                              SoloKeys Solo 2n/a

                                              SoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OATH/PIV/OpenPGP); it does not process or store user data in a way that would support AI-generated insights or suggestions. This axis is a category error for an authentication hardware token.

                                                Token2n/a

                                                Token2 is a hardware security key vendor with management/provisioning tools (FIDO2 device management, TOTP tools, PIV tools); it has no data analytics, AI-generated insights, or suggestion features, and this is a category mismatch rather than a missing capability for its product type.

                                                • ai-native userSet up automations that run autonomously in the background

                                                  weight 2 · not comparable
                                                  SoloKeys Solo 2n/a

                                                  SoloKeys Solo 2 is a hardware security key for authentication (passkeys/FIDO2/OTP); it has no automation/workflow-orchestration capability and the concept of 'background autonomous automations' does not apply to a physical security token requiring touch confirmation.

                                                    Token2n/a

                                                    Token2 is a hardware security-key/FIDO2 management product; there is no concept of autonomous background automations in its evidence. This is a category mismatch (agenticness axis) rather than a missing feature for this authentication-tool product.

                                                    • ai-native userDelegate tasks to a built-in AI assistant inside the product

                                                      weight 3 · not comparable
                                                      SoloKeys Solo 2n/a

                                                      SoloKeys Solo 2 is a hardware security key for FIDO2/WebAuthn authentication, not an AI assistant or agentic platform; delegating tasks to a built-in AI assistant is a category error for this product type.

                                                        Token2n/a

                                                        Token2 is a hardware security-key/authentication management product (FIDO2/PIV/TOTP tooling); there is no AI assistant feature or agentic task-delegation concept applicable to this product category.

                                                        • ai-native userOperate the product with natural-language commands

                                                          weight 2 · not comparable
                                                          SoloKeys Solo 2n/a

                                                          Solo 2 is a hardware security key/authenticator; operating it is inherently physical (touch sensor, insert USB, tap NFC) or via CLI commands, not natural-language interaction. This is a category error—natural-language operation is not a fair axis for a hardware auth token.

                                                            Token2n/a

                                                            Token2 is a hardware security-key/FIDO2 management product (GUI apps, CLI tools, browser demos); natural-language command operation is a wrong axis for this category of product — no evidence of any NL interface, and none would be expected.

                                                            • ai-native userExplore an interactive API reference with runnable examples

                                                              weight 2 · not comparable
                                                              SoloKeys Solo 2n/a

                                                              SoloKeys Solo 2 is a hardware security key with a CLI/firmware toolchain, not an API/SaaS product; there is no API surface for which an interactive reference with runnable examples would be a meaningful offering. The probes confirm no OpenAPI/API docs exist, but this reflects the product category, not a missing capability.

                                                              • [probe] PROBE openapi: all candidate paths 404 (https://docs.solokeys.dev/openapi.json, https://docs.solokeys.dev/swagger.json, https://docs.solokey…
                                                              • [github] solo2 list # list connected devices (alias: solo2 ls)
                                                              Token2none0/10

                                                              Token2 is a hardware security key vendor with no evidence of an API reference at all — the probes explicitly show no OpenAPI/swagger spec exists (404s across all candidate paths) and no llms.txt or docs.md exposure. There's no indication of an interactive, runnable API explorer anywhere in the evidence.

                                                              • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
                                                              • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
                                                              • [probe] PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md
                                                            • ai-native userTest against a sandbox environment without touching production data

                                                              weight 1 · not comparable
                                                              SoloKeys Solo 2n/a

                                                              SoloKeys Solo 2 is a physical hardware security key; the concept of a 'sandbox environment vs production data' for AI-native testing does not apply to this product category.

                                                                Token2n/a

                                                                Token2 is a hardware security key vendor with companion tools (FIDO2 management, TOTP generation, PIV/miniDriver tools), not a platform or API with distinct production/sandbox environments; the concept of testing against a sandbox without touching production data does not apply to this product category.

                                                                • ai-native userRely on versioned APIs with a documented deprecation policy

                                                                  weight 2 · not comparable
                                                                  SoloKeys Solo 2n/a

                                                                  SoloKeys Solo 2 is a hardware security key that implements standard protocols (FIDO2/WebAuthn, OATH, PIV, OpenPGP); it is not an API-driven service or SDK for which a versioned API deprecation policy would be a meaningful axis. This story is a category error for this product type.

                                                                    Token2none0/10

                                                                    Token2 is a hardware security key vendor with desktop/CLI tools for FIDO2/PIV management; there is no evidence of any versioned public API, and probes confirm no OpenAPI/Swagger spec exists (404s across all candidate paths). No documentation of API versioning or deprecation policy is present anywhere in the evidence.

                                                                    • [probe] PROBE openapi: all candidate paths 404 (https://www.token2.com/openapi.json, https://www.token2.com/swagger.json, https://www.token2.com/api…
                                                                    • [probe] PROBE llms.txt: HTTP 404 at https://www.token2.com/llms.txt
                                                                    • [probe] PROBE docs-md: HTTP 404 at https://www.token2.com/site/page/tools-for-fido-security-keys.md
                                                                  • ai-native userDefine rules that trigger actions automatically on events

                                                                    weight 3 · not comparable
                                                                    SoloKeys Solo 2n/a

                                                                    Solo 2 is a hardware security key (FIDO2/passkey/OATH/PIV authenticator); it has no rules/automation engine or event-trigger system, and this axis is a category error for an authentication hardware token.

                                                                      Token2n/a

                                                                      Token2 is a hardware security-key/authentication vendor with management tools for FIDO2/PIV devices; there is no automation/event-trigger rules engine in its product category, and the evidence pack covers device management, provisioning, and demos only, not conditional automation.

                                                                      • ai-native userSchedule recurring jobs or workflows

                                                                        weight 2 · not comparable
                                                                        SoloKeys Solo 2n/a

                                                                        SoloKeys Solo 2 is a hardware security key for authentication; scheduling recurring jobs/workflows is not a capability that applies to this product category.

                                                                          Token2n/a

                                                                          Token2 is a hardware security key/authentication tool vendor; nothing in its product scope relates to scheduling recurring jobs or workflows, which is an automation/orchestration concern outside a security-key management product's category.

                                                                          • ai-native userVersion, review, and roll back my automations

                                                                            weight 1 · not comparable
                                                                            SoloKeys Solo 2n/a

                                                                            SoloKeys Solo 2 is a hardware security key/authenticator; 'automations' with version/review/rollback is not a concept applicable to this product category.

                                                                              Token2n/a

                                                                              Token2 is a hardware security-key/FIDO2 management product; 'automations' with version/review/rollback is a concept from workflow/agent automation platforms, not applicable to a security key management toolset.

                                                                              • ai-native userChoose where my data is stored (region/residency)

                                                                                weight 2 · not comparable
                                                                                SoloKeys Solo 2n/a

                                                                                Solo 2 is a local hardware security key whose keys never leave the device ('stays on your key, not their cloud') — there is no cloud data storage or region selection concept applicable to this product category.

                                                                                • [claimed-docs] Passkeys are replacing passwords across the web. Solo 2 supports the passkey standard — except yours stays on your key. Not their cloud.
                                                                                Token2n/a

                                                                                Token2 is a hardware security-key/authenticator vendor with local management tools; it does not store user data in a cloud service, so data residency/region selection is not an applicable axis for this product category.

                                                                                • ai-native userPrevent my data from being used to train AI models

                                                                                  weight 3 · not comparable
                                                                                  SoloKeys Solo 2n/a

                                                                                  Solo 2 is a hardware security key (FIDO2/passkey/OATH/PIV/OpenPGP authenticator); it has no relationship to AI model training data or consent controls over such use. This story is a category error for this product type.

                                                                                    Token2n/a

                                                                                    Token2 is a hardware security key/FIDO2 authentication vendor; it has no AI model training data pipeline or data-usage policy relevant to AI training. This axis is a category error for a hardware authentication product line.