
Hardware Security
YubiKey
Hardware security keys for phishing-resistant MFA and passwordless authentication.
YubiKey Overview
What it does
YubiKey is a hardware security key for phishing-resistant multi-factor authentication (MFA) and passwordless login that keeps private keys inside a secure element they never leave. During FIDO2 registration each credential is cryptographically bound to the registering site's origin, so the key refuses to sign challenges from look-alike phishing domains. A touch, PIN, or fingerprint confirms user presence, and YubiKey 5 Series keys on firmware 5.7 or later store up to 100 passkeys with no battery, software agent, or network connection required.
How it works
Each key runs several authentication applications side by side: FIDO2/WebAuthn and FIDO U2F for web and cloud sign-in, a PIV-compatible smart card for Windows, macOS, and Linux login and PKI, OpenPGP for signing and encryption, and OATH-TOTP, OATH-HOTP, and Yubico OTP for systems without FIDO support. Firmware 5.8 adds CTAP 2.3, hardware-backed passkey signatures for document signing and Secure Payment Confirmation, and enterprise attestation reporting serial numbers to up to 16 identity providers. YubiKey as a Service pairs subscription keys with YubiEnterprise Delivery to 199 locations and FIDO Pre-reg, which ships keys already enrolled against Okta, Ping Identity, or Versasec.
Credentials and traction
The YubiKey 5 FIPS Series is FIPS 140-3 validated (certificate 5291, Overall Level 2) and enables NIST SP 800-63B Authenticator Assurance Level 3; YubiEnterprise services hold a SOC 2 Type II attestation. Yubico was named Best Security Company of the Year at the 2025 Cyber Security Awards and one of PCMag's Best Tech Brands for 2025. More than 22 million YubiKeys have shipped to over 160 countries; T-Mobile deployed 200,000 keys and Hyatt Hotels uses them for passwordless access.
Key Capabilities
mapped to solution categoriesProvides an enterprise portal for registering, managing, and auditing hardware key deployment across the organization at scale.
Implements the FIDO2 WebAuthn specification for phishing-resistant authentication, binding authentication to the registered origin, preventing credential use on phishing domains.
Supports FIDO2, FIDO U2F, PIV (smart card), and TOTP on a single device, enabling use across web applications, VPNs, OS login, and legacy systems.
Supports NFC tap-based authentication for mobile devices alongside USB-C and USB-A, determining which use cases and device types the key supports.
Uses FIDO attestation during registration to verify the make and model of each hardware key, so an enterprise can require only approved, certified authenticators.
On-key fingerprint sensor with templates stored in the secure element, enabling PIN-free FIDO2 and PIV user verification. Availability varies across key models and vendors.
Binds passkeys to specific device hardware (TPM, Secure Enclave), the private key cannot be exported or used from a different device.
Implements FIDO2/WebAuthn for phishing-resistant authentication, binding credentials cryptographically to the registered origin to prevent use on phishing domains.
Supports parallel operation of password and passwordless authentication during transition, allowing gradual user migration without a hard cutover.
Enables passwordless authentication for applications that do not natively support FIDO2, using reverse proxy, credential injection, or identity broker patterns.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with YubiKey
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.