Security Stack Logo
YubiKey logo

Hardware Security

YubiKey

Hardware security keys for phishing-resistant MFA and passwordless authentication.

YubiKey Overview

What it does

YubiKey is a hardware security key for phishing-resistant multi-factor authentication (MFA) and passwordless login that keeps private keys inside a secure element they never leave. During FIDO2 registration each credential is cryptographically bound to the registering site's origin, so the key refuses to sign challenges from look-alike phishing domains. A touch, PIN, or fingerprint confirms user presence, and YubiKey 5 Series keys on firmware 5.7 or later store up to 100 passkeys with no battery, software agent, or network connection required.

How it works

Each key runs several authentication applications side by side: FIDO2/WebAuthn and FIDO U2F for web and cloud sign-in, a PIV-compatible smart card for Windows, macOS, and Linux login and PKI, OpenPGP for signing and encryption, and OATH-TOTP, OATH-HOTP, and Yubico OTP for systems without FIDO support. Firmware 5.8 adds CTAP 2.3, hardware-backed passkey signatures for document signing and Secure Payment Confirmation, and enterprise attestation reporting serial numbers to up to 16 identity providers. YubiKey as a Service pairs subscription keys with YubiEnterprise Delivery to 199 locations and FIDO Pre-reg, which ships keys already enrolled against Okta, Ping Identity, or Versasec.

Credentials and traction

The YubiKey 5 FIPS Series is FIPS 140-3 validated (certificate 5291, Overall Level 2) and enables NIST SP 800-63B Authenticator Assurance Level 3; YubiEnterprise services hold a SOC 2 Type II attestation. Yubico was named Best Security Company of the Year at the 2025 Cyber Security Awards and one of PCMag's Best Tech Brands for 2025. More than 22 million YubiKeys have shipped to over 160 countries; T-Mobile deployed 200,000 keys and Hyatt Hotels uses them for passwordless access.

Key Capabilities

mapped to solution categories
Hardware Authentication Keys

Provides an enterprise portal for registering, managing, and auditing hardware key deployment across the organization at scale.

Implements the FIDO2 WebAuthn specification for phishing-resistant authentication, binding authentication to the registered origin, preventing credential use on phishing domains.

Supports FIDO2, FIDO U2F, PIV (smart card), and TOTP on a single device, enabling use across web applications, VPNs, OS login, and legacy systems.

Supports NFC tap-based authentication for mobile devices alongside USB-C and USB-A, determining which use cases and device types the key supports.

Uses FIDO attestation during registration to verify the make and model of each hardware key, so an enterprise can require only approved, certified authenticators.

On-key fingerprint sensor with templates stored in the secure element, enabling PIN-free FIDO2 and PIV user verification. Availability varies across key models and vendors.

Passwordless Authentication

Binds passkeys to specific device hardware (TPM, Secure Enclave), the private key cannot be exported or used from a different device.

Implements FIDO2/WebAuthn for phishing-resistant authentication, binding credentials cryptographically to the registered origin to prevent use on phishing domains.

Supports parallel operation of password and passwordless authentication during transition, allowing gradual user migration without a hard cutover.

Enables passwordless authentication for applications that do not natively support FIDO2, using reverse proxy, credential injection, or identity broker patterns.

Compliance

certifications
FIPS 140-2FIPS 140-3SOC 2 Type II

Integrations

compatible tools
1PasswordActive DirectoryAWSAWS IAM Identity CenterAWS Identity and Access Management (IAM)AzureBitwardenBitwarden for BusinessCiscoCloudflareDashlaneDelinea Secret ServerDockerDropboxDropbox for Business & TeamsDuo for FederalDuo SecurityGitHubGitLabGoogle AccountsGoogle CloudGoogle WorkspaceHYPR True Passwordless MFAIdira by Palo Alto NetworksKeeper Business & EnterpriseKubernetesLastPassLastPass Enterprise and TeamsLinuxmacOSMicrosoft - Entra ID with smart cardsMicrosoft 365Microsoft accountsMicrosoft Active Directory Federated Services (ADFS) with smart cardsMicrosoft Entra IDOktaOpenAIPing IdentityRed Hat Enterprise LinuxSalesforceSalesforce.comSSHVersasec vSEC:CMS

Implementation & support

Support channels
24/7 SupportCustomer Success Manager (CSM)DocumentationKnowledge BaseTicketing Portal

Info last updated on September 7, 2026

Buyers

Start a shortlist with YubiKey

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.