How the YubiKey works (2024)

Protect the Digital You with the most secure and easy-to-use security key.

How the YubiKey works (1)

Proven security at scale

How the YubiKey works (2)
Stop account Takeovers

YubiKeys are trusted by the world’s largest companies and users have experienced 0 account takeovers.

Learn More

How the YubiKey works (3)
Easy to Setup and Support

It’s as easy as USB! Access your accounts 4x faster than other 2FA, and cut support calls by 92%

Learn More

One key for many applications

The YubiKey works with hundreds of enterprise, developer and consumer applications, out-of-the-box and with no client software. Combined with leading password managers, social login and enterprise single sign on systems the YubiKey enables secure access to millions of online services.

How the YubiKey works (5)

How it works

A single YubiKey has multiple functions for securing your login to email, online services, apps, computers, and even physical spaces. Use any YubiKey feature, or use them all. The versatile YubiKey requires no software installation or battery so just plug it into a USB port and touch the button, or tap-n-go using NFC for secure authentication.

How the YubiKey works (6)
Register your YubiKey

To use the YubiKey, go to the Security Settings of a supported service and select two-factor authentication.

How the YubiKey works (7)
Insert YubiKey & tap

On a computer, insert the YubiKey into a USB-port and touch the YubiKey to verify you are human and not a remote hacker.

How the YubiKey works (8)
Tap on phone

For NFC-enabled phones, just tap your NFC-enabled YubiKey against the phone to complete authentication.

How the YubiKey works (9)

Multi-protocol security key secures modern and legacy systems

The YubiKey supports WebAuthn/FIDO2, FIDO U2F, one-time password (OTP), OpenPGP 3, and smart card authentication offering a solution that bridges legacy and modern applications. Yubico and the YubiKey will continue to grow with your evolving business needs.

The YubiKey supports one-time passcodes (OTP)

OTP supports protocols where a single use code is entered to provide authentication. These protocols tend to be older and more widely supported in legacy applications. The YubiKey communicates via the HID keyboard interface, sending output as a series of keystrokes. This means OTP protocols can work across all OSs and environments that support USB keyboards, as well as with any app that can accept keyboard input.

Learn more about OTP

How the YubiKey works (10)
How the YubiKey works (11)

The YubiKey enables smart card authentication

Smart cards are another supported protocol on the YubiKey. The YubiKey identifies itself as a smart card reader with a smart card plugged in so it will work with most common smart card drivers. The YubiKey allows three different protocols to be used simultaneously – PIV, as defined by the NIST standard for authentication; OpenPGP for encryption, decryption, and signing; and OATH, for client apps like Yubico Authenticator.

Learn more about Smart Card/PIV

Enable modern authentication with FIDO U2F

FIDO U2F is another protocol supported by the YubiKey. The U2F protocol provides strong authentication without requiring a complex backend or framework to support it. Turning traditional authentication on its head, FIDO U2F makes the authentication device, like the YubiKey, the authentication provider. It issues unique keys to the services it is authenticating against, ensures each service does not have any information about the others, and removes the need for a central authentication service.

Learn more about FIDO U2F

How the YubiKey works (12)
How the YubiKey works (13)

Experience passwordless authentication with FIDO2

FIDO2 is the passwordless evolution of FIDO U2F. The overall objective for FIDO2 is to provide an extended set of functionality to cover additional use cases, with the main driver being passwordless login flows. The U2F model is still the basis for FIDO2 and compatibility for existing U2F deployments is provided in the FIDO2 specs.

Learn more about FIDO2

Get world class authentication security

For less than a cup of coffee per user/month

Get Started

How the YubiKey works (14)
Find the right Yubikey

Take the quick Product Finder Quiz to find the right key for you or your business.

How the YubiKey works (15)
Get protected today

Browse our online store today and buy the right YubiKey for you.

How the YubiKey works (2024)

FAQs

How does YubiKey actually work? ›

Yubikeys are a type of security key made by Yubico that makes two-factor authentication easier. Yubikeys use U2F, which is based on public-key cryptography. Using a Yubikey allows you to do a one-touch login and have as many Yubikeys as you want.

How many passwords can YubiKey hold? ›

OATH (Yubico Authenticator) - the YubiKey 5's OATH application can hold up to 32 OATH-TOTP credentials (AKA authenticator app codes).

Is one YubiKey enough? ›

A Yubikey can be used for an unlimited number of accounts if you're using WebAuthn. You also have an unlimited number of accounts for U2F.

Should I leave my YubiKey plugged in all the time? ›

Do I need to keep my yubikey plugged in all the time? A. No, you only need to insert your yubikey when you are prompted to do so during login. Leaving it plugged in could result in the yubikey being lost or damaged.

Does YubiKey work without Internet? ›

Mobile-free, secure authentication

Unlike SMS codes and mobile push authentication, YubiKeys do not require a cellular connection to operate. In fact, they don't even require batteries or have any other external dependency.

Can I use YubiKey for all my passwords? ›

The YubiKey works with Password Safe to protect your passwords using two-factor authentication (2FA). Both a master password and a YubiKey are needed to enable access to your Password Safe file, which contains the usernames, websites, passwords and other information for all of your online accounts.

What are the best uses for YubiKey? ›

Using a Microsoft account with a YubiKey gives you quick and easy access to services such as Outlook.com, Office, Skype, OneDrive, Xbox Live, Bing and more. Just tap your YubiKey and you're in. No password required.

What if someone steals my YubiKey? ›

If you lose your Yubikey, you can still use your phone authenticator app, but you cannot create a backup Yubikey. However, Yubikey also provides methods to recover your account, so you can get a replacement. An advantage to Yubikey is that it comes on a USB that cannot be identified.

Does 1 password work with YubiKey? ›

Staying safe online is a habit that needs to be nurtured, and using a password manager is the simplest way to upgrade your online account security. 1Password's YubiKey integration delivers strong password management to both personal users and organizations of all sizes.

Can YubiKey replace a password manager? ›

The solution: YubiKey + password manager

Using a password manager application is the best way to create and maintain unique and strong passwords for all your account logins, and protecting your password manager with a YubiKey is the most secure way to manage multiple digital credentials.

Can I use one YubiKey for multiple devices? ›

Can I use one YubiKey with multiple devices? Yes! Just plug your YubiKey into any computer and log in the way you normally would. That's really it—you'll be able to log in to all of your accounts, same as before.

Is there a better alternative to YubiKey? ›

Feitian security keys come with most of the same security features and protocols as the Yubico options do, and they offer a variety of connectivity choices, including USB-C and NFC and even a fingerprint option. Feitian is also the company that makes Google's keys.

How many YubiKeys should I have? ›

Q: How many spares should I get? A: Many of our customers actually purchase several spares for maximum security and peace of mind. This is not a bad idea when guarding extremely critical accounts. Starting off, you should be fine with 1-2 spare keys.

What is the life expectancy of a YubiKey? ›

The counter starts at zero and is incremented each time the device is plugged in. Two bytes for the session counter allows for 2(2*8) = 65,536 sessions. In other words, you can plug in the Yubikey three times a day for almost 60 years before running out of session counters.

Does YubiKey read fingerprint? ›

and add compatible services. It's easy to get started with your YubiKey Bio! Yubico Authenticator for Desktop 5.1 and later enables you to enroll and manage fingerprints on all supported operating systems. Use the Yubico Authenticator for Desktop on your Windows, Mac, or Linux computers.

Do I need to eject my YubiKey? ›

How can I safely remove my YubiKey? The YubiKey identifies as a USB keyboard to your PC, and does not need to be ejected when removed – you can just pull it out!

Is YubiKey the best security? ›

Best all-round security key

The YubiKey USB authenticator has multi-protocol support, including FIDO2, FIDO U2F, Yubico OTP, OATH-TOTP, OATH-HOTP, smart card (PIV), OpenPGP, and challenge-response capabilities, providing solid hardware-based authentication.

Does YubiKey work on a cell phone? ›

YubiKey for Mobile

Securing the mobile experience with strong authentication for iOS, Android, and Windows 10.

Can YubiKey be tracked? ›

YubiKeys can be easily numbered, tracked, and managed as a state asset. If a user leaves the organization, the YubiKey can be quickly and securely reassigned to another user.

Is YubiKey a VPN? ›

The YubiKey secures remote access by enabling phishing-resistant 2FA or MFA for leading VPN applications such as Pulse Secure and Cisco AnyConnect, as well as other remote access applications, using smartcard (PIV), one-time password (OTP), FIDO U2F, or FIDO2 capabilities.

Can you store things on a YubiKey? ›

The YubiKey is designed to be a user authentication or identification device. The applications on the YubiKey hardware are limited to contain only authentication secrets and keys either generated internally or loaded by users; none of the functions on a YubiKey are designed for mass storage of data.

Does YubiKey store private keys? ›

Owners can secure private keys with the YubiKey by importing them or, better yet, generating the private key directly on the YubiKey. Private keys cannot be exported or extracted from the YubiKey. The YubiKey supports various methods to enable hardware-backed SSH authentication.

Why is a YubiKey better than Google Authenticator? ›

Authenticator apps provide a layer of security and are a convenient option for use by many, but they are still vulnerable to phishing due to the 30-second window. Security keys, like the YubiKey, are considered to be both more convenient and more secure.

Can I use YubiKey with my Amazon account? ›

YubiKeys for AWS IAM satisfies strong authentication

AWS IAM and root users can use their YubiKey as a multi-factor authentication (MFA) device to add an extra layer of protection on top of their user name and password.

Will a magnet damage a YubiKey? ›

Static magnetic fields from permanent magnets does not affect the Yubikey.

Why do companies use YubiKey? ›

The YubiKey is an easy to use extra layer of security for your online accounts. A single YubiKey has multiple functions for securing your login to email, online services, apps, computers, and even physical spaces. key to trust. Login with your login credentials and the YubiKey to prevent account takeovers virtually.

Can YubiKey get malware? ›

Yubico's YubiKey is built on a foundation of strong authentication. This robust resistance to phishing offers malware protection because it hinges on the ability to detect these attacks before they take place.

Why does YubiKey ask for a PIN? ›

Why they appear. FIDO2 is made up of two components - WebAuthn on the service provider end, and CTAP2 on the YubiKey end. PIN prompts are a result of a WebAuthn setting known as User Verification.

What is the secret key for YubiKey? ›

Answer: The secret key aka AES key stored in the "yubikeys" table is actually the AES Key of your YubiKey. We hope this helps!

How many accounts can you link to YubiKey? ›

You can add up to five YubiKeys to your account.

Which password manager works best with YubiKey? ›

Password Manager YubiKey Compatibility
  • Bitwarden: Premium users of Bitwarden can use the YubiKey in two-step logins.
  • LastPass: All YubiKey models can work with all paid plans, including Premium, Families, Enterprise, and Teams.
May 5, 2022

Can I duplicate my YubiKey? ›

Therefore you cannot duplicate or back up a YubiKey or Security Key. For this reason, we recommend having a backup device and registering both with your accounts so that if one is lost or broken you can use the other to log in.

Does YubiKey prevent phishing? ›

Yubico, the inventor of the YubiKey, is a global authentication leader that makes secure logins easy and available to everyone. YubiKeys are the gold standard for phishing-resistant multi-factor authentication (MFA), enabling one single device to work across any number of services.

Do you tap or insert your YubiKey? ›

To view the credential, tap and hold your YubiKey on the back of your phone where the NFC antenna is located. Yubico Authenticator displays the six digit code associated with this credential. This is the code you need to enter to authenticate when using two-factor authentication.

Can I reuse an old YubiKey? ›

Should YubiKeys be reused? YubiKeys could be reused. There are a number of considerations that need to be taken into account when deciding on whether or not to reuse YubiKeys. Besides removing and reissuing credentials, tracking systems may need to be updated.

Why is YubiKey so expensive? ›

It is costly to design, mould, manufacture, sell and support a hardware product, even something as small as this. Since you don't want your 2FA company to go out of business there is good value in knowing they have a stable business model that can actually support a company rather than just burning capital.

How much is YubiKey good for the Internet? ›

Yubico is providing Security Keys at “Good for the Internet” pricing - as low as $10 per key. Yubico will ship the keys to customers directly.

Why do I need two YubiKeys? ›

We at Yubico always recommend having more than one YubiKey. This way, one key can be used as a primary key, and the other can be used as a spare. Please note that for security reasons, the firmware of our products does not allow stored secrets to be read, meaning it is not possible to “clone” or "duplicate" a YubiKey.

Can YubiKey get damaged? ›

Our product's quality is top of mind for us and if your YubiKey is damaged we ask that you submit a support ticket with the following information. The order number or copy of invoice from when you purchased the YubiKey. A valid shipping address in the event we send a replacement YubiKey to you.

Can a YubiKey be hacked? ›

> A Yubikey can be hacked to send arbitrary keystrokes - but that's of limited usefulness.

Is YubiKey a one time purchase? ›

Buy YubiKeys at Yubico.com | Shop hardware authentication security keys. Opt for greater flexibility with subscription, compared to a one-time purchasing model. Businesses with 500+ users qualify for YubiEnterprise Subscription. YubiKeys as a service, via subscription, delivers peace of mind in an uncertain world.

Can someone use a stolen YubiKey? ›

If you lose your Yubikey, you can still use your phone authenticator app, but you cannot create a backup Yubikey. However, Yubikey also provides methods to recover your account, so you can get a replacement. An advantage to Yubikey is that it comes on a USB that cannot be identified.

Do you have to touch YubiKey? ›

In short, when using the YubiKey as a Touch-Triggered OTP authenticator with a computer, the end user will always follow these steps: Plug the YubiKey directly into the computer. Place the text cursor in the field where an OTP needs to be entered. Touch the gold contact on the YubiKey.

How does YubiKey generate code? ›

The passcode is generated by concatenating various YubiKey fields into a 128-bit long string and encrypting the string with the YubiKey configuration's unique 128-bit AES key.

What happens when you press a YubiKey? ›

Instead of a code being texted to you, or generated by an app on your phone, you press a button on your YubiKey. That's it. Each device has a unique code built on to it, which is used to generate codes that help confirm your identity. Press the button and you can log in.

Can YubiKey replace passwords? ›

FIDO2 offers expanded authentication options including strong single factor (passwordless), two factor, and multi-factor authentication. With these new capabilities, the YubiKey enables the replacement of weak username/password credentials with strong hardware-backed cryptographic key pair credentials.

How long does a YubiKey last? ›

Q: How long does the YubiKey last? A: We don't artificially limit the life-span of any YubiKey. The internals of the YubiKey's security algorithms currently limits each key to 30+ years of usage. The Yubikey is powered by the USB port and therefore requires no battery and there is no display on it that can break.

Can a YubiKey be cloned? ›

For security, the firmware on the YubiKey does not allow for secrets to be read from the device after they have been written to the device. Therefore you cannot duplicate or back up a YubiKey or Security Key.

Top Articles
Latest Posts
Article information

Author: Frankie Dare

Last Updated:

Views: 6488

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Frankie Dare

Birthday: 2000-01-27

Address: Suite 313 45115 Caridad Freeway, Port Barabaraville, MS 66713

Phone: +3769542039359

Job: Sales Manager

Hobby: Baton twirling, Stand-up comedy, Leather crafting, Rugby, tabletop games, Jigsaw puzzles, Air sports

Introduction: My name is Frankie Dare, I am a funny, beautiful, proud, fair, pleasant, cheerful, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.