Skip to main content
TrustRadius
Yubico YubiKeys

Yubico YubiKeys

Overview

What is Yubico YubiKeys?

Yubico YubiKeys make the internet safer with phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts. The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks, and…

Read more
Recent Reviews

Yubico Review

8 out of 10
May 16, 2024
Incentivized
When we access sensitive servers, there is always a need to have a 2-step verification process. So one step is always what you know, which …
Continue reading

Yubico Review

9 out of 10
May 16, 2024
Incentivized
There are various use cases that we use Yubico YubiKeys for. All of our authentication to the Fido server is through Yubico YubiKeys, and …
Continue reading

Yubico Review

10 out of 10
May 16, 2024
Incentivized
It's for personal usage, I've used it for password managers and that kind of stuff. For the corporate, I would say at the moment …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

Entry-level set up fee?

  • Setup fee optional
For the latest information on pricing, visithttps://www.yubico.com/yubienterprise…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Starting price (does not include set up fee)

  • $3.94 per month per user
Return to navigation

Product Demos

Setting up the Security Key

YouTube
Return to navigation

Product Details

What is Yubico YubiKeys?

Yubico YubiKeys supports phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts.

Stopping phishing attacks and account takeovers before they start
The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks. And users experience fast and easy authentication with a simple touch or tap. For organizations that wish to secure sensitive data stored in servers, the YubiHSM offers an ultra-portable hardware security module, bringing great flexibility and affordability to any organization. For organizations that wish to secure sensitive data stored in servers, the YubiHSM offers a portable hardware security module, bringing great flexibility and affordability to any organization.

Deploying modern hardware MFA at scale
Organizational security is only effective when users adopt it. Distributing Yubico YubiKeys and onboarding users is simple and comes with expert guidance, enterprise subscriptions and global turnkey delivery services. A single Yubico YubiKey can be used right out-of-the-box across personal and work online accounts, and across 800+ IT systems and online services which makes it easier for the organization and the user to enhance protection for online accounts.

Yubico YubiKeys Features

  • Supported: Security: Two-factor, multi-factor and passwordless authentication
  • Supported: Authentication: Phishing defense using modern FIDO protocols that stops account takeovers
  • Supported: Multi-protocol capabilities: A single YubiKeys supports a range of authentication protocols such as FIDO2 (passkey)/WebAuthn, FIDO U2F, Smart card/PIV, OTP
  • Supported: Range of form factors: USB-A, USB-C, NFC enables stronger security across a range of legacy and devices
  • Supported: Supports legacy and modern environments: Secures legacy on-premises and modern cloud environments
  • Supported: Enterprise-ready: Hardware MFA available as a “YubiKeys as a Service” model to help deliver strong phishing-resistant MFA

Yubico YubiKeys Videos

Accelerating Zero Trust strategy with the YubiKey delivering strong, phishing-resistant MFA
The Bridge to Passwordless Authentication
Phishing-resistant MFA to meet new cyber insurance requirements

Yubico YubiKeys Technical Details

Deployment TypesOn-premise, Software as a Service (SaaS), Cloud, or Web-Based
Operating SystemsWindows, Linux, Mac
Mobile ApplicationApple iOS, Android

Frequently Asked Questions

Yubico YubiKeys make the internet safer with phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts. The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks, and delivers users authentication with a simple touch or tap.

Yubico YubiKeys starts at $3.94.

The most common users of Yubico YubiKeys are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(136)

Attribute Ratings

Reviews

(1-25 of 38)
Companies can't remove reviews or game the system. Here's why
May 20, 2024

Yubico Review

Score 10 out of 10
Vetted Review
Verified User
Incentivized
So we use the YubiKey for securing most of our cloud services, like Office 365, Microsoft 365 mainly, but also other things like password managers. And as far as the services will let us, we try to use mainly the Yubikeys for the physical security tokens and trying to use them for passwordless access to avoid the risks of password theft.
  • The setup is very easy. It's well documented and it's well supported with most services.
  • The backup situation is a hard problem to solve, but it needs to be resolved sooner or later because as it is now, if you have two Yubikeys, you have to enroll them both. When you lose one, you have to remember which one to deactivate and that's a hassle. Fortunately that doesn't happen very often. But having a backup Yubikey that you don't have to enroll everywhere but they can switch over to would be a dream.
I'd say it's very appropriate to secure your cloud access and also for login, it's less appropriate for local login. I'd say logging into Windows computers can be hard to do correctly. And on Mac computers, it's a no go as far as I can tell.
May 16, 2024

Yubico Review

Score 8 out of 10
Vetted Review
Verified User
Incentivized
When we access sensitive servers, there is always a need to have a 2-step verification process. So one step is always what you know, which is like a password. The second step is something that you have, which is the Yubico YubiKeys. So Yubico YubiKeys provides that 2-step authentication process without going through the hassle and it's also convenient because of the laptops that we have. I think it supports both Windows and Mac and I think we have both kinds of users and they both use it and it seems to work well.
  • It works all the time and it works well, so I think that's all I care about and it that's the work that it's supposed to do really well.
  • It can be about access control because either right now it's just you have access or you don't have access. I think there can be a use case where you are allowed a particular set of servers and not a particular set of servers. I think maybe it's there or we don't use it, but I haven't seen that. I think I've used Yubico YubiKeys at two companies and I haven't seen that. Maybe that's something that can be added.
It's well suited. I think the only issue is you need to have the key and if you lose it, then maybe there is a potential issue. I think those are the only concerns I have.
May 16, 2024

Yubico Review

Score 9 out of 10
Vetted Review
Verified User
Incentivized
There are various use cases that we use Yubico YubiKeys for. All of our authentication to the Fido server is through Yubico YubiKeys, and we also use it for the VPN right now. A lot of my teammates are using it for the Linux authentication tool, and we also store digital certificates, so we use it for PKI. So there are a lot of use cases that we use Yubico YubiKeys for.
  • I think the best thing is it has a lot of capacity and it's very, very secure. It can store a lot of private keys versus all the other products. We have reviewed a few other products, but Yubico YubiKeys gives a lot more capabilities than some of the other security key brands.
  • I think the only thing that I feel is the capability to store more keys on it, and it's a bit expensive compared to the other security manufacturers. So if we really have to sell it to our customers, they're not very comfortable paying for the high price, but then you're paying for more features.
We've been using this for one of our products where the requirement is AL3 where you can only use the web certified security gear and it offers the highest level of security and authentication. So I think the key that Yubico YubiKeys is providing is the best for that use case. For less appropriate, I think right now, I mean with pass keys, the sync pass keys becoming a thing. I don't know how for a consumer market you become a person would not want to keep a security key. It depends on the level of security that you're looking for. So for a consumer market for probably my social medias, I won't use a security key. I probably sync it to the cloud.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Primary use case is logging in that is authentication and we use for multiple products. One is logging into the machine. The other things we use is the based off of the roles and the responsibilities. We have various apps that require additional authentication after opening the laptop, the server, and that's where we use YubiKey and it's integrated with backend, author and off.
  • Primarily it's very convenient to use. Then also it assures when we open the machine, the authentication is on when we open the machines, which I refer to laptop, that's a very primary use case for us and that has been consistent along.
  • It requires a little bit of setup. I think that's where we had a little additional resources spent on it to integrate our current ortho dot with the YubiKey. When we bring in and the newer models, when we bring in, there's a little more maintenance that we need to do on and off every time. So that's something I request to look into to make it more easier.
Server authentications is where we don't see much of a use case. So far my primary role and also the use cases I have seen so far is using the laptop and authenticating the apps in the laptop. So those are the two major use cases I have seen. But this can be expanded to servers as well because I'm not in the infrastructure area, so I do not know whether you have it or not. But that's one thing I feel like you can look into expanding
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use it for a second factor in authentication for logging into stuff.
  • It's very, very cost effective and is quite reliable.
  • I can't think of any. They're nice and small too. I kind of like that. I don't take up space on the laptop really.
I like to use it as another factor in authentication. I think it's really great that way. It's supported by industry standards, open standards.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I can talk more about it in my personal capacity. So I use it to secure all of my own personal services, Google, social media, government, login services, basically anything that supports two FA and supports a hardware token, I'll use that over OTP, SMS, or anything is just simply the most secure solution I have found. I've always heard of people getting, "oh, my account's been hacked, my things, my account's being drained." I don't have this problem because I use hardware security module.
  • It's very easy to use. So I use the USBC and NFC one, so not only can I either insert it into a USB-C port, which the new iPhone 15 or iPad has, but you can also just tap it using NFC. So it's really easy across the broad range of devices to authenticate.
  • The only con is hardware based, so if it's in the other room you might have to get off the sofa to go get it. But aside from that, I mean I think that trade off is worth the security provides.
Anything where you value the security of access to data? Financial data, whether it's personal or professional, is highly useful because it provides us with that extra layer of physical security protection. If the data is something you're signing up for where you don't really care, it doesn't really matter at that point if it's a throwaway account on an internet site. But anything where security is important, definitely.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use it mostly for our MFA. It helps enforce MFA more easily without having to pick up my phone for an OTP.
  • Easy and lightweight, very quick to output needed keys.
  • Reliable and always functional.
  • It would be nice if it had an OTP feature.
  • The nano is nice but too easy to hit and accidentally send passcodes.
Yubikeys are good for MFA and ensuring specific access to some of our resources.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We evaluated its use for employee authentication and conducted proof-of-concept with a small number of users. Most users preferred the current 2FA with the RSA key. However, Yubikey presents distribution challenges compared to a soft token that could be sent electronically to users. Also, we ran into challenges when end-users would lose their Yubikey, requiring a new key to be distributed and the old key revoked.
  • Highly secure storage of credentials.
  • Portability of credentials to any device.
  • Multi-factor, biometrics authentication.
  • Doesn't work with USB-C.
  • Improved mobile device support.
  • Cost point could be lower.
It is great for secure authentication for workers who physically come into the office and can pick up a physical key. Distribution is a significant challenge for remote workers; ideally, a soft token approach similar to competitors would be helpful to deal with this challenge. Also, escrow of keys so that credentials can move to a new key when the key is lost.
May 09, 2024

Great security key

Score 10 out of 10
Vetted Review
Verified User
Incentivized
Use my Yubico YubiKeys for 2FA during the login to enterprise SSO.
  • Reliable
  • Good size and compatibility
  • Not sure it is a Yubico YubiKeys problem, but mobile browsers do not always prompt for a PIN code, which is a bit scary
If a service supports security keys, I always enable it and enroll my Yubico YubiKeys. On the other hand, I prefer passkeys if they are supported and allowed, which is the case for our enterprise SSO. However, even in this case, I use Yubico YubiKeys for new platforms / browsers or as a backup.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I've used a YubiKey 5 for several years for a 2nd factor authentication method to log into our VPN as well as adding it to many of my personal accounts. I've appreciated that it offers multiple authentication methods for different platforms both for work and personal accounts.
  • It makes logging in with a second factor very convenient
  • I like the small form factor making it easy to carry around
  • The different authentication profiles it provides makes it nice for personal and business use
  • It would be nice if the new biometric readers also offered all the same features as the older Yubico YubiKeys 5. Having everything in one.
It just works. I've been using the devices for several years and it just works. They are easy to add to multi accounts.
May 09, 2024

Yubi key.

Score 7 out of 10
Vetted Review
Verified User
Incentivized
Use it to authenticate to Okta and other security settings that require 2fa.
  • Easy to install.
  • Integrates well.
  • No OTP code support.
It is easy to set up. But when I need the OTP code, it is not available, and it is annoying to switch it off.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Yubico YubiKeys are used a secure form of MFA for our internal tools and also for my personal use. As a SaaS company, we also support the use of Yubico YubiKeys as a form of 2FA through either the OTP or WebAuthn protocols. We always recommend that our customers set up some form of 2FA, with the hardware keys being considered the most secure.
  • Quick to install
  • Reliable activation
  • Many options of form factors
  • Management software is confusing
  • Limited room for passkeys (25) at time of writing
It's great for security and ensuring that your accounts are essentially hack proof. One problem is traveling, if you leave your key in your hotel room or even back at home, you are pretty stuck. I would love to see a Yubico YubiKeys form factor that's designed to fit easily into wallets, such as a credit-card form factor.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use YubiKeys for multi-factor authentication. Some organization still use same channels as password reset/ registration such as email to enable MFA, and the amount of breaches due to email compromise is high so having a device such as YubiKey would provide extra assurance on the strength of the Organizations security posture in terms of authentication
  • Key generation
  • Strong keys/ offline key storage
MFA
Score 10 out of 10
Vetted Review
Verified User
Incentivized
To authenticate to things like Okta, Entra ID in multiple regions, as well as OTP to OpenVPN both with yubicloud and greenradius
  • Simple and complex OTP
  • FIDO2 auth with major browsers
  • End user instruction/videos for HOW to use Yubico YubiKeys and what each function actually does.
Anywhere MFA is use Yubico YubiKeys are well suited, assuming the mechanism can handle it.
Less appropriate are really just legacy type systems that don’t even allow MFA implementation at all.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Yubico YubiKeys for MFA across multiple applications as our standard method of MFA for all users
  • Top tier MFA
  • Easy to implement
  • Secures accounts
  • FIDO standard
  • More robust 3rd party support
Well suited for any account that needs secured with MFA that supports it. Not well suited for homegrown applications
Antônio Mocelim | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Yubico YubiKeys to validate users and guarantee that they're who is using the credentials.
  • Simple to validade
  • Very strong
  • Compatible with note and mobile
  • Some kind of geo localization
  • Any kind of validation about the person
For me the best device to validate the right use of credentials, free of fishing
May 08, 2024

Yubico YubiKeys

Score 10 out of 10
Vetted Review
Verified User
Incentivized
I use Yubico YubiKeys to access corporate and private SaaS application. Different form-factors help to auth on laptop and mobile devices. Thanks.
  • Passwordless authentication
  • Secure auth
  • FIDO2 support
  • Extended integration with Identity Providers
  • Built-in functionality like Apple tags to simply find hardware keys
Very reliable. Variety of options. Great customer support
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Yubico YubiKeys has a fantastic solution for securing my logins to very important websites like email services, cloud providers and many others. I don't only use to improve the security on those services but use it for SSH logins to servers and GitHub. Over the years I have gathered multiple Yubico YubiKeys to make sure I always have one at hand. They have never let me down and are very reliable and even the USB one that I have for 10 years still works. I wouldn't be able to live without them thanks to the sense of protection they provide.
  • Securing logins to important services
  • SSH Protection
  • Github and Gitlab push protection
  • Initially getting my SSH keys working on it wasn't that easy, but thanks to some fantastic open-source tooling this now works very reliable
  • Get more websites to support it
I trust Yubico YubiKeys to keep my logins safe and protect me from compromise and lockout. Over the years I have made sure to gather multiple Yubico YubiKeys to have an extra fail safe.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Yubico YubiKeys are crucial to our operations for secure access. I recommend them to our customers on a regular basis.
  • Phishing resistant authentication
  • Strong auth without mobile phones
  • Nothing - I love Yubico YubiKeys!
Yubico YubiKeys are phenomenal for scenarios where phishing resistant authentication is needed; and especially for areas where mobile phones are not appropriate.
May 01, 2024

YubiKeys at an MSP

Michael Hasner | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
ResellerIncentivized
YubiKeys have been a fantastic addition to our offering, especially in areas where employees refuse to utilize their cellphones for MFA. I also utilize them for high security systems where having phishing resistant MFA is an absolute must.
  • Phishing resistant MFA
  • Ease of use, particularly with types of devices available
  • Availability of FIPS encrypted devices for GovCloud environments
  • The YubiKey management apps could be easier to use
YubiKeys are appropriate everywhere. There are no reasons not to use them for every environment, as they’re a perfect option and remove the need for a phone to be the primary login option. They have a broad range of functionality, work with most sites (even more if you federate an SSO with Microsoft 365, or another IDP that supports FIDO keys), and can even be utilized as a smart card for Windows and/or Mac logins.
Chris Cowherd | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
I have implemented Yubikey hardware security keys for additional authentication and access control to our most sensitive IT infrastructure and accounts. Yubikeys provides multi-factor authentication, requiring users to have a physical security key, username, and password to gain access. We initially rolled out Yubikeys to our server admins and engineers who require privileged access to our production servers, databases, and network devices. Requiring the Yubikey as a second factor prevents unauthorized access if their credentials are compromised. It also protects against phishing attempts.
  • Provides additional factors for authenticating against critical systems.
  • Significantly reduces the chance of a successful phishing attempt.
  • Can function as your primary credential for passwordless authentication.
  • Extremely durable - I've had the same Yubikeys in use for years.
  • Cross-platform - can be used on all mainstream operating systems and mobile devices.
  • Yubikeys can get lost so you will need to plan for recovery.
  • Biometric Yubikeys can be finicky so you may need a backup authentication option.
  • Yubikeys can be shared or given to someone else.
  • If you use them for time-based authentication, they store a limited number of codes.
For securing your most sensitive accounts, systems, and data that require strong access controls, YubiKeys offer excellent protection by strengthening your organization's authentication strategy. Rather than relying solely on passwords or mobile-based two-factor methods for your highest-risk user logins, YubiKeys provide rock-solid multi-factor authentication tied to a tamper-resistant physical device. This eliminates many of the vulnerabilities associated with passwords and mobile authenticators alone. By requiring both a password and the possession of a YubiKey for access, you can drastically reduce the risks of unauthorized logins, even in the event of password leaks. YubiKeys also provide phishing protection by cryptographically verifying legitimate sites, preventing spoofing attacks.For infrastructure like production servers, databases, and network equipment where compromised access would be catastrophic, YubiKey-secured logins should be mandatory for administrators and engineers. Similarly for business-critical software as a service accounts and registrar/DNS logins where hijacking could shut down the business.
February 02, 2024

MFA on Your Keyring

Score 10 out of 10
Vetted Review
Verified User
Incentivized
I have used multiple generations of Yubico YubiKeys and watched them improve over time. I like to keep them as a backup method for any account that can't be easily reset. If you lose your primary MFA device you can have a YubiKey locked in a safe that gives you a physical key back into the digital world. We also use them for employees who don't have or won't use a personal device as an MFA token. This is a better solution than buying company-owned smartphones.
  • MFA
  • Small device
  • Good price
  • I would like to have my fingerprint unlocked. This would make the device good for two factors in one device.
They are a great backup MFA device because it isn't safe to only have one MFA token. They are also good for anyone who doesn't want to use a smartphone as their MFA device. They have a FIPS-validated solution for anyone who works in government or government contracting.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Yubico YubiKeys are an essential part of our logins. When hired, every employee in my business unit receives a YubiKey 5c Nano along with their laptop. Since we are a hybrid workforce and many of us work from home, this allows us to log in with phishing-resistant MFA to all of our SaaS applications that are protected by Duo. Since WebAuthn is the standard from the start, this ensures that the highest level of protection is enforced from an authentication perspective. This has solved the issue of wondering whether or not users are logging in securely from disparate locations. It is also easy for users to authenticate with the tap of a finger to access critical applications - even in a Passwordless workflow!
  • Ease of use
  • Multiple authentication protocols
  • Cross-compatibility
  • Reduce the cost of keys
  • Honestly, Yubico YubiKeys are great and have all the features we need
  • No other criticisms - it just works!
Yubico YubiKeys are great for hybrid applications that support both modern and legacy authentication methods. For example, for web-based applications that are federated behind an IdP, the Yubico YubiKey WebAuthn (FIDO2) mechanism is the gold standard of phishing-resistant MFA. The same Yubico YubiKey (if a supported model) can also be used as an OTP hardware token so that the user does not have to use 2 different roaming authenticators for logging into all their applications. One YubiKey to rule them all!
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We initially implemented Yubico YubiKeys as a replacement to our OTP token-based MFA solution, due to the old solution no longer satisfying our security requirements. We started by using them in the role of PIV/CAC for cert-based authentication but soon expanded to using them as FIDO2 devices for other systems. The flexibility and ease with which we were able to deploy this highly secure 2-factor solution are highlights of the product for us.
  • Certificate-based authentication, in PIV/CAC smart card role
  • FIDO2 device, used with 3rd party systems which are difficult to implement cert-based authentication on
  • Reliable, long-lasting hardware token, with no batteries to replace, perpetual licensing, and simple management.
  • Looking forward to pre-provisioning, especially with Okta
  • Some type of centralized management system, some way to automate inventory management and tracking, at least at the moment of deployment
Yubico YubiKeys shines when used as part of a larger MFA solution. It provides a very flexible component, however, it remains dependent on the infrastructure and environment in which it is deployed.
February 02, 2024

Love Yubico YubiKeys!

Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Yubico YubiKeys company-wide to secure all employee accounts. This is used for accounts on all 3rd party platforms that support it.

We implemented Yubico YubiKeys after having problems with constant phishing attempts being sent to our employees. We feel that the phishing-resistant protections provided by the Yubico YubiKeys, greatly increases our security posture.
  • Phishing resistance
  • Easy passwordless
  • Cross-platform passkeys
  • Get more platforms to support it
  • Better NFC compatibility
  • Cheaper
I love using Yubico YubiKeys everywhere it is supported. I believe it provides the best security and ease of use.

Unlike SMS or Authenticator based MFA, Yubico YubiKeys provide phishing resistance to protect against MITA. It also provides easy passwordless login which eases the user flow and decreases the need for password resets
Return to navigation