FIDO Specifics

This section describes YubiKey integration with Fast Identity Online (FIDO): FIDO2, Web Authentication (WebAuthn), and FIDO Universal 2nd Factor (U2F).

FIDO2 Features

For an overview of the FIDO2 features that are supported with the 5.7.x and later firmware, see 5.7 - 5.6 Firmware Specifics.

The FIDO2 standard offers the same high level of security as FIDO U2F, since it is based on public key cryptography. In addition to providing phishing-resistant two-factor authentication, the FIDO2 application on the YubiKey allows for the storage of resident credentials, also called discoverable credentials. As these credentials can accommodate the username and other data, this enables truly passwordless authentication on sites and applications that support the WebAuthn protocol. YubiKeys in the 5 Series can hold up to 25 resident keys.

FIDO2 PINs and Fingerprint Templates

PINs and fingerprint templates, collectively referred to as “User Verification” or UV for short, are one of the enhancements from U2F included in FIDO2. FIDO2 UV enables single device Multi-Factor Authentication (MFA). It enables people to use a single device (the YubiKey) to provide two authentication factors: something they have - the YubiKey, and something they know (a PIN) or a unique physical attribute (a biometric fingerprint template on the YubiKey Bio).

FIDO2 credentials on a YubiKey cannot be accessed without either the PIN or on the YubiKey Bio, the fingerprint. There are no backdoors to bypass the UV protections. This is the main reason that Yubico recommends registering a minimum of two YubiKeys on each web site you use, to ensure you continue to have access to that site if you lose access to the first YubiKey. If the fingerprint sensor on the YubiKey Bio is damaged, the PIN is the only method available to use the credentials on the device.

Because the PIN or fingerprint is only used to authenticate with the YubiKey, and the protection against brute-force attacks (a maximum of eight incorrect PIN attempts before the YubiKey FIDO2 application locks), there is no security benefit to regularly changing the PIN unless there is reason to believe it has been compromised. Changing the FIDO2 PIN will not invalidate any credentials on the YubiKey. However, previous values for the PIN are not stored within the YubiKey, so if the current PIN is forgotten, an older PIN will not be recognized.

Locking FIDO2 Credentials

Note

By default, no PIN is set.

The resident credentials can be left unlocked and used for strong single-factor authentication, or they can be protected by a PIN for two-factor authentication. This is achieved by performing user verification (UV) at the time of authentication. Where UV is the user tapping the YubiKey sensors or the BIO sensor,and entering a PIN value that is stored on the YubiKey.

See Minimum PIN Length.

Discoverable Credentials: Passkeys

Another new feature added in FIDO2 is discoverable credentials. Formerly referred to as resident keys, discoverable credentials are credentials which contain information about the site or service the credential belongs to, including the address and account username.

These credentials can be more convenient for web sites that support them, because they allow secure login without requiring users to enter a username. That is, the site or service validates the user through the stored discoverable credentials on YubiKey. Users authenticate their login with a tap on the Yubikey and do not need to enter a username.

Not all web sites or service providers offer support for discoverable credentials. In these cases, no information is stored on the YubiKey.

FIDO over CCID

As of YubiKey Firmware 5.8, FIDO over Chip Card Interface Device (CCID) allows CTAP 2.x commands to be carried using ISO7816 APDU (Application Protocol Data Unit) messaging over the USB CCID smart card interface instead of the USB HID (Human Interface Device) FIDO interface.

This means FIDO operations can run through the operating system’s smart card stack (PC/SC), using the same communication model as traditional smart card applications. For platforms, this provides a standards-defined alternative transport for CTAP that integrates with existing smart card infrastructure. For RPs, no WebAuthn changes are required as transport selection is handled by the platform. However, broader transport support increases deployment reliability in managed environments.

CTAP 2.x supports transport binding using Application Protocol Data Unit (APDU) over USB CCID (ISO7816) and NFC (ISO14443). This allows FIDO commands to be carried through the smart card (PC/SC) stack instead of through the USB HID FIDO interface. SCP11b secure channel support is currently NFC-only. Extending it to CCID and USB enables transport-agnostic secure provisioning for all key types and can support services such as Yubico Remote Pre-Registration.

This means FIDO operations can run through the operating system’s smart card stack (PC/SC), using the same communication model as traditional smart card applications. For platforms, this provides a standards-defined alternative transport for CTAP that integrates with existing smart card infrastructure. For RPs, no WebAuthn changes are required as transport selection is handled by the platform. However, broader transport support increases deployment reliability in managed environments.

Note

Where power consumption issues may occur, such as in with some MacBooks, consider disabling this option.

Default Values

PIN: None set.

YubiKeys are generally shipped without a PIN. The user sets the PIN. Some YubiKeys shipped through the YubiKey as a Service, can have a pre-registered PIN, that the user is forced to change upon first use.

AAGUID Values

An AAGUID (Authenticator Attestation GUID) is a 128-bit identifier indicating the type of the authenticator. The FIDO2 specification states that an AAGUID must be provided during attestation.

New AAGUIDs are issued for new YubiKey products that support FIDO2, or when existing YubiKey products have FIDO2 features added or removed.

For the complete list of AAGUIDs, see our the article on our Support site, YubiKey hardware FIDO2 AAGUIDs.

Supported Extensions

As of YubiKey Firmware 5.8, the YubiKey 5 Series supports CTAP 2.3 and 2.2 Authenticator API 2.3 and Defined Extensions 2.3.

As of YubiKey Firmware Prior 5.7.4, the YubiKey 5 Series supports CTAP 2.1 Authenticator API 2.1 and Defined Extensions 2.1.

For YubiKeys with Firmware Prior 5.7.4, the YubiKey 5 Series supports the AppID extension (appid) as defined by the W3C Web Authentication API specification. This extension allows U2F credentials registered using the legacy FIDO JavaScript APIs to be used with WebAuthn. That means if you register a YubiKey in the 5 Series on a website that used U2F at that time and later upgrades to FIDO2, your U2F credentials continue to work on that website.

FIDO2 Extensions Available per Firmware Version
Extension and feature Firmware Versions
5.8.x 5.7.x 5.6.x 5.5.x 5.4.x 5.3.x 5.2.x 5.1.x 5.0.x
Standards and Algorithms
ECC P256 Credentials yes yes yes yes yes yes yes yes yes
EdDSA/Ed25519 Credentials yes yes yes yes yes yes yes    
ECC P384 Credentials yes yes yes            
CTAP Extensions
Credential Protection
credProtect
yes yes yes yes yes yes yes    
HMAC-Secret
hmac-secret
yes yes yes yes yes yes yes    
HMAC-Secret MakeCredential
hmac-secret-mc
yes                
Third Party Payment
authentication
thirdPartyPayment
yes                
CTAP Authenticator API
PIN Protocol v2 yes yes yes yes yes        
Credential Blob
credBlob
yes yes yes yes          
Authenticator Large Blob,
largeBlobKey required
4kB 4kB 1kB 1kB          
Attestation
Enterprise Attestation yes yes yes            
Attestation Formats
attestationFormats
yes yes              
Attestation Formats Preference
attestationFormatsPreference
yes                
PIN Management
Force PIN Change yes yes yes yes          
Minimum PIN Length
minPinLength
yes yes yes yes          
Maximum PIN Length
maxPinLength
yes                
PIN Complexity extension
pinComplexityPolicy
yes                
Count when user verifies PIN
uvCountSinceLastPinEntry
yes                
Credentials
Credential Management yes yes yes yes yes yes yes    
Always Require User
Verification alwaysUV
yes yes yes yes          
Make Credential UV
Not Required
yes yes yes yes          
Persistent PIN User
Access Token (PPUAT)
yes                
Persistent Credential
Management Read Only
(PCMR)
yes                
YubiKey Functions
Biometric Enrollment yes yes yes yes          
Built-in UV (fingerprint) yes yes yes yes          
Long Touch Reset yes                
previewSign yes                
YubiHSM Auth yes 1 yes yes yes yes        

Note

  1. YubiHSM Auth change without deleting and recreating.

CTAP Specifics

Client to Authenticator Protocol (CTAP) protocol, a specification in FIDO2, is supported on YubiKeys. CTAP 2.1 is supported on YubiKey firmware 5.7.x or later. CTAP 2.3 is supported on YubiKey firmware 5.8.x or later.

Because CTAP implementation is developer focused, for additional information, see Yubico’s Developer site for Client To Authenticator Protocol (CTAP) - FIDO2 Developer Guide.

See also:

Enterprise Attestation with FIDO 2

CTAP 2.3 and YubiKey Firmware 5.8, supports a post-quantum enabled ecosystem, attestationFormatsPreference option in authenticatorGetInfo. This allows greater control and flexibility in determining the capabilities of authenticators. Currently more of a future proofing feature, it allows potential expansion as alternate attestation formats become available.

The YubiKey firmware 5.8 API communicates supported attestation formats, preparing for a post-quantum cryptography (PQC) enabled ecosystem. Though currently, there are no standard post-quantum attestation formats defined. If one is defined in the future, this GetInfo extension enables platforms to determine which formats are supported by a security key.

See CTAP 2.3 authenticatorGetInfo.

As of YubiKey firmware 5.7 through custom configured keys, Enterprise Attestation (EA) enables pre-defined Relying Parties (RPs), such as Identity Providers (IdPs), to read the YubiKey serial number during FIDO2 registration.

This satisfies a variety of asset tracking requirements, and can aid in account recovery by allowing an end user to prove they have a specific FIDO2 device.

In addition to support from the RP and/or Identity Provider (IdP), EA requires platform support in the form of CTAP 2.1 capabilities. See Enterprise Attestation Platform/RP Support and CTAP 2.1 Features.

EA’s ability to identify individual authenticators as opposed to just the type of authenticator changes the privacy model of the FIDO protocol. This makes the FIDO credential behave more like a certificate.

Typical Use-Cases

  • Tracking of individual authenticators on registration ensures that only authenticators issued by the organization are used. This resolves a common compliance requirement that previously could only be met by using policies or custom AAGUIDs.
  • If the organization knows what serial number a user was issued but does not see it registered or did not register it on the user’s behalf, the organization can take appropriate steps to help the end user register their authenticator. This helps organizations roll out phishing-resistant MFA.
  • Tie the FIDO credential to a PIV certificate by matching serial numbers (or other device-specific information) between the FIDO EA and the PIV Attestation certificate.
  • Identify individual authenticators in troubleshooting scenarios. When a key is lost or broken, a user can be guided by an IT admin who knows what authenticator holds what credential. The admin can advise which key is being used and which should be de-activated. The serial number of a back-up authenticator can be identified, too.

Note

On Enterprise Attestation enabled YubiKeys, if a FIDO reset is performed the Enterprise Attestation is disabled. To re-enable Enterprise Attestation, use ykman CLI. See YubiKey Manager (ykman) CLI User Guide, FIDO Commands.

Developers seeking more information, refer to Enterprise Attestation on developers.yubico.com.

Enterprise Attestation Platform/RP Support

At present, few RPs support this feature; however, there is platform support for it in Chrome and some Chromium-based browsers. Windows 11 is required on Windows platforms.

CMS vendor support for EA is currently a little sparse; however, that is rapidly changing.

Minimum PIN Length

As of YubiKey firmware 5.7.4, the Minimum PIN Length Extension minPINLengthExtension enables the minimum PIN length to be set on an authenticator. minPINLengthExtension enables:

  • a Relying Party (RP) to enforce PIN length requirements, for example in regulated environments.
  • IdPs to support FIDO registration self-enrollment processes by enforcing the configured minimum PIN length.

minPINLength is configurable only by platforms or by communicating with the YubiKey directly. We recommend using a local client tool such as the Yubico Authenticator or ykman.

IdPs, RPs pre-defined by the organization, and end users are able to query the minPINLength of the authenticator, but only if it is configured via an allowed list on the YubiKey.

Once set, the PIN length cannot be shortened until the authenticator is reset.

Generally, PIN length is between 4 and 63 alphanumeric characters, but the actual minimum PIN length varies depending on the firmware version, whether or not the YubiKey is a FIPS key, and whether PIN Complexity is added or not.

Minimum PIN Length
YubiKey 5.7 and later with PIN complexity 6
YubiKey 5.7 and later without PIN complexity 4
YubiKey FIPS 5.7 8
YubiKey FIPS prior to 5.7 6
YubiKey prior to 5.7 4

On the YubiKey Bio Multi-protocol Edition, the PIN is shared between the PIV and FIDO2 applets. PIN length requirements depend on firmware version and YubiKey application status.

The special (developer-focused) requirements for the PIN are described in The FIDO2 PIN.

In YubiKey firmware version 5.7.4, the minPINLength extension resolves compliance requirements for organizations that need to enforce use of specific PIN lengths.

Prior to 5.7, enforcing PIN length was only possible with:

  • YubiKey 5 FIPS Series authenticators certified for FIPS 140-2, which have a minimum PIN length of 6.
  • YubiKey 5 FIPS Series Enhanced PIN and Security Key Series have minimum PIN length set to 6 by default.
  • Custom configuration, which RPs could do when the authenticator had a custom AAGUID.

Changing Minimum PIN Length

To change the minimum PIN length, see Increasing the minimum PIN length.

See also, CTAP 2.3, Setting a minimum PIN Length.

  • To re-attempt to enter the PIN after you have entered an incorrect PIN three times in succession, power-cycle the FIDO2 application.
  • Once a FIDO2 PIN is set, it can be changed but removal of a FIDO2 PIN requires a FIDO2 reset.
  • If the PIN is entered incorrectly eight times in succession, the FIDO2 application locks and FIDO2 authentication is no longer possible. To unlock the FIDO2 application, a FIDO2 reset is required.

Note

Resetting the FIDO2 application also resets the U2F application. This means the YubiKey must be re-registered not only with all the FIDO2 sites, but also with all the U2F sites.

Note

The YubiKey 5 supports FIDO2 credential management. This enables selectively deleting resident keys. See our article YubiKey 5.2 enhancements to FIDO 2 Support for details.

Minimum PIN Length Platform/RP Support

No current RP supports this feature, however there is platform support for it in Chrome and some Chromium-based browsers. Windows 11 is required on Windows platforms.

Force PIN Change

As of YubiKey firmware 5.7.4, Force PIN Change (FIDO 2.1 specification) enables vendors or IT admins to prompt end-users to change their FIDO2 PIN upon next use. This is valuable in a pre-registration/enroll-on-behalf of scenario where the organization does not want their end users’ PINs to be known. End-users are prompted to set their own PINs (can be combined with minPINLength).

This is valuable in a pre-registration/enroll-on-behalf-of scenario where the organization does not want to know their end users’ PINs. End-users are prompted to set their own PIN (may be combined with minPINLength), i.e. a PIN not known by the organization.

This feature also minimizes the number of help-desk calls due to forgotten PINs because end-users can set PINs that are meaningful to them.

Note

A PIN is not a password; it is local to the authenticator.

Force PIN Change Platform Support

There is no need for explicit RP support for force PIN change. The force PIN change flag is set on the client/platform side. The client/platform triggers the change PIN flow. The PIN change can only be set by communicating directly with the YubiKey.

Chrome and some Chromium-based browsers support it. Windows 11 is required on Windows platforms.

Always Require User Verification

Always Require User Verification (UV), alwaysuv, was introduced to prompt users for user verification with each use (authentication and registration). This ensures consistent behavior between different platforms and RPs. End-users are often confused because the setting uv=preferred/discouraged behaves differently depending on whether the user is on a macOS or a Windows machine.

An organization might want to enable it so that users always enter their PIN, ensuring they are less likely to forget it.

Always Require User Verification (UV) has a default setting for each YubiKey series.

Always Require User Verification Defaults by YubiKey
YubiKey Series Default If YubiKey is reset Notes
YubiKey 5 Series Disabled Reverts to disabled Can toggle.
YubiKey 5 CCN Series Disabled Reverts to disabled Can toggle.
YubiKey 5 Enhanced PIN Series Enabled Reverts to enabled Can toggle.
YubiKey 5 FIPS Series Enabled Not applicable Cannot be disabled.
YubiKey Bio Series Enabled Reverts to enabled
Can toggle. Always asks for biometrics
and never only “plain touch”/User
Presence (UP), even in a second factor
flow when UV is not required.
Security Key Series Disabled Reverts to disabled Can toggle.

Always User Verification Platform/RP Support

This setting is internal to the authenticator and requires no specific platform or RP support.

AlwaysUV and FIDO2

If you disable FIDO2 and leave AlwaysUV enabled, U2F fails.

To prevent U2F failing:

  1. Disable AlwaysUV first.
  2. Then disable FIDO2.

To correct U2F failure, if you disabled FIDO2 and did not disable AlwaysUV first:

  1. Enable FIDO2.
  2. Disable AlwaysUV.
  3. Disable FIDO2.

Blob Storage

One of two blob storage options available on the YubiKey 5.7 and later. Both Credential Blobs and Large Blobs require support on the platform as well as from the Relaying Party (RP).

Large blob storage is:

  • 4096 bytes on firmware 5.7.0 and later
  • 1024 bytes on firmware 5.5.x and 5.6.x

Credential Blob

Credential Blobs, credBlob, are 32 bytes of unencrypted storage per credential that can be set during registration and retrieved during authentication for discoverable credentials. This feature allows for a small amount of data to be associated with a discoverable credential during makeCredential. The blob is opaque to the authenticator. This enables IdPs to include a small amount of information such as a certificate thumbprint to aid in authentication scenarios. PII can be stored in this field if it is used with credProtect.

There are many use cases, as the credBlob extension enables storage of arbitrary data; however, it can:

  • Be used as HPKP-like public key hash to identify for example kerberos certificates to trust when using a given credential (“on prem AD”).
  • Provide information about the issuance of the specific credential.

Large Blob

Large blob, authenticatorLargeBlob, storage is compressed, shared storage on the authenticator. It is managed by the platform, and is always encrypted with the Large Blob Key - a per-credential symmetric encryption key that is used by the platform to read the contents of the large blob. Large blobs can be used for storing authentication certificates or other artifacts linked to the private FIDO2 key stored on an authenticator.

The size of the Large Blob varies, depending on the YubiKey firmware version:

  • 4096 bytes on firmware 5.7.0 and later
  • 1024 bytes on firmware 5.5.x and 5.6.x.

The large blob feature allows for a “large” amount of data to be added to a discoverable credential upon creation. The typical use case is a public SSH key.

Creating an SSH key using a discoverable FIDO2 credential enables the authenticator to be hardware-bound and to perform SSH authentications using a key stored in the FIDO2 applet.

With the addition of large blob the user can take the authenticator to a new machine and does not need to copy the public part to the new client machine.

Any other data can be associated with the key, such as linkage to a PIV certificate or details on the creation of the credential.

The largeBlobKey is required to decrypt the data in the Large Blob.

Calculating the RPID hash

The FIDO2 protocol uses the RPID (Relying Party ID) as an identifier for the RP (Relying Party) that an authenticator authenticates against. To calculate the PRID hash of an URL, apply the SHA-256 algorithms over the RPID. For example, the RPID yubico.com has the RPID hash of 378209b72defcba91dcbf854edb4daa648828a2cbd180afc77a74434655a1c7d. This can be calculated by running echo -n "yubico.com" | openssl dgst -sha256, which returns the result SHA2-256(stdin)= 378209b72defcba91dcbf854edb4daa648828a2cbd180afc77a74434655a1c7d.

Developers seeking more information can refer to The W3C’s WebAuthn specification.

FIDO2 Management Tasks

This section describes:

Tools for Managing the FIDO2 Application

Each operating system has different software available to manage the YubiKey, with different capabilities. Note that the same YubiKey can be configured using any or all of the tools listed.

Yubico Authenticator for Windows, MacOS and Linux

Platforms:Windows, MacOS, Linux
Capabilities:Set or change the PIN, manage fingerprint templates, manage discoverable credentials, reset the YubiKey
Works with:All YubiKeys that support FIDO2

Yubico Authenticator enables users to manage all aspects of the FIDO2 application, and can do all the things that are outlined in this document for managing the YubiKey, including adding fingerprint templates to the YubiKey Bio. Yubico Authenticator requires administrative privileges for several operations on Windows, so for non-administrative users on Windows, the built-in Windows Security Key tools may be a better option.

See Managing Discoverable Credentials with Yubico Authenticator. Download Yubico Authenticator for Windows, MacOS or Linux.

ykman CLI for Windows, MacOS and Linux

Install the most recent version of the ykman, because the YubiKey Manager GUI includes an older version of the ykman CLI.

Platforms:Windows, MacOS, Linux
Capabilities:Set or change the PIN, reset the YubiKey, manage discoverable credentials (ykman CLI only)
Works with:All YubiKeys that support FIDO2.

For Windows, MacOS, Linux, download the Yubico Authenticator with its intuitive and easy-to-use graphical interface, the ykman, a lightweight software package installable on many OS, or the YubiKey Manager GUI, though it is not as robust as the other tools.

These are general purpose utilities that is able to configure many of the applications on the YubiKey in addition to FIDO2. They require administrative privileges to configure FIDO2, or detect FIDO2-only devices like the Security Key series or the YubiKey Bio on Windows, so for non-administrative users, the built in Windows Security Key tools may be a better option.

Chrome on MacOS, Linux and ChromeOS

Platforms:MacOS, Linux, ChromeOS
Capabilities:Set or change the FIDO2 PIN, manage fingerprint templates, manage discoverable credentials, reset the YubiKey
Works with:All YubiKeys that support FIDO2.

Chrome has built-in support for managing FIDO2 devices, and will allow for managing security keys on the non-mobile based platforms where it is available. These capabilities are not available on Windows installations of Chrome.

Built-in Security Key Management on Windows

Platforms:Supported versions of Windows 10 or 11, and Windows Server
Capabilities:Set or change the PIN, Manage fingerprint templates, Reset the YubiKey
Works with:All YubiKeys that support FIDO2.

Windows has supported security keys for many versions, and all the most recent releases of all supported Windows Desktop and Server support FIDO2, and make that support available to web browsers running on the platform. Windows includes built-in tools for setting and changing the PIN on FIDO2 devices like the YubiKey, as well as resetting the YubiKey. Search for “Set up Security Key” in the Start menu to find Windows built-in FIDO2 management tools. This method of interacting with the security key does not require administrative rights.

Managing Discoverable Credentials

Any YubiKey with firmware 5.2.1 and higher supports viewing and deleting individual discoverable credentials (also known as Passkeys) that are stored on the YubiKey. A PIN must be configured, and entered each time you want to view discoverable credentials. Deleting a discoverable credential is a permanent action, and can not be undone. It is recommended to ensure that you have access to an account by other means (such as a different YubiKey) before deleting a discoverable credential for a specific account.

Managing Discoverable Credentials with Yubico Authenticator

  1. Download and install Yubico Authenticator for Windows, MacOS or Linux. The iOS and Android versions of Yubico Authenticator do not support resetting the FIDO2 application of the YubiKey.

  2. Insert your YubiKey or Security Key in a USB port on your computer.

  3. Open Yubico Authenticator.

  4. Click the menu icon (three vertical bars) in the upper left hand corner and select WebAuthn.

    • Windows 10 or 11 users, if prompted, enter administrator consent.

      Due to underlying OS mechanics, when using Windows 10 or 11, applications that manage FIDO2 devices need to be run as administrator in order to access FIDO2 options and/or to detect the Security Key Series keys.

    • Enter a PIN at the prompt, if a PIN is set on the device.

      Any discoverable credentials on the device are listed. Most discoverable credentials provide a way to identify the account. The URL that the credential is used for is always visible.

  5. Locate the credential you want to delete, and click on the elipses (…) icon to the right of the credential.

    The Username and URL of the credential is listed again.

  6. Click the Delete Passkey button under the credential. To cancel the deletion, click the X Close button.

  7. Confirm deletion by clicking the delete button. This permanently deletes the credential.

Managing Discoverable Credentials with Google Chrome on MacOS or Linux

Note

Chrome for Windows does not support managing individual FIDO2 credentials due to Windows operating system restrictions.

To list and delete credentials:

  1. Open the Chrome Settings menu. Click the 3 vertical dots.

    Alternatively, navigate to chrome://settings/securityKeys and skip to step 5.

  2. Select Privacy & Security from the settings navigation on the left hand side.

  3. Scroll down and select Security.

  4. Scroll down and select Manage security keys.

  5. Select Sign-in data.

  6. Enter your YubiKey’s PIN and click Continue.

  7. Located the credential you want to delete and click the trash can icon next to it.

  8. Confirm deletion by clicking the delete button. This permanently deletes the credential.

Resetting the FIDO2 Application

Note

Device Support: This article applies to Yubico devices that support the FIDO2 protocol, like the YubiKey 5 Series, YubiKey 5 FIPS Series, and Security Key Series, but not to the FIDO U2F Security Key, which cannot be reset. Also note that FIDO2 reset performed over a Lightning connection is only supported for devices with firmware 5.7.4 and higher.

If the FIDO2 PIN has been forgotten, and the fingerprint sensor on the YubiKey Bio is not working, the key will need to be reset. Resetting the key will remove the PIN, but it will also destroy all the U2F and FIDO2 credentials on the YubiKey, whether they are discoverable or not. Entering the PIN incorrectly 8 times will also cause the FIDO2 application to lock.

Note

Device Support: This article applies to Yubico devices that support the FIDO2 protocol, like the YubiKey 5 Series, YubiKey 5 FIPS Series, and Security Key Series, but not to the FIDO U2F Security Key, which cannot be reset. Also note that FIDO2 reset performed over a Lightning connection is only supported for devices with firmware 5.7.4 and later.

Before Resetting the FIDO2 Application

Once the FIDO2 application on the YubiKey has been reset, there is no way to recover the previously stored credentials or PIN. Resetting the FIDO2 application will effectively unregister your key from any accounts it was registered with using FIDO U2F or FIDO2. We therefore recommend following the steps below, prior to resetting.

Determine which accounts will be affected by a reset (see below). Log in to each of those accounts, unregister the key to be reset, and then double-check that you are still able to log in and modify the account’s 2FA settings (without the key that is to be reset). This process is easier if you have more than one key registered with your accounts, which we recommend.

Determining which accounts may be affected

To determine which of your accounts may be affected by a FIDO reset:

  1. Search for each service your YubiKey is registered with in the Works With YubiKey Catalog.

  2. Under each service’s listing, check the security protocol support section for FIDO2/WebAuthn, Universal 2nd Factor (U2F), or similar. Services that indicate support for these may be affected by a FIDO2 reset.

    For instance, Google’s listing in the WWYKC has both of these listed, indicating it would be affected by a reset.

    Services that only list Yubico OTP, OATH-TOTP, etc., and do not include any of the aforementioned protocols should not be affected.

The YubiKey will return to its initial state without a FIDO2 PIN. We recommend using the Yubico Authenticator app or built-in OS support on a desktop OS to set the PIN prior to using the YubiKey again.

Resetting the FIDO2 Application

  1. Download and install YubiKey Manager GUI.

    Alternatively, use either the Yubico Authenticator with its intuitive and easy-to-use graphical interface or the ykman, a lightweight software package installable on many OS.

  2. Insert your YubiKey or Security Key into an available USB port on your computer.

  3. Open YubiKey Manager.

    Note

    When using Windows 10 or 11, applications that manage FIDO2 devices need to be run as administrator in order to access FIDO2 options and/or to detect the Security Key Series keys.

  4. Navigate to Applications > FIDO2.

  5. Click “Reset FIDO” > “YES”.

  6. Follow the prompts to remove, re-insert, and touch your key.

Resetting the FIDO2 Application Using Yubico Authenticator

If a PIN has been set, Yubico Authenticator requires that PIN in order to reset the FIDO2 application.

Note

When using Windows 10 or 11, applications that manage FIDO2 devices need to be run as administrator in order to access FIDO2 options and/or to detect the Security Key Series keys. If you are using Windows and do not have administrative access, consider using the built-in security key management features of Windows.

  1. Download and install Yubico Authenticator for Windows, MacOS or Linux. The iOS and Android versions of Yubico Authenticator do not support resetting the FIDO2 application of the YubiKey.
  2. Insert your YubiKey or Security Key into an available USB port on your computer.
  3. Open Yubico Authenticator.
  4. In the upper left hand corner, click on the menu icon (three vertical bars) and then select “WebAuthn”.
  5. You will be prompted for a PIN if a PIN is set on the device; however, if a PIN has not been set, entering the PIN is not required for a reset.
  6. In the upper right hand corner of the Authenticator, click on the icon for the device you are using, and select “Reset FIDO”.
  7. Follow the on-screen instructions.

Resetting the FIDO2 Application Using Windows Built-in Security Key Management

Windows 10 and 11 provide built-in tools to manage FIDO2 devices.

  1. Open the Start menu and select “Set up security key”.

    Alternatively, open Windows Settings and navigate to “Accounts” > “Sign-in options” > “Security Key”.

  2. Click the “Manage” button.

  3. When prompted, touch your security key.

  4. Click “Reset security key”, and follow the on-screen prompts.

Resetting the FIDO2 Application Using Google Chrome on MacOS or Linux

Chrome for Windows does not support resetting the FIDO2 application because of Windows OS restrictions.

  1. Open the Chrome Settings menu by clicking on the 3 vertical dots on the upper right of the browser, next to the URL field.

    Alternatively, navigate to chrome://settings/securityKeys and skip to step 5.

  2. Select “Privacy & Security” from the settings navigation on the left hand side.

  3. Scroll down and select “Security”.

  4. Scroll down and select “Manage security keys”.

  5. Click “Reset your security key”, and follow the on-screen prompts.

Setting or Changing the FIDO2 PIN

For a general description of the FIDO2 PIN, see FIDO2 PINs and Fingerprint Templates.

Note that the FIDO2 PIN is independent from the PIV PIN, and may be set to a different value, or not set at all. Changing the FIDO2 PIN will not change the PIV PIN, and vice-versa.

Note

This does not apply to the YubiKey Bio Multi-protocol Edition where the two PINs are shared between the applications.

Setting or Changing the FIDO2 PIN on Windows

When using Windows 10 or 11, applications that manage FIDO2 devices need to be run as administrator in order to access FIDO2 options and/or to detect the Security Key Series keys If you are using Windows and do not have administrative access, consider using the built-in security key management features of Windows.

  1. Download and install YubiKey Manager GUI.

    Alternatively, use either the Yubico Authenticator with its intuitive and easy-to-use graphical interface or the ykman, a lightweight software package installable on many OS.

  2. Insert your YubiKey or Security Key into an available USB port on your computer.

  3. Open YubiKey Manager.

  4. Navigate to Applications > FIDO2.

  5. Click “Set PIN” or “Change PIN”.

  6. Follow the prompts to set or change the PIN.

Setting or Changing the FIDO2 PIN Using Yubico Authenticator

When using Windows 10 or 11, applications that manage FIDO2 devices need to be run as administrator in order to access FIDO2 options and/or to detect the Security Key Series keys. If you are using Windows and do not have administrative access, consider using the built-in security key management features of Windows.

The iOS and Android versions of Yubico Authenticator do not support setting the FIDO2 PIN.

  1. Download and install Yubico Authenticator for Windows, MacOS or Linux.
  2. Insert your YubiKey or Security Key into an available USB port on your computer.
  3. Open Yubico Authenticator.
  4. In the upper left hand corner, click on the menu icon (three vertical bars) and select “WebAuthn”.
  5. You will be prompted for a PIN if a PIN is set on the device. In the upper right hand corner, click on the icon representing your device, and select “Set PIN” or “Change PIN”, depending on whether your device already has a PIN configured.

Setting or Changing the FIDO2 PIN Using Windows Built-in Security Key Management

Windows 10 and 11 provide built in tools to manage FIDO2 devices without needing administrative access.

  1. Open the start menu and search for “Set up security key”.

    Alternatively, open Windows Settings and navigate to “Accounts” -> “Sign-in options” -> “Security Key”

  2. Click on the “Manage” button.

  3. Touch your security key as prompted

  4. Under “Security key PIN”, Click on “Add” or “Change”, and follow the on-screen prompts.

Setting or Changing the FIDO2 PIN Using Google Chrome on MacOS or Linux

Chrome for Windows does not support setting or changing the FIDO2 PIN because of Windows OS restrictions.

  1. Open the Chrome Settings menu by clicking on the 3 vertical dots.

    Alternatively, navigate to chrome://settings/securityKeys and skip to step 5.

  2. Select “Privacy & Security” from the settings navigation on the left hand side.

  3. Scroll down and select “Security”.

  4. Scroll down and select “Manage security keys”.

  5. Click on “Create a PIN”, and follow the on-screen prompts to set or change the FIDO2 PIN.

Enrolling Fingerprints on the YubiKey Bio

Videos demonstrating how to enroll fingerprints in the YubiKey Bio can be found at Set up your YubiKey. Click the enroll your fingerprint link.

FIDO U2F

FIDO U2F is an open standard that provides strong, phishing-resistant two-factor authentication for web services using public key cryptography. U2F does not require any special drivers or configuration to use, just a compatible web browser. The U2F application on the YubiKey can be associated with an unlimited number of U2F sites.