YubiKey 5.8 Datasheet
Expand beyond trusted authorization to verified authorization.
The new YubiKey 5.8 firmware fast tracks enterprises to passwordless authentication and extends hardware-backed assurance beyond authentication into authorization—enabling preview support for hardware-backed signatures, trusted AI workflows, digital wallets, and enterprise-ready phishing-resistant identity. YubiKey 5.8 supports all of the capabilities of YubiKey 5.7.4 and expands the use of passkeys for enterprise use cases.
Simplified development with standard APIs
By introducing support for FIDO Client-to-Authenticator Protocol (CTAP) 2.3 paired with the developer preview for emerging WebAuthn signing extensions, developers can use familiar standards and APIs to build secure, privacy-preserving workflows (ARKG) without relying on expensive backend key management systems or custom cryptographic infrastructure. This significantly lowers the barrier to building trusted digital workflows, allowing developers to integrate secure signatures into web applications, digital wallets, and workflow approval systems with greater speed and less complexity.
Passkeys now secure human authorization
Organizations can now begin extending passkeys from secure login to secure authorized action. Developers can begin testing hardware-backed, privacy-preserving digital signatures using WebAuthn-aligned patterns associated with passkey credentials. Whether signing documents, approving agent-driven actions, confirming medical treatments, or authorizing critical workflows, YubiKey 5.8 enables high-assurance human-in-the-loop authorization and digital actions anchored in hardware-backed trust.
Supports emerging initiatives such as Digital Wallets and Payments
YubiKey 5.8 introduces support for digital wallets, verifiable credentials, and Secure Payment Confirmation (SPC). Not only can the YubiKey support hardware-backed signatures but it supports algorithms that are privacy-preserving. The preview signed extension capability (ARKG) generates single use keys that prevent verifiers from tracking users across multiple sessions. These capabilities enable YubiKeys to serve as the hardware-backed root of trust for secure digital identity and financial transactions. This enables early development and partner testing across digital identity wallets, document signing, payments, and AI-driven approval workflows.
Enable trusted AI workflows
As agentic AI systems become more autonomous, organizations need ways to anchor high-consequence actions to verified human intent. The latest YubiKey 5.8 enables human-in-the-loop approvals, agentic AI action authorization and identity-bound workflow approvals.
Streamlined user experience
YubiKey 5.8 improves the user experience of hardware-backed passkeys by introducing key features such as Persistent PIN User Access Token (PPUAT) which allows for frictionless autofill-like credential discovery. This enables credentials stored on YubiKeys to appear alongside software-based passkeys in modern authentication workflows, reducing PIN prompts for users. YubiKey 5.8 reduces friction, simplifies login experiences, and helps accelerate passkey adoption across organizations.
Enterprise scalability
YubiKey 5.8 expands enterprise flexibility by increasing Enterprise Attestation support from 2 to 16 RPIDs, making it easier for organizations to manage multiple identity providers and development-to-production environments at scale. One YubiKey can now support multiple environments: development, testing, staging, and production. Lastly, YubiKey 5.8 enhances enrollment through the YubiKey as a Service – Enroll app available in limited early access on Android phones.
YubiKeys deployed in:
19 of top 20 technology companies
9 of top 10 financial services companies
8 of top 10 retail companies
*As defined by Forbes Global 2000, excluding China-owned companies.
The latest firmware brings powerful new capabilities: YubiKey 5.8
| New capabilities | YubiKey 5 Series | Security Key Series | Security Key Series Enterprise Edition (Subscription-only) | YubiKey Bio Series – FIDO Edition | YubiKey Bio Series – Multi-Protocol Edition (Subscription-only) |
| Verifiable credentials | ✓ | ✓ | ✓ | ✓ | ✓ |
| Digital identity wallets | ✓ | ✓ | ✓ | ✓ | ✓ |
| Preview signed extension capability (ARKG) to prevent tracking | ✓ | ✓ | ✓ | ✓ | ✓ |
| Secure Payment Confirmation (SPC) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Conditional Mediation and PPUAT support | ✓ | ✓ | ✓ | ✓ | ✓ |
| Enroll YubiKey through YubiKey as a Service Enroll app (LEA) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Enterprise Attestation RPIDs from 2 to 16 and can store more credentials | ✓ | ✓ | ✓ | ✓ | ✓ |
| Temporary FIDO2 PIN can be set (forces user to change upon next use) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Enterprise attestation capable | ✓1 | ✓1 | ✓1 | ✓1 | |
| Serial number retrievable by client software in Windows without admin rights | ✓ | ✓ | ✓ | ✓ | |
| RSA-3072 and RSA-4096 support | ✓ | ✓ | |||
| Ed25519 and X25519 support | ✓ | ✓ | |||
| Enhanced PIN complexity | ✓2 | ✓ | ✓1 | ✓1 | |
| Default minimum PIN length | ✓ | ✓ | ✓ | ✓ | ✓ |
| Support for 100 passkeys | ✓ | ✓ | ✓ | ✓ | ✓ |
| Support for 24 PIV certificates | ✓ | ✓ | |||
| Support for 64 OATH credentials | ✓ | ||||
| Support for 2 OTP seeds | ✓ |
1 Requires custom config
2 Available via subscription with YubiKey 5 Series – Enhanced PIN, or YubiKey 5 Series requires custom config
