Yubico

Yubico

Two-factor authentication hardware key provider

Overview

Yubico makes security hardware keys called YubiKey that provide strong two-factor authentication for individuals and organizations. The keys are inserted or tapped to verify identity, working with multiple authentication standards (FIDO/U2F, smart card, and one-time passwords) and offered in models for personal and business use; developers receive tools and documentation to integrate login into their apps and systems. Unlike software-only methods, Yubico blends a hardware device with broad platform compatibility and active developer and enterprise support, selling devices plus services like technical assistance and consulting. The goal is to make login safer and more reliable to protect data and systems across various industries.

About Yubico

Simplify's Rating
Why Yubico is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Hardware

Cybersecurity

Company Size

501-1,000

Company Stage

IPO

Headquarters

Palo Alto, California

Founded

2007

Get referred to Yubico

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 organic sales rose 12%; gross margin hit 80%; EBIT reached SEK 79 million.
  • Gross retention reached 98.1%, and net retention hit 107.1% in Q2 2026.
  • YubiKey Passkey Enabler and Android NFC support broaden enterprise deployment on Google Play Services.

What critics are saying

  • Bookings fell 5% organically in Q2 2026, showing weak large-deal conversion.
  • March 11, 2026 layoffs cut about 45 employees, exposing management's cost pressure.
  • If Apple, Google, and Microsoft default users to built-in passkeys, YubiKey becomes niche hardware.

What makes Yubico unique

  • YubiKey 5.8, launched July 21, 2026, extends passkeys into verified authorization workflows.
  • FIPS 140-3 validated YubiKey 5 FIPS and YubiHSM 2 satisfy U.S. government buyers.
  • OpenAI partnership and TAC mandate embed YubiKeys inside a massive AI ecosystem.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$719.2M

Above

Industry Average

Funded Over

5 Rounds

Notable Investors:
Post IPO Equity funding comparison data is currently unavailable. We're working to provide this information soon!
Post IPO Equity Funding Comparison
Coming Soon

Benefits

Retirement plan

Wellness benefit

Equity in the company

Learning & development

Global events

Parental leave

Stock Price

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

1%
Yahoo Finance
Aug 9th, 2026
Yubico reports 12% organic growth and 80% gross margin despite 5% booking decline

Yubico reported 12% organic net sales growth in Q2 2026, with a gross profit margin of 80% at the higher end of guidance. The Swedish security key maker posted an EBIT of SEK 79 million with a 14.4% margin, up 12 percentage points year-over-year. Small and mid-size bookings grew 18%, whilst perpetual bookings increased 7%, primarily from deals below SEK 3 million. YubiKey as a Service now represents 24% of total bookings. However, order bookings declined 5% organically, impacted by a lack of large multi-year deals. Currency fluctuations negatively affected EBIT by SEK 10 million. The company also underwent a reduction in force as part of cost-saving measures. Yubico maintained strong customer retention with a 98% gross retention rate and 107% net retention rate. The company held a cash position of SEK 1.02 billion.

Yubico
Aug 3rd, 2026
The 'air-gap conundrum': when password managers meet the data center floor.

The 'air-gap conundrum': when password managers meet the data center floor. Jonathan Hanlon August 3, 2026 Late one afternoon, a critical legacy server dropped offline. A diligent security admin rushed to the air-gapped data center floor to fix it, but ran into a familiar barrier: clipboard redirection was disabled by policy. Forced to manually transcribe a complex, 30-character randomized password on a rack keyboard, a single slipped finger triggered an immediate account lockout - snowballing a routine five-minute fix into a high-stress, multi-hour P0 incident. This is a broken workflow every SysAdmin and network engineer knows all too well. To bypass this daily frustration, teams often resort to risky workarounds like scribbling temporary passwords on sticky notes or weakening password complexity so credentials are easier to type. For years, maintaining high security and operational practicality in restricted environments has felt mutually exclusive - until now. Introducing "Copy to YubiKey" in Devolutions Remote Desktop Manager (RDM). To solve this challenge, Yubico and Devolutions have partnered to introduce a powerful new feature in Devolutions Remote Desktop Manager (RDM): Copy to YubiKey. This new solution directly bridges the gap between legacy credential requirements and modern hardware security. Instead of forcing admins to choose between compliance and sanity, it turns the YubiKey they already carry into a secure, automated credential injector. Designed to be incredibly seamless for an admin already deep in the RDM dashboard, this feature works once a YubiKey is connected to their workstation. A new "Copy to YubiKey" action dynamically appears on credential entries within RDM. From there, the process takes only a few seconds: * Select the Credential: The admin locates the vaulted, high-entropy password within RDM. * Choose the Slot: They trigger the "Copy to YubiKey" action and select which hardware slot on the YubiKey they want to temporarily use (Slot 1 or Slot 2). * Program the YubiKey: RDM securely programs that specific credential directly into the chosen YubiKey slot as a static password. Because the YubiKey can act as a standard USB keyboard (Human Interface Device), a single physical press of the key instantly injects the credential into any text field - no software, network connection, or clipboard required. Security without the friction. "Copy to YubiKey" is about more than just convenience; it's about fortifying the security posture for the gatekeepers of your infrastructure. By combining Devolutions' connection management with Yubico's gold-standard phishing-resistant, hardware-backed passkeys, the joint solution delivers immediate operational advantages: * Passwords that work where 'copy-paste' doesn't Acting as a hardware keyboard, YubiKey instantly injects complex passwords into restricted interfaces like server consoles and BIOS prompts. * Eliminating the clipboard attack surface Bypasses system clipboards entirely, preventing risks from clipboard history, cloud syncing, and monitoring malware. * Maintaining strict governance and auditing Keeps credentials vaulted in Devolutions RDM so YubiKeys only store deliberately and traceably copied data. * Maximizing the hardware you already carry Uses existing YubiKey configuration slots to safely transport privileged credentials alongside standard MFA workflows. Instead of spending hours manually relaying authentication information between a phone and a terminal, administrators can now bypass the process entirely. Because the credential injects perfectly on the first try, users shift from being a reactive firefighter to a proactive architect. Instead of staring at account lockout screens, they are able to focus on high-value projects that push the business forward. Through this integration, Yubico and Devolutions are ensuring that when you must use a password, you can do so with the speed, accuracy, and physical assurance that modern enterprises demand. Ready to eliminate manual password typing in your restricted environments? * Ensure your team is running the latest version of Devolutions Remote Desktop Manager. * Check out the Devolutions RDM Listing in the Works with YubiKey Catalog for technical compatibility and setup details.

Cyber Press
Jul 22nd, 2026
Yubico introduces YubiKey 5.8 with hardware-backed authorization for AI agent workflows.

Yubico introduces YubiKey 5.8 with hardware-backed authorization for AI agent workflows. July 22, 2026 Yubico has released the YubiKey 5.8, a firmware update that extends the hardware security key beyond login authentication to verify and authorize digital actions, including approvals initiated by autonomous AI agents. Announced July 21, 2026, the update responds directly to the rise of agentic AI systems capable of executing complex business workflows with minimal human oversight. Traditional multi-factor authentication answers one question: who is logging in. As AI systems increasingly initiate transactions, approve documents, and trigger automated processes, security teams face a harder problem: confirming that a specific action was genuinely sanctioned by a human rather than spoofed mid-workflow. Yubico introduces YubiKey 5.8. YubiKey 5.8 tackles this by extending phishing-resistant, hardware-backed cryptography into signature and authorization use cases rather than just session logins. "YubiKey 5.8 represents one of the most significant architectural updates to the modern authentication ecosystem by expanding phishing resistance into the workflows themselves," said Albert Biketi, Yubico's chief product and technology officer. He added that organizations must now enable dynamic verification of human intent as AI agents take on high-consequence business tasks. Yubico introduces CTAP 2.3 support along with preview access to the emerging WebAuthn signing extension, enabling hardware-backed digital signatures through standard APIs without requiring custom cryptographic infrastructure. It also expands Enterprise Attestation to cover 16 Relying Party IDs per key, letting a single YubiKey operate across development, staging, and production environments spanning multiple identity providers while preserving user privacy. The update further adds support for digital identity wallets, privacy-preserving verifiable credentials, and Secure Payment Confirmation for hardware-backed web payments. Persistent PIN and user verification auth tokens cut down on repeated PIN prompts and enable smoother credential autofill, while a new autofill-style credential discovery mechanism works alongside software passkeys to reduce IT helpdesk enrollment overhead. Together, these changes let developers integrate high-assurance signing into document workflows, digital wallets, and AI approval gates using familiar WebAuthn and FIDO2-adjacent standards instead of building bespoke key management backends. Leif Johansson, executive director at the SIROS Foundation, called the signing capabilities "a game changer for digital identity and credentials," noting that FIDO authentication became the industry standard for phishing resistance over the past decade, and that adding signature support opens new applications without introducing platform lock-in. YubiKey 5.8 ships across all major YubiKey product lines starting immediately and remains fully backward-compatible with YubiKey 5.7.4. Two exceptions apply for regulated environments: the YubiKey FIPS Series stays on FIPS 140-3 validated firmware 5.7.4 to preserve compliance, and the YubiKey CCN Series also remains on 5.7.4 pending final re-certification. Organizations in FIPS or Common Criteria-regulated sectors should not expect 5.8 features until those certifications complete. The launch signals a broader industry shift, with authentication vendors treating AI agents as first-class actors in enterprise workflows that require cryptographic accountability. Enterprises building AI-driven approval chains or document-signing pipelines should evaluate whether hardware-backed signature verification closes gaps that session-based MFA leaves open, particularly around non-repudiation and human-in-the-loop validation. Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.

Associated Press
Jul 21st, 2026
Yubico launches YubiKey 5.8 with passkey expansion beyond authentication to verified authorization

Yubico has launched YubiKey 5.8, expanding the device's role from authentication to include hardware-backed authorisation. The new firmware enables secure enterprise workflows across identity wallets, document signing and AI-driven approvals. The update introduces support for the CTAP 2.3 standard and preview support for the WebAuthn signing extension. This allows developers to build secure, privacy-preserving workflows using familiar standards without requiring expensive backend key management systems. Key features include expanded Enterprise Attestation support to 16 Relying Party IDs on a single key and persistent PIN/UV auth tokens for improved user experience. The firmware also supports digital identity wallets, verifiable credentials and Secure Payment Confirmation. YubiKey 5.8 is now shipping across all major YubiKey product lineups. The FIPS and CCN Series will remain on firmware 5.7.4 to maintain regulatory alignment.

Yubico
Jul 21st, 2026
Beyond the login: Top 3 things developers need to know about YubiKey 5.8.

Beyond the login: Top 3 things developers need to know about YubiKey 5.8. Mario Bodemann July 21, 2026 With today's launch of the YubiKey 5.8, Yubico is excited to continue efforts toward shifting passkeys from a mechanism for trusted authentication into a standard for verifiable, digital authorization. For organizations and developers, YubiKey 5.8 now expands the role of identity from simply verifying who a user is to authorizing what they can do with verified human intent. YubiKey 5.8 is now shipping across all major YubiKey product lineups starting today, except the FIPS Series and CCN Series (currently undergoing final re-certification). Hardware-backed passkeys have transformed how the industry approaches identity verification, offering an unprecedented line of defense against modern phishing vectors. Whether signing documents, approving agent-driven actions, confirming medical treatments, or authorizing critical workflows, YubiKey 5.8 enables high-assurance digital actions anchored in hardware-backed passkey trust. Here, Yubico'll detail the top three things developers need to know about the YubiKey 5.8 so that you can begin building passkey-native apps today. Check out its newest webinar with 1Password and SIROS Foundation, "Beyond the Login: Securing Trusted Actions and AI Workflows with Passkeys," for a conversation on the shift from trusted login to trusted action. 1. Hardware-backed digital signatures through preview APIs. Historically, implementing high-assurance digital signatures required spinning up complex, expensive backend Hardware Security Modules (HSMs) or custom Public Key Infrastructures (PKIs). YubiKey 5.8 introduces full support for FIDO CTAP 2.3 alongside a developer preview for emerging WebAuthn signing extension - allowing developers to request cryptographic digital signatures from a hardware security key using the open-standard WebAuthn extension patterns you already use for your login workflows. This directly opens up a an exciting new area of use cases, including: * Agentic AI safeguards: Binding an automated AI workflow's high-risk decisions (like altering production database schemas) to a mandatory human-in-the-loop physical touch. * Decentralized identity: Serve as the secure root-of-trust for digital identity wallets, verifiable credentials, and Secure Payment Confirmation (SPC). 2. Privacy-preserving cryptography (ARKG preview). Yubico know that user privacy is a non-negotiable architectural requirement for next-generation apps. A common roadblock with digital signing tracking is that public keys can accidentally be used by third-party verifiers to collude and track users across separate digital sessions. To solve this, YubiKey 5.8 introduces a developer preview of Asynchronous Remote Key Generation (ARKG) extension. ARKG allows the security key to dynamically generate unique, public keys for distinct workflows. Verifiers can cryptographically confirm the validity of the signature and the hardware origin without ever being able to link or track the user across separate platform interactions. This makes it possible to support emerging initiatives such as digital wallets and payments. 3. Streamlined UX and frictionless credential discovery. Hardware-backed passkeys are incredibly secure, but historically they've had a visibility problem in the browser compared to native software credentials. YubiKey 5.8 implements the latest CTAP 2.3 UX enhancements, including Persistent PIN/User Verification Auth Token (PPUAT) protocol feature. This mechanism allows applications to discover discoverable credentials stored on the hardware key smoothly and intuitively. For the end user, this translates to a streamlined, autofill-like passkey experience inside native apps. Users can leverage system autofill dropdowns to select their security key credentials instantly, significantly minimizing redundant, repetitive PIN prompt bottlenecks throughout a multi-application workspace session. Working together to secure and build for AI-era workflows. Yubico is committed to empowering the developers and engineers with the best security tools, and receiving critical feedback from the community. To kickstart development, Yubico will be hosting the YubiKey 5.8 Virtual Hackathon on August 5, 2026. Accepted developers receive a YubiKey 5C NFC with custom laser-marked "HACKATHON 5.8" to prototype experimental code across trusted AI workflows, digital wallets, secure payments, and more. Join its developer community to learn more about future hackathons and engage with the Yubico Developer Relations team here.

Recently Posted Jobs

Sign up to get curated job recommendations

Yubico is Hiring for 14 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →