Yubico, the creator of the original passkey, the YubiKey, has announced its latest launch of its YubiKey 5.8.
The new release marks the expansion of the role of the passkey from secure authentication to include verifiable, hardware-backed authorisation.
Securing enterprise workflows
According to Yubico, the new firmware delivers a foundation for secure enterprise workflows across identity wallets, document signing and AI-driven approvals, while also providing developers with the critical capabilities needed to test, design and deploy these next-generation security features early.
As generative and agentic AI mature to drive rapid, automated cyber-attacks, traditional multi-factor authentication (MFA) is failing to keep pace.
Yubico reported that security leaders now face a challenge globally: securing not just who logs into a system, but exactly what actions a user or autonomous AI agent can perform.
While the YubiKey has long delivered defence against phishing, YubiKey 5.8 addresses the needs of complex, multi-environment enterprises – going beyond trusted logins to provide a secure, hardware-backed foundation for verifiable digital actions in the age of AI.
“One of the most significant architectural updates”
Albert Biketi, Chief Product and Technology Officer at Yubico commented: “YubiKey 5.8 represents one of the most significant architectural updates to the modern authentication ecosystem by expanding phishing resistance into the workflows themselves.
“In an era where AI agents execute high-consequence business workflows, organisations must enable dynamic verification of human intent.”
Biketi continued: “YubiKey 5.8 bridges that gap, bringing hardware-backed phishing resistance directly into digital signatures, enterprise credential management and human-in-the-loop validation workflows – without requiring costly custom cryptographic rollouts.”
Usability and scalability
The company explained that the new firmware introduces support for the CTAP 2.3 standard while offering preview support for the emerging WebAuthn signing extension.
Developers can now use familiar standards and APIs to build secure, privacy-preserving workflows without relying on expensive backend key management systems or custom cryptographic infrastructure.
This significantly lowers the barrier to building trusted digital workflows, allowing developers to integrate high-assurance signatures into web applications, digital wallets and AI-driven workflow approval systems with greater speed and less complexity.
YubiKey 5.8
Yubico explained that the YubiKey 5.8 delivers substantial technical upgrades built directly for developers working across the modern enterprise identity control plane. The upgrades include:
- Support for cutting-edge use cases: Enables hardware-backed digital signatures through standardised APIs – opening the door to document signing, identity wallets, workflow approvals and other high-assurance transactions
- Better user experience and enterprise scale: Expanded Enterprise Attestation support to 16 Relying Party (RP) IDs on a single key. This allows a single YubiKey to be simultaneously uniquely identified down to an individual device across trusted development, testing, staging and production environments across multiple identity providers without compromising user privacy
- Simplified developer integration: Introduces CTAP 2.3 support and preview support for the emerging WebAuthn signing extensions and more, making it easier for developers to integrate secure digital signatures using familiar standards
- Emerging initiatives secured: Expands support for digital identity wallets, verifiable credentials with privacy-enabling algorithms and Secure Payment Confirmation (SPC) support for those developing hardware-backed payment use cases on the web
- Streamlined user experience: Persistent PIN/UV auth tokens allow apps to enable frictionless credential discovery and selection, with more autofill capabilities and fewer PIN prompts for users
- Operational simplicity and lower overhead: Introduces autofill-like credential discovery directly alongside software passkeys. This reduces user confusion, accelerates phishing-resistant passkey adoption and minimises IT helpdesk enrolment costs
“A game changer”
Leif Johansson, Executive Director, SIROS Foundation commented: “The new signing capabilities of YubiKey 5.8 are a game changer for digital identity and credentials.
“In the last decade, FIDO authentication has become the industry gold standard for phishing-resistant authentication.
“By adding signatures, a whole range of new applications become possible without introducing platform lock-in.
“At SIROS, we are working to integrate the new signing capabilities into a seamless framework for secure phishing-resistant, digital identity credentials,” Johansson concluded.

