Skip to content
Bastyx
Book a Demo
Bastyx + YubiKey

Make your YubiKeys the only login your team needs.

Eliminate workforce passwords with YubiKey and Bastyx, from workstation login and SSH to every service and application in your domain. Run Bastyx in our cloud or on your own servers.

Alex Morgan’s YubiKey 5C NFC in the Bastyx console, registered as the primary authenticator, signing in to workstation login on macOS, Windows and Linux, SSH to 24 production servers, SAML and OIDC apps, domain apps through Kerberos, legacy apps and approvals, with the built-in fingerprint sensor as a backup and zero passwords.

Coverage

One touch, from workstation login to every app in the domain.

The same key and the same identity everywhere, so there’s no password left to phish, reuse or reset.

  • Workstation login

    Unlock macOS, Windows and Linux with a YubiKey touch and PIN, or a fingerprint on YubiKey Bio, instead of a password.

  • SSH

    The same ssh command, a key touch and a short-lived certificate. No SSH keys to copy, no authorized_keys to maintain.

  • SAML and OIDC apps

    SaaS, cloud consoles and internal tools with single sign-on accept the same key.

  • Domain apps

    Passwordless Windows sign-in gets a Kerberos ticket, so apps using Integrated Windows Authentication open without a prompt.

  • Legacy apps

    Apps that only accept a password sit behind the access proxy or use a vaulted credential nobody sees.

  • Approvals

    Temporary production access and sensitive AI agent actions are approved with a touch of the owner’s key.

How it fits together

The YubiKey proves who. Bastyx decides what.

YubiKey

  • The private key is generated on the YubiKey and never leaves it
  • A touch, plus a PIN or a fingerprint, proves a person is present
  • Signatures are bound to the real domain, so phishing sites get nothing

Bastyx

  • Binds each key to a person and an enrolled device
  • Applies policy, such as a hardware key for production
  • Revokes a key, or a person, in one step
  • Records every sign-in and change in the audit log

Supported keys

Every YubiKey with FIDO2.

Other FIDO2 keys and built-in sensors work too. See the full compatibility matrix.

  • YubiKey 5 Series

    USB-A, USB-C and NFC · touch and FIDO2 PIN

    Available
  • Security Key Series

    USB-A, USB-C and NFC · touch and FIDO2 PIN

    Available
  • YubiKey Bio Series

    USB-A and USB-C · fingerprint matched on the key

    Available

Deployment

Our cloud, or your servers.

Bastyx Cloud
Nothing to run. Keys register and verify against Bastyx Cloud. From $6 per user per month.
On-premises
The server that registers and verifies your YubiKeys runs in your own data center or cloud account, with the same policies and console. Part of Enterprise.

Rollout

Hand out keys, then stop managing passwords.

  1. Register

    Each person registers their YubiKey and a second authenticator, such as the laptop’s fingerprint sensor, from the Bastyx app.

  2. Require it where it matters

    A policy can require a hardware key for admins and anything in production, while built-in sensors cover the rest.

  3. Lost key

    Revoke that one key in the console. The person keeps working on their second authenticator. Recovery needs admin approval and a second registered authenticator.

  4. Offboarding

    Every key a person registered is deregistered along with the rest of their access, and the change is recorded.

FAQ

YubiKey questions

Which YubiKeys work with Bastyx?

Any YubiKey with FIDO2: the YubiKey 5 Series, Security Key Series and YubiKey Bio Series, over USB-A, USB-C or NFC. Other FIDO2 security keys work too.

Do we have to buy YubiKeys from Bastyx?

No. Use the YubiKeys you already have, or buy them where you normally would. Bastyx doesn’t charge for authenticators you own.

Can a YubiKey we already use for Google, GitHub or Microsoft work with Bastyx?

Yes. A FIDO2 key holds a separate credential for each service, so registering it with Bastyx doesn’t affect the others, and nothing is shared between them.

What happens if someone loses their YubiKey?

Revoke that key in the console and the person keeps working on their second registered authenticator. Recovery requires admin approval and a second registered authenticator, so a lost key can never be used to recover itself.

Can the server that verifies our YubiKeys run on-premises?

Yes. On the Enterprise plan, the Bastyx control plane that registers and verifies keys runs in your own data center or cloud account, with the same policies, enrollment and console as Bastyx Cloud.

Do we need YubiKeys to use Bastyx?

No. Built-in fingerprint sensors and passkeys work too. We recommend hardware keys such as YubiKeys for admins and production access.

See a YubiKey replace every password.

A 20-minute live demo: laptop login, SSH and an app with one key, then offboarding and the audit log. We reply the same business day.

YubiKey and Yubico are trademarks of Yubico AB, used here only to describe compatibility. Bastyx is not sponsored or endorsed by Yubico.