SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Yubico's YubiKey 5.8 adds digital signing features

Yubico's YubiKey 5.8 adds digital signing features

Wed, 22nd Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Yubico has launched the YubiKey 5.8 security key, extending its role from authentication into digital authorisation workflows.

The update is now generally available across the main YubiKey product lines and is aimed at uses including digital signatures, identity wallets, payment confirmation and approval processes involving AI systems.

YubiKey 5.8 adds support for the CTAP 2.3 standard and preview support for an emerging WebAuthn signing extension. The firmware is intended to let developers build signing and approval functions using established standards and application programming interfaces, rather than custom cryptographic systems or backend key management tools.

The move reflects a broader shift in security priorities as companies look beyond login protection to controlling which actions can be approved within software systems. That has become more pressing as automated and AI-driven processes take on larger roles in business operations.

Albert Biketi, Chief Product and Technology Officer at Yubico, said the release marks a major change in how phishing-resistant security can be used inside enterprise workflows.

"YubiKey 5.8 represents one of the most significant architectural updates to the modern authentication ecosystem by expanding phishing resistance into the workflows themselves," said Albert Biketi, Chief Product and Technology Officer at Yubico.

"In an era where AI agents execute high-consequence business workflows, organisations must enable dynamic verification of human intent. YubiKey 5.8 bridges that gap, bringing hardware-backed phishing resistance directly into digital signatures, enterprise credential management and human-in-the-loop validation workflows, without requiring costly custom cryptographic rollouts," Biketi said.

Developer focus

The firmware changes are aimed in part at developers working across identity and access systems in large organisations. Among the additions is support for hardware-backed digital signatures through standardised interfaces, which could be used for document signing, workflow approvals and digital identity credentials.

Enterprise Attestation support has also been expanded to 16 Relying Party IDs on a single key. This allows one physical key to be identified across development, test, staging and production environments, including deployments spanning multiple identity providers.

The product also introduces persistent PIN and user verification authentication tokens, intended to reduce repeated prompts during credential discovery and selection. Another change places hardware-backed credentials alongside software passkeys in an autofill-style experience, which should reduce user confusion and lower helpdesk overhead linked to enrolment.

Identity and payments

Beyond login security, the new firmware extends support for digital identity wallets, verifiable credentials using privacy-focused algorithms, and Secure Payment Confirmation for web-based payments. In these areas, technology suppliers and standards bodies have been pushing for stronger proof that a user is both genuine and actively approving an action.

The release also drew support from SIROS Foundation, which is working on digital identity systems.

"The new signing capabilities of YubiKey 5.8 are a game changer for digital identity and credentials," said Leif Johansson, Executive Director at SIROS Foundation.

"In the last decade, FIDO authentication has become the industry gold standard for phishing-resistant authentication. By adding signatures, a whole range of new applications become possible without introducing platform lock-in. At SIROS, we are working to integrate the new signing capabilities into a seamless framework for secure phishing-resistant digital identity credentials," Johansson said.

Certification split

Not all YubiKey ranges are moving to the new firmware immediately. The YubiKey FIPS Series will remain on firmware version 5.7.4 to maintain alignment with FIPS 140-3 validation requirements.

The YubiKey CCN Series will also stay on version 5.7.4 while it completes final recertification. That means customers in regulated environments may continue using the previous firmware while the broader commercial range shifts to the latest version.

Founded in 2007, Yubico helped develop authentication standards including FIDO2, WebAuthn and FIDO U2F. Its products are used in more than 160 countries, giving it a sizeable installed base as organisations test whether passkey-based tools can extend from login security into broader transaction approval and identity workflows.