2. Using "webauthn.io" to register a new Yubikey PIN.

https://webauthn.io is a site that allows you to test Passkeys (also known as "Webauthn") on your device. If you have a new, unprotected Yubikey, we can use https://webauthn.io to force the initialization to assign a PIN.

  1. Plug in your unprotected Yubikey

  2. Go to https://webauthn.io

  3. Once at the site, enter a bogus username (it doesn't matter what) and click on "register".

  1. At this point, you should be prompted to select a device you wish to store your new "Passkey". Select the "User a different phone, table, or security key".

  1. At this point, you may be prompted with a QR code. At this point, press your Yubikey.

  1. At this point, your browser should detect that your Yubikey is not protected. You should be prompted to PIN protect your Yubikey.

  1. Upon verification and hitting "Next", your Yubikey will be protected by the PIN.

  2. At this point, you can remove the Yubikey and stop the registration process.

Last updated