Automic VaultAutomic Vault

brew

ykman mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für ykman in AI-Agent-Workflows.

Installation

Weitere Installationsbefehle

macOS

Homebrewverifiziert · 100%
brew install ykman

local Homebrew formula metadata

Überblick

Paketzusammenfassung

Tool for managing your YubiKey configuration

Verlauf

Projektgeschichte und Nutzung

YubiKey Manager CLI, usually run as `ykman`, is Yubico's maintained command-line and Python-library interface for configuring modern YubiKeys. It sits at the center of the current YubiKey administration stack because it manages multiple applications on the same hardware token, including FIDO, OATH, OpenPGP, OTP, and PIV.

Projektgeschichte

The GitHub repository for yubikey-manager was created on 2016-07-04, after Yubico already had older, narrower tools for OTP personalization and related YubiKey tasks. The project consolidated YubiKey administration into a Python CLI/library that can talk to a YubiKey over the relevant USB interfaces instead of being limited to the original OTP personalization workflow.

Yubico's current developer page describes YubiKey Manager CLI as a Python 3.10-or-later library and command-line tool for configuring a YubiKey, and points GUI users to Yubico Authenticator. The separate user guide describes it as an advanced cross-platform tool and the premier CLI for advanced management of YubiKey applications.

Adoptionsgeschichte

`ykman` became the practical successor for day-to-day YubiKey configuration as YubiKeys expanded beyond OTP into FIDO2/WebAuthn, PIV smart-card certificates, OATH credentials, OpenPGP, and other applets. Its Homebrew, MacPorts, pip/pipx/uv, Windows installer, Linux package, and FreeBSD port paths reflect a tool meant for developers, admins, and security teams rather than only one operating system.

In the YubiKey ecosystem, adoption is also explained by deprecation pressure: Yubico has announced end-of-life dates for the older YubiKey Personalization package, while YubiKey Manager continues to track newer firmware and application capabilities.

Wie es verwendet wird

Typical usage starts with `ykman list` or `ykman info`, then moves into application-specific subcommands such as `ykman fido`, `ykman oath`, `ykman openpgp`, `ykman otp`, and `ykman piv`. It is used to inspect tokens, configure applications, manage credentials or certificates, reset applets, and script YubiKey fleet setup from a terminal.

Package users should think of `ykman` as hardware administration tooling, not a passive client: commands can change security-sensitive state on a physical token, and some platforms require USB HID, smart-card, or input-monitoring permissions for particular YubiKey interfaces.

Warum Paket-Nerds sich dafür interessieren

`ykman` is package-nerd significant because it is where modern hardware-token support becomes ordinary package-manager plumbing: a Python CLI, platform-specific USB and smart-card access, shell completion, native installers, and OS packages all wrap one small executable that configures real cryptographic hardware.

It also shows the maintenance arc of security-device tooling. Old single-purpose C utilities remain historically important, but the package that users now expect to install is the cross-application manager that follows current firmware and authentication standards.

Zeitleiste

  • 2016-07-04: Yubico creates the yubikey-manager GitHub repository.
  • 2020s: YubiKey Manager CLI becomes Yubico's documented advanced cross-platform CLI for current YubiKey applications.
  • 2025-02-19: Yubico announces end of life for the older YubiKey Personalization package, strengthening `ykman` as the maintained path for newer YubiKey management.
  • 2026: Yubico documentation describes ykman as supporting features of current YubiKey firmware and applications including FIDO2, PIV, OTP, OpenPGP, OATH, Security Domain, and YubiHSM Auth.

Related projects

  • YubiKey Personalization / ykpers is the older OTP-focused personalization library and CLI.
  • Yubico Authenticator is Yubico's GUI-oriented application for users who do not want the CLI.
  • Related Yubico tools and protocols include yubico-c, libfido2, python-fido2, PIV, OpenPGP, OATH, YubiOTP, FIDO2, and WebAuthn.

Sicherheitslage

Risikostufe: grün

narrow executable package without higher-risk signals.

Risikoklassifikator

grün Risiko · niedrig Konfidenz · appliance

Warum

  • narrow executable package without higher-risk signals

Signale

  • metadata:no-higher-risk-signals

Installationsverhalten

  • In den Formelmetadaten ist kein Homebrew-Post-install-Hook erfasst.
  • Homebrew-Bottle-Metadaten sind für 6 Plattformziele verfügbar.
  • Installiert mit 2 Laufzeitabhängigkeiten.
  • Build-Metadaten listen 2 Build-Abhängigkeiten.

Empfohlene Prüfung

Prüfe vor unbeaufsichtigter Agent-Nutzung, ob das Tool Klartext-Credentials liest, Remote-Zustand schreibt, Artefakte veröffentlicht oder Plugins ausführt.

Executables

Installierte Executables

BefehlArtSichtbarkeitHinweis
ykmancliglobales Executable

Aktualität

Version und Aktualität

Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.

Seite generiert2026-07-25
Manager-Version5.9.2
Manager aktualisiert2026-07-01
lokale DatenOK
Upstreamnot checked
neueste erkannte Versionnicht erkannt

https://developers.yubico.com/yubikey-manager/

Installationsmetadaten

Paketmetadaten

Paketschlüsselbrew:ykman
Version5.9.2
PaketmanagerHomebrew
Paketmanager-Seitehttps://formulae.brew.sh/formula/ykman
Homepagehttps://developers.yubico.com/yubikey-manager/
Repositoryhttps://github.com/Yubico/yubikey-manager
Upstream-Dokumentationhttps://developers.yubico.com/yubikey-manager
LizenzBSD-2-Clause
Quellarchivhttps://files.pythonhosted.org/packages/1f/ab/5b0671484bcdac6cf383ba6682626ab23478889fab5fe7a1744ed78a33c4/yubikey_manager-5.9.2.tar.gz
Zuletzt aktualisiert2026-07-01T17:34:10Z
Pulseupdated
Abhängigkeitencryptography, python@3.14
Build-Abhängigkeitencmake, swig
Von macOS bereitgestellte Bibliothekenpcsc-lite
Bottleverfügbar (auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnicht definiert
Dienstkeiner deklariert

Registry-Fakten

Details aus der Quelldatenbank

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameykman
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

Quellspur

Aus Repository-Daten generiert

Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.

Verwendete Quellen

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment