macOS
brew install yubikey-agentlocal Homebrew formula metadata
brew
Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de yubikey-agent pour les workflows d'agents IA.
installation
brew install yubikey-agentlocal Homebrew formula metadata
sudo apk add yubikey-agentAlpine Linux edge package indexes · yubikey-agent · Source: dl-cdn.alpinelinux.org
sudo apt install yubikey-agentDebian stable package indexes · yubikey-agent · Source: deb.debian.org
nix profile install nixpkgs#yubikey-agentnixpkgs package indexes · pkgs/by-name/yu/yubikey-agent/package.nix · Source: api.github.com
aperçu
Seamless ssh-agent for YubiKeys and other PIV tokens
historique
yubikey-agent is Filippo Valsorda’s Go ssh-agent for YubiKeys and other PIV tokens, packaged because it makes hardware-backed SSH keys feel like a normal SSH_AUTH_SOCK workflow.
The project appeared publicly in 2020, in the same period when OpenSSH 8.2 introduced native FIDO/U2F security-key support. yubikey-agent chose a different compatibility path: use the YubiKey PIV applet to present ordinary SSH public keys through an agent interface, so existing servers did not need support for the newer `-sk` SSH key types.
The README emphasizes three design goals that shaped its history: one-command setup, resilience across unplugging and sleep, and keys generated on the YubiKey so private material cannot be extracted. It is written in Go and built on go-piv/piv-go plus Go’s SSH libraries.
Its documentation also candidly records the tradeoffs: keeping a persistent PIV transaction helps PIN caching and UX, but can conflict with gpg-agent, YubiKey Manager, and other tools that want the same PIV applet.
Early adoption came from security-conscious developers who wanted hardware-backed SSH without the fragility of gpg-agent, manual PKCS#11 loading, or server-side FIDO2 support. A Hacker News launch discussion in May 2020 framed it as a friendly way to plug in a key and SSH securely with minimal setup.
Packaging spread through Homebrew, AUR/Arch-style packaging, NixOS modules, FreeBSD ports, Alpine testing, Debian, and Ubuntu. The README’s install instructions are package-manager first, which helped the tool become a normal service rather than a custom local build.
Users install the package, start the service, run `yubikey-agent -setup` to generate a key on the YubiKey, and point `SSH_AUTH_SOCK` or per-host `IdentityAgent` settings at the agent socket. After that, SSH sees an ordinary agent while the YubiKey enforces PIN and touch policy.
The tool is commonly compared with OpenSSH FIDO2 keys, gpg-agent with the OpenPGP applet, raw ssh-agent PKCS#11 loading, pivy-agent, and macOS Secure Enclave tools such as Secretive. Its niche is the compatibility and UX middle ground: hardware-backed keys with ordinary SSH public-key compatibility.
yubikey-agent is a package-nerd favorite because it collapses a historically fiddly stack into one daemon and one socket. It is not the only hardware-backed SSH route, but it is one of the cleanest examples of wrapping smart-card behavior in a familiar Unix interface.
It also tells a packaging story about defaults: Homebrew services, systemd user units, NixOS services, pcscd, and SSH_AUTH_SOCK all matter as much as the binary itself.
posture de sécurité
broad file, network, media, or database tool signal. formula declares a Homebrew service.
risque orange · confiance moyen · infrastructure
Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.
exécutables
| Commande | Type | Exposition | Note |
|---|---|---|---|
yubikey-agent | cli | exécutable global |
fraîcheur
Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.
https://github.com/FiloSottile/yubikey-agent
métadonnées d'installation
| Clé du paquet | brew:yubikey-agent |
|---|---|
| Version | 0.1.6 |
| Gestionnaire de paquets | Homebrew |
| Page du gestionnaire de paquets | https://formulae.brew.sh/formula/yubikey-agent |
| Page d'accueil | https://github.com/FiloSottile/yubikey-agent |
| Dépôt | https://github.com/FiloSottile/yubikey-agent |
| Docs amont | https://github.com/FiloSottile/yubikey-agent#readme |
| Licence | BSD-3-Clause |
| Archive source | https://github.com/FiloSottile/yubikey-agent/archive/refs/tags/v0.1.6.tar.gz |
| Dernière mise à jour | 2026-06-06T11:29:14Z |
| Pulse | updated |
| Dépendances de compilation | go, pkgconf |
| Bibliothèques fournies par macOS | pcsc-lite |
| Bouteille | disponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| post-install Homebrew | non défini |
| Service | declared |
| Précautions | To use this SSH agent, set this variable in your ~/.zshrc and/or ~/.bashrc: export SSH_AUTH_SOCK="$HOMEBREW_PREFIX/var/run/yubikey-agent.sock" |
faits du registre
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | yubikey-agent |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
correspondances dans les bases sources
Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.
yubikey-agent 0.1.4-2+b19
seamless ssh agent for YubiKeys
https://github.com/FiloSottile/yubikey-agent
sudo apt install yubikey-agentyubikey-agent
nix profile install nixpkgs#yubikey-agentyubikey-agent 0.1.4-2build1
seamless ssh agent for YubiKeys
https://github.com/FiloSottile/yubikey-agent
sudo apt install yubikey-agentyubikey-agent 0.1.6-r22
Seamless ssh-agent for YubiKeys
https://github.com/FiloSottile/yubikey-agent
sudo apk add yubikey-agentpiste source
Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.