FIDO2 Token Management Tool - fido2-manage

Last updated 2026-10-06

FIDO2 Keys can be managed and configured using standard operating-system tools. No special tool installation is needed to start using FIDO keys — most modern browsers prompt to set a PIN when required, and authentication and enrollment are handled through the browser's standard API. Additional tools are only needed for specific tasks such as changing the PIN, viewing or deleting passkeys, enforcing PIN entry, resetting, fingerprint enrollment, and other advanced configurations.

Overview

fido2-manage is an open-source, cross-platform tool for managing FIDO2 security keys over USB and NFC — passkeys (resident keys), PINs, PIN policy, fingerprints and factory reset. This is the ground-up rewrite of the earlier fido2-manage: a single native application for Windows, macOS and Linux, with no Python/pexpect dependency and the familiar command-line syntax preserved.

The project ships in two forms, in the same package:

  • fido2-manage — the command-line tool (the main deliverable). Drop-in compatible with the classic fido2-manage.exe flag set.
  • Token2 Key Manager — a graphical front-end for fido2-manage, which additionally adds PIV certificate management and OTP / OATH-TOTP/HOTP account management. (This is why it is no longer named "FIDO2 Manager".)

The package also bundles token2-piv-tool for PIV smart-card management on the command line.

New unified tool
This page covers the new cross-platform version. The previous C++ (Windows) and Python/tkinter (Linux) tools are superseded by it; their source is preserved on the legacy branch.

Supported devices

Works with FIDO2.1 (PRE or FINAL) keys from any brand, as well as PIV and OATH-capable devices. With FIDO2.0 keys, passkey management is not possible, so only basic information is shown. Token2 PIN+ and FIDO2 keys are fully supported, including their OTP and PIV applets.

Key features

  • FIDO2: device info and storage statistics, passkey (resident key) listing and deletion, PIN set/change, minimum-PIN-length policy, enforce user-verification (always-UV), fingerprint enrollment/listing/rename/delete on biometric keys, and factory reset.
  • PIV (GUI and token2-piv-tool): generate keys, import/export certificates, PIN/PUK and management-key operations, with a PKCS#11 module.
  • OTP / OATH (GUI): Token2 OTP applet and OATH-TOTP/HOTP account management, including the HID-keyboard (Button-HOTP) and USB-interface settings on Token2 PIN+ keys.
  • Cross-platform & self-contained: native Windows, macOS and Linux builds; no Python runtime required.

Download

The project is fully open-source and available on Github:

Downloads (Releases) Source code

Windows

Download the portable folder. It contains the GUI (token2-key-manager.exe), fido2-manage.exe, the other command-line tools and all required DLLs together. No installation needed — unzip and run.

macOS

Download the signed and notarized .dmg, drag the app to Applications, and launch it.

Linux

Three options are provided:

  • .deb package (recommended) — installs the GUI and CLI tools, and automatically pulls in and enables the required smart-card service. No extra steps:
    sudo apt install ./token2-key-manager_*_amd64.deb
  • AppImage — a single portable file. On Ubuntu 24.04 and newer it requires libfuse2 (sudo apt install libfuse2), or run it with ./Token2-Key-Manager-x86_64.AppImage --appimage-extract-and-run. The bundled command-line tools are reachable via --tool, e.g. ./Token2-Key-Manager-x86_64.AppImage --tool fido2-manage -list.
  • Portable folder — the binaries and libraries, for manual placement.

For the AppImage and portable builds, FIDO2 and PIV need the PC/SC smart-card service installed and running:

sudo apt install pcscd libpcsclite1 libccid
sudo systemctl enable --now pcscd

(The .deb does this for you. OTP works over USB-HID without PC/SC.)


Command-line usage (fido2-manage)

Open a terminal in the folder containing the tool and run fido2-manage with the parameters below. The syntax matches the classic Windows fido2-manage.exe.

Parameters

  • -list: List available devices. With a single key plugged in, the device number is always 1.
  • -info -device [number]: Device information.
  • -storage -device [number]: Resident-credential storage statistics (used / free).
  • -residentKeys -device [number]: List the relying parties (domains) on the device.
  • -residentKeys -device [number] -domain [domain]: List resident keys for a specific domain.
  • -delete -device [number] -credential [credential]: Delete a credential by its ID.
  • -uvs -device [number]: Enforce user verification (always-UV) on.
  • -uvd -device [number]: Disable enforcing user verification.
  • -setPIN -device [number]: Set a PIN (new or freshly reset keys).
  • -changePIN -device [number]: Change the PIN.
  • -reset -device [number]: Factory-reset the FIDO applet. Must be run within ~10 seconds of plugging the key in — replug, run the command, and touch the key when it blinks. This resets only the FIDO applet; it does not affect the OTP or PIV applets on the same key.
  • -forcePINchange -device [number]: Require a PIN change at next use.
  • -setMinimumPIN [minimum] -device [number]: Set the minimum PIN length. Can only be increased, not decreased; a factory reset reverts it (default 4 for regular keys, 6 for PIN+ series, 8 for PIN+ Octo).

Biometric key options

  • -fingerprint -device [number]: Enroll a fingerprint (4 samples of the same finger). Add -fingerprintname [name] to label it.
  • -fingerprintlist -device [number]: List enrolled fingerprints.
  • -deletefingerprint [ID] -device [number]: Delete an enrolled fingerprint by its list ID.
  • -renamefingerprint [ID] -fingerprintname [name] -device [number]: Rename a fingerprint slot.

If -pin [PIN] is omitted on a command that needs it, the tool prompts for the PIN (input is masked). If a PIN does not meet the length or complexity requirements, FIDO_ERR_PIN_POLICY_VIOLATION is returned.

Examples

  1. List devices:
    fido2-manage -list
  2. Device info:
    fido2-manage -info -device 1
  3. Storage statistics:
    fido2-manage -storage -device 1
  4. All relying parties:
    fido2-manage -residentKeys -device 1
  5. Resident keys for a domain:
    fido2-manage -residentKeys -device 1 -domain login.microsoft.com
  6. Delete a credential:
    fido2-manage -delete -device 1 -credential Y+Dh/tSy/Q2IdZt6PW/G1A==
  7. Set a PIN (new/after reset):
    fido2-manage -setPIN -device 1
  8. Change a PIN:
    fido2-manage -changePIN -device 1
  9. Enforce user verification:
    fido2-manage -uvs -device 1
  10. Rename fingerprint in slot #1:
    fido2-manage -renamefingerprint 1 -fingerprintname Index_Finger -device 1
Administrator rights on Windows

Whether you need an elevated terminal depends on how the key is accessed, not on the operation:

  • No admin needed — Token2 keys over USB present a smart-card (CCID / PC-SC) interface, which a normal user process can use. Listing, info, PIN, passkeys, fingerprints and reset all work without elevation.
  • Admin needed — raw-HID FIDO keys (e.g. a YubiKey over USB) and NFC-connected devices are opened directly, and Windows restricts raw FIDO AID accessto elevated processes. Run the app/cli as Administrator for those.

macOS and Linux do not require elevation for either path.


Graphical application (Token2 Key Manager)

The GUI is a native desktop application for Windows, macOS and Linux. It detects the connected key, shows its applets, and provides the FIDO2, PIV and OTP management screens.

FIDO2

  • Select a key; a valid PIN is required to view and manage passkeys and fingerprints. If no PIN is set, "Set PIN" is the only enabled action.
  • Device info: model, AAGUID, firmware version, algorithms, transports, and passkey storage (used / free).
  • Passkeys: list resident credentials (with the relying party / username) and delete them.
  • PIN: set or change the PIN, set the minimum PIN length, enforce user verification (always-UV), and force a PIN change at next use.
  • Fingerprints (biometric keys): list, enroll, rename and delete fingerprints. Token2 keys support up to 29 fingerprints.
  • Reset: factory-reset the FIDO applet (within ~10 seconds of plugging the key in).

PIV

  • Smart-card certificate and key management: generate keys, import/export certificates, and PIN/PUK and management-key operations.

OTP / OATH

  • Token2 OTP applet and OATH-TOTP/HOTP account management, plus the HID-keyboard (Button-HOTP) and USB-interface settings on Token2 PIN+ keys.

On Windows, because FIDO applets of Token2 keys are accessed over the smart-card interface, the GUI does not require administrator rights for those keys. Raw-HID-only keys still need to be run elevated.


Good to know

  • Any brand: the tool works with FIDO2.1 keys from any manufacturer, not only Token2.
  • FIDO2.0 keys: only basic information is shown; passkey management requires FIDO2.1.
  • Platform authenticators / Windows Hello may appear in the device list but cannot be managed by this tool — use the platform's own settings for those.
  • Masked PIN entry: the command-line tool masks PIN input. Deleting a credential is irreversible and asks for confirmation.
  • No Python required: unlike the previous Linux tool, this version is a native binary with no Python/pexpect/tkinter dependency.

FAQ

Q: Is this for Token2 devices only?
A: No. As a member of the FIDO Alliance, we aim to make the tool usable with any standards-compliant device. It works with FIDO2.1 security keys from any brand.

Q: What happened to the old Windows (C++) and Linux (Python) tools?
A: They have been replaced by this single cross-platform version, which removes the Python dependency and adds PIV and OTP management. The old source remains on the legacy branch.

Q: Do I need administrator rights?
A: On Windows, not for latest Token2 keys over USB (smart-card interface). Raw-HID-only keys need an elevated terminal. macOS and Linux need no elevation.