OpenID meets the YubiKey: Clavid's 2008 two-factor login
In August 2008 Clavid let OpenID users add a YubiKey as a second factor. How that one-time-code login worked and how it differs from FIDO2 and passkeys today.
HistoryPublished
In August 2008 you could log in to OpenID-enabled websites with a password and a YubiKey, a small USB key that typed a one-time code when you touched it. The provider that made it possible was Clavid, a Swiss OpenID identity provider, and OpenID Europe announced the integration on 17 August 2008. This page tells the story for readers who arrive from old forum links and want to know what that login was, and how it compares with today’s security keys.
What Clavid announced
The OpenID Europe post presented the YubiKey from Yubico as one of the most appealing security tokens for easy internet authentication. Clavid, the post said, had integrated YubiKey authentication into its professional OpenID provider. The result was two-factor authentication: something you know (a password) plus something you have (the YubiKey, which generates one-time tokens). No manual typing was needed. You put your finger on the key’s touch sensor, and it entered a 44-character one-time token for you.
This was early. Yubico had been founded in Stockholm in 2007, and the first YubiKey was shown publicly at the RSA Conference in April 2008. Clavid’s integration followed only a few months later. More about the provider and its other experiments with smart cards, fingerprints and certificates is in Clavid, Switzerland’s first OpenID provider.
How a one-time-token login worked
The 2008 YubiKey acted as a tiny keyboard. Each touch produced a long string that combined a fixed part identifying the key with a part that changed every time. The server checked that the string was valid and newer than the last one it had accepted. A code could therefore be used only once, and a captured old code was worthless.
For OpenID, the sequence was straightforward. A site asked you for your OpenID. Your browser went to Clavid. Clavid asked for your password and the one-time token. If both were correct, Clavid told the site who you were. The site never saw the key or the password.
The limit of one-time codes
A one-time code is better than a password alone, but it has a weakness that matters in 2026. If an attacker builds a fake login page, you type your password and touch the key, and the fake page forwards both to the real site immediately, the attacker gets in. The code is valid, and it has not been used yet. In other words, the method is not phishing-resistant, a gap explained in phishing-resistant MFA.
OpenID 2.0 had its own version of the same problem. A login that starts by redirecting you to a provider page works only if you can tell the real provider page from a fake one.
What changed: FIDO2, passkeys and the YubiKey of today
The security-key world moved to a different design. Yubico’s key gained FIDO U2F support in 2014, and in April 2018 the company released its first key with FIDO2, which brought WebAuthn and the CTAP protocol. In public-key designs the key signs a challenge for one specific web address. A look-alike site cannot reuse the answer, because the browser includes the real origin in what is signed. The technical background is in FIDO2 and WebAuthn.
Passkeys extend the idea. A passkey is a FIDO credential that can live on a phone, in a password manager or on a hardware key. The YubiKey 5 series, introduced in 2018, supports FIDO2 and passkeys as well as older modes, including the Yubico OTP that Clavid used. For new logins, FIDO2 is the mode to choose wherever a service offers it. See passkeys explained.
| Clavid with YubiKey, 2008 | Security key with FIDO2, today | |
|---|---|---|
| Factors | Password plus one-time token | Key plus PIN or touch (or passkey alone) |
| Technique | One-time code checked on a server | Public-key signature for one website |
| Phishing | Code can be relayed in real time | Login bound to the real web address |
| Where used | OpenID logins at Clavid | Any service with FIDO2 or passkey support |
Which key to buy today
If you want a hardware key now, our YubiKey 5 review assesses the current model, and the guide to hardware security keys explains how to use one and why you should buy two. The whole 2008 story sits in the OpenID timeline.
Facts about the 2008 announcement come from the archived OpenID Europe post. Product details are as documented by the vendors and checked in October 2026.
Frequently asked questions
Did OpenID support the YubiKey in 2008?
Not the protocol itself. OpenID 2.0 left the choice of authentication method to the provider. The Swiss provider Clavid integrated the YubiKey into its own OpenID login, so people with a Clavid OpenID could use the key at any website that accepted OpenID.
Is the 2008 YubiKey one-time password the same as FIDO2?
No. The 2008 method generated a one-time code that a server checked. FIDO2 uses public-key cryptography and binds each login to the real web address, which makes it phishing-resistant. Current YubiKeys offer both, plus other modes.
Can I still use a YubiKey today?
Yes. Current YubiKeys work with FIDO2, passkeys and other protocols. Which sites accept them depends on the service, so check its security settings.
More in History
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.