Using a hardware token (YubiKey 5 NFC)¶
A YubiKey 5 NFC (USB-A) or 5C NFC (USB-C) can be used instead of the Duo Mobile app, Touch ID, or Windows Hello — both models work identically for everything on this page. It can also be registered with Duo two different ways, with different capabilities; this page covers both.
Two ways to use a YubiKey¶
| YubiKey used as... | Duo device type | Works for SSH | Works for Duo web | How it's added |
|---|---|---|---|---|
| Security key (WebAuthn/FIDO2) | Security key | No | Yes | Self-service — during enrollment, or later via Managing your devices |
| Hardware token (Yubico OTP) | Hardware Token | Yes | Yes | Admin-added, after a help desk ticket |
The same physical key can be registered both ways on the same Duo account — Duo just sees them as two separate devices:
Enrolling for the first time: use it as a Security key¶
If you don't want to use the Duo Mobile app, Touch ID, or Windows Hello, you can use the YubiKey as a Security key instead — either as your very first Duo device, or as an additional device on an account you're already enrolled in. The screens differ slightly depending on which of those applies to you.
-
Obtain a YubiKey 5 NFC or 5C NFC (either works) — see the product page.
-
Start the security key setup:
-
You have no Duo device at all yet: go to
https://lvk-duo-registration.ligo.org/registration, sign in with your usual LIGO.ORG username and password, then click the big Register with Duo button. You may be asked to sign in a second time. Click Get Started. On the First, add a device screen, choose Security key. -
You already have a Duo device (Duo Mobile, Touch ID, or Windows Hello) and want to add a Security key too: sign in and verify with your existing device, then reach self-service device management — see Managing your devices for the exact clicks (Other options → Manage devices → Add a device). On the Add a device screen, choose Security key.
-
-
Follow your browser's security key setup prompts. If your YubiKey doesn't have a FIDO2 PIN yet, you'll be asked to create one on the spot — or you can set it ahead of time via Yubico Authenticator: click Passkeys in the left menu, then Change PIN.
-
Enter the PIN when prompted, then insert and touch the key again to finish.
-
Duo confirms the security key was added.
This only covers Duo web logins
A Security key device only works for Duo web logins, not SSH — see the table above. If you also SSH into LDG machines, follow Adding a YubiKey as a hardware token below too; the same physical key can be registered both ways.
Already enrolled? Add it as a hardware token (for SSH)¶
If you enrolled with the Duo Mobile app, Touch ID, Windows Hello, or a Security key first, you can still add the same or a different YubiKey as a hardware token to also cover SSH:
-
Download and install Yubico Authenticator, then generate the credential Duo needs:
-
Insert the YubiKey and open Yubico Authenticator. It should recognize the device and show its model, serial number, and supported applications, including Yubico OTP.
-
Click Slots in the left menu, then pick a slot — slot 1 fires on a short touch (about 1–2.5 seconds), slot 2 on a long touch (3+ seconds). Either works for Duo; pick whichever slot is free.
-
Choose Yubico OTP.
- Click the Use serial icon next to Public ID to fill it in from the device.
-
Click Generate random for both Private ID and Secret key.
-
Before clicking Save, capture the three values one of two ways:
- Select and copy each value by hand — especially the Secret key.
- Export to a CSV file — click the Export dropdown next to Cancel / Save, choose Select file, and pick where to save it on your laptop.
The exported file has a single line: serial number, Public ID, Private ID, Secret key, an empty field, and a timestamp, for example:
34646190,vvcccdbcljlu,55bc3011c740,efb333d7cbded35272da5b03d049ad45,,2026-08-07T11:14:50, -
Click Save. If the slot already has a credential in it, Yubico Authenticator will ask you to confirm Overwrite — that's fine, but see the warning below first.
Copy the values immediately, and keep them secure
Private ID and Secret key are shown only once — Yubico Authenticator can't read them back off the key afterward. Copy all three values (Public ID, Private ID, Secret key), or export them to a CSV file, right away, or you'll need to redo this step. Overwriting a slot also permanently replaces whatever was there before — if that slot's old credential is still in use anywhere else, it will stop working once you save.
If you export a CSV file, treat it like a password: it contains the same secret the help desk will use to add your token to Duo. Don't leave it sitting in a Downloads folder — share it via secrets.ligo.org (next step) and then delete the local copy.
-
-
Share the CSV content securely via secrets.ligo.org {: #share-via-secrets } — don't email it or paste it directly into the help desk ticket:
- Go to https://secrets.ligo.org/secrets/ and create a secret.
- Title it
<your username> yubikey, e.g.albert.einstein yubikey. -
Paste the CSV content from the step above into the Secret field, then click Create Secret.
-
On the secret's page, add
Communities:DuoAdmin:authorizedunder Groups permitted to view, so the Duo admin team — and only them — can read it.
-
Copy the secret's page link from your browser's address bar — you'll paste it into the help desk ticket next.
-
Open a help desk ticket requesting that the hardware token be added to your Duo account, and include the secrets.ligo.org link from the previous step so an admin can add it. Don't paste the CSV content itself into the ticket or send it by email — the secrets.ligo.org link is the only place it should live. Title the ticket "Add hardware token for Duo <your username>", e.g. "Add hardware token for Duo albert.einstein".
After September 1: secrets.ligo.org and the help desk also require Duo
Once Duo web enforcement is live, both secrets.ligo.org and the GitLab help desk will themselves require you to already have a second factor registered. If you don't have any second factor yet, first enroll using the YubiKey as a Security key — that's self-service and doesn't depend on either of these tools — then come back here to also add it as a hardware token for SSH.
If you genuinely can't reach either web service, email computing-help@igwn.org instead.
Hardware tokens can't be self-added
Unlike a phone (see Managing your devices), a hardware token can't be added through Duo's self-service device management — it requires the help desk step above.