YubiKey Guide
Use a YubiKey as your root key for the strongest possible identity protection. Your root key lives inside the hardware token — it cannot be extracted, even by you.
Requirements
- YubiKey 5 series with firmware 5.7.0 or later (Ed25519 PIV support)
- NFC-capable device — iPhone 7+ or Android with NFC
- Mark app v3.0.0 or later
Initial setup
4 stepsSetup takes about 30 seconds. You will need your YubiKey and your phone.
- Open Mark and go to Settings → Identity → Root Key.
- Tap “Set up YubiKey” and hold your YubiKey to the NFC reader.
- Enter your PIN when prompted. (Default PIN is 123456 — you should change it.)
- Done. Mark generates an Ed25519 key inside the YubiKey's PIV slot 9a, creates a subkey certificate, and publishes your updated service record.
Everything happens in a single NFC session — one tap, one PIN entry.
Daily use
After setup, you sign documents using your device's signing subkey as usual — Face ID or fingerprint, no YubiKey needed. The YubiKey is only required for:
- Subkey rotation — when your signing subkey expires (every 90 days by default)
- Key revocation — if you need to revoke a compromised subkey
- Identity updates — changing your trust tier or service record
For these operations, Mark will prompt you to tap your YubiKey and enter your PIN.
PIN management
Change your PIN immediately after setup. Mark will prompt you if it detects the default PIN. The PUK is your recovery mechanism — store it securely offline.
Hardware attestation
When you set up a YubiKey, Mark extracts the PIV attestation certificate. This certificate is signed by Yubico's root CA and proves:
- The key was generated on a genuine YubiKey
- The key was generated inside the secure element (not imported)
- The key cannot be exported
This attestation is uploaded to the Mark server and included in your service record. Verifiers can independently validate it against Yubico's published root certificate.
Hardware attestation is what enables Trust Tier 4 (T4) — the highest identity assurance level.