The validation signature
Whether the OTP presented is valid (okay)
The server nonce to prevent replay attacks
The OTP code
Whether the response signature from the server is valid
Optional
slThe status of the request
The response timestamp
Set to true
if both the OTP presented and the server response signature are valid
The YubiKey device ID that presented the OTP