According to the sentense below in this page, "Security Key by Yubico" does NOT have a serial number.
Serial numbers are unique across all models of YubiKeys, with the exception of Security Keys, which do not have serial numbers.
However, in Yubico Demonstration Site, the same "Yubico" can register security key in only 1 key.
So, I consider that "Yubico" has some mechanism to identify each "Yubiko" without using serial number.
Then, how does the authenticator in webserver identify each key without a serial number?