Source-available lab prototype

See what your key is about to sign.

csiPass puts the site, operation, and account on its own display. One firmware stack and one optional companion cover passkeys, OTP, SSH, files, and updates. Only the glass and physical Confirm can approve.

csiPass Companion showing resident passkeys and their cryptographic properties
csiPass device naming a sign-in site and account before confirmation
See what you signSite, operation, and account on glass. Companion never approves.
Passwordless where it mattersFIDO2/WebAuthn passkeys — Resident and Site-side.
One stick, many secretsPasskeys, OTP, FIDO-sk SSH, encrypted Files, Activity.
All in one stackOne firmware + companion. ESP32-S3R8 board family, not any MCU.
Hardened for this classEncrypted vault, split USB authority, gesture gates. Production SB still a gate.
Post-quantum ready algosML-DSA-44/65 beside ES256, Ed25519, and RS256.

How approval works

The computer asks. The device explains. You decide.

A compromised host can draw a convincing window. It cannot silently replace the relying-party identity shown by firmware or manufacture a fresh physical gesture after the request arrives.

01 / REQUEST

Protocol data arrives

CTAP and management fields are bounded and parsed before they reach the display.

02 / GLASS

The key names the action

Site, operation, and account are rendered by autonomous firmware, not mirrored from the host.

03 / CONFIRM

A fresh press completes it

Success appears only after the cryptographic or protected management operation succeeds.

All in one

One vault layout. Many credential surfaces.

A single application image and optional companion cover FIDO, management, Files, OTP, SSH, and updates — not a zoo of host daemons. The trade-off is honest: the SoC class is ESP32-S3R8 (Waveshare board family via board_profile), not “any MCU.” Panel, touch, RTC, and SD vary inside that family.

Store Capacity Status
Resident / vault-held passkeys200Shipping in LAB
Site-side metadata100Shipping in LAB
OTP (HOTP / TOTP)200Shipping in LAB
SSH FIDO-sk100Shipping in LAB
Activity history1000Shipping in LAB
Encrypted SD safe1024 objects per indexShipping in LAB when SD present
OpenPGP Card3 key roles + card objectsShipping in the LAB card image
PIV24 key slots + containersShipping in the LAB card image
Password Manager (vault / Safe-Type)Flash band reserved (~5.5 MiB)Open (M19)

OpenPGP and PIV work on the LAB card image with GnuPG, OpenSC and Windows; the on-device password vault is visible in the layout and roadmap. None of them is sold as a ready product feature yet. Board family details · Open roadmap

csiPass Companion browsing files inside an encrypted microSD shelf

Optional companion

Manage the key without turning the host into a second approval surface.

The native Go companion inventories credentials, manages the encrypted microSD safe, RTC, Activity, display and firmware, and keeps approval on the device. Protected writes wait for the glass.

  • Resident, Site-side, HOTP/TOTP, and FIDO-sk SSH views
  • Files safe with streaming transfers, notes, and copy history
  • RTC, Activity, Display, Carousel, Storage, and security policy
  • Signed LAB application OTA and guarded REC-LAB factory flashing
  • No private-key, OTP-secret, PIN, or one-time-code export

Current surfaces

Real glass and companion, not mock-ups.

Generated from the native companion and firmware renderers.

Current boundary

Useful in the lab. Not a production security key.

Registration, sign-in, management, HOTP/TOTP, SSH, encrypted files, Activity, and signed LAB update flows work in development builds. Release identity, hardening, hardware validation, and independent review still matter more than another feature checkbox.

Prototype

Secure Boot v2, flash encryption, eFuse rollback policy, production signing and attestation, assigned AAGUID/VID/PID, interoperability, and certification are not complete. Use disposable test data only.

Open roadmap

Licensing

Source-available. Commercial use is a conversation.

Firmware, deploy tooling, documentation, and this site use PolyForm Shield. The Go companion under cmd/ and internal/ uses AGPL-3.0. Shield permits reading, building, running, auditing, and internal deployment — not shipping a competing authenticator product from this work. Commercial use of the companion binaries we distribute for Windows, Linux, and macOS needs a separate license to use that build. A companion you build from source does not. There is no second edition.

Every published release converts to open source four years after publication — code under GPL-3.0-or-later, documentation under CC BY 4.0. The name is licensed to no one: forks ship under their own name (TRADEMARK.md).

Contributions require the CLA. For commercial licensing, OEM, custom board, or redistribution terms, write to the contact below.

Write to me

Questions, licensing, or commercial use.

Anton A. Bespalov

a.bespalov@csilab.ru

github.com/ABespalov/csipass

Orders, OEM, custom boards, and commercial licensing start with an email — not a self-serve cart.