Passkeys you can see before you approve
csiPass is a USB authenticator whose screen is the trust surface. The host can lie. The glass cannot approve remotely.
Why
A passkey is only as honest as the place you decide to use it. csiPass puts that decision on a small trusted display attached to the key itself: relying-party identity, operation, and account when the protocol supplies it.
An optional local companion helps you list credentials, change PIN policy, and adjust display preferences. It never presses Confirm. Approval stays on the device.
Who it is for
Builders who want a readable FIDO stack on real hardware. Security reviewers who need source they can audit. Early adopters who accept a development board instead of a sealed product.
Use disposable test accounts only. csiPass is not FIDO certified, not a finished commercial key, and not something you should make the only way into anything you care about.
Trust model in one line
A compromised computer can show you anything in the companion and still cannot authorise a registration or assertion. Only a fresh physical gesture after the request arrives — Confirm on the device — completes the cryptographic step.
Footer claim, same as the companion: No blind signing. No black boxes.
Status
Contact
Anton A. Bespalov
a.bespalov@csilab.ru
github.com/ABespalov/csipass
Commercial licensing inquiries and CLA questions use the same address.