Open hardware · lab prototype

See what your key is about to sign.

csiPass puts the site, operation, and account on its own display. The companion can configure the key. Only the glass and physical Confirm can approve it.

csiPass Companion showing an OATH account whose code stays on the device
csiPass device naming a sign-in site and account before confirmation
Autonomous UIFirmware renders every trusted prompt.
Separate USB pathsFIDO and management do not share authority.
Encrypted storageResident vault, site-held journal, and OATH band.
Local-first companionLoopback only; no cloud account required.

One trust surface

The computer asks. The device explains. You decide.

A compromised host can draw a convincing window. It cannot silently replace the relying-party identity shown by firmware or manufacture a fresh physical gesture after the request arrives.

01 / REQUEST

Protocol data arrives

CTAP and management fields are bounded and parsed before they reach the display.

02 / GLASS

The key names the action

Site, operation, and account are rendered by autonomous firmware, not mirrored from the host.

03 / CONFIRM

A fresh press completes it

Success appears only after the cryptographic or protected management operation succeeds.

csiPass Companion Display settings panel

Optional companion

Manage the key without turning the host into a second approval surface.

The local Go companion inventories passkeys and site-held records, enrols HOTP accounts, adjusts display preferences, and manages PIN/UV policy. Protected writes wait for the device.

  • Resident, site-side, and OATH views
  • Display and screensaver controls, including idle CPU presets
  • Rename, delete, reveal-on-glass, PIN policy, and erase flows
  • No private-key, OATH-secret, PIN, or one-time-code export
csiPass Ready screen showing vault use

Built for review

A readable FIDO stack on real ESP32-S3 hardware.

The firmware owns CTAPHID, CTAP2, CTAP1/U2F, Client PIN, credential management, encrypted records, local browsing, and the 172×320 trusted UI. The implementation is intentionally inspectable.

Current boundary

Useful in the lab. Not a production security key.

Registration, sign-in, management, and HOTP work in development builds. Release hardening and independent review still matter more than another feature checkbox.

Prototype

Secure Boot v2, flash encryption, rollback-controlled signed recovery and update, production attestation/VID/PID, interoperability work, and certification are not complete. Use disposable test accounts only.

Track progress

Contact

Questions, review notes, or licensing.