Protocol data arrives
CTAP and management fields are bounded and parsed before they reach the display.
Source-available lab prototype
csiPass puts the site, operation, and account on its own display. One firmware stack and one optional companion cover passkeys, OTP, SSH, files, and updates. Only the glass and physical Confirm can approve.
How approval works
A compromised host can draw a convincing window. It cannot silently replace the relying-party identity shown by firmware or manufacture a fresh physical gesture after the request arrives.
CTAP and management fields are bounded and parsed before they reach the display.
Site, operation, and account are rendered by autonomous firmware, not mirrored from the host.
Success appears only after the cryptographic or protected management operation succeeds.
All in one
A single application image and optional companion cover FIDO, management,
Files, OTP, SSH, and updates — not a zoo of host daemons. The trade-off is
honest: the SoC class is ESP32-S3R8 (Waveshare board family
via board_profile), not “any MCU.” Panel, touch, RTC, and SD
vary inside that family.
| Store | Capacity | Status |
|---|---|---|
| Resident / vault-held passkeys | 200 | Shipping in LAB |
| Site-side metadata | 100 | Shipping in LAB |
| OTP (HOTP / TOTP) | 200 | Shipping in LAB |
| SSH FIDO-sk | 100 | Shipping in LAB |
| Activity history | 1000 | Shipping in LAB |
| Encrypted SD safe | 1024 objects per index | Shipping in LAB when SD present |
| OpenPGP Card | 3 key roles + card objects | Shipping in the LAB card image |
| PIV | 24 key slots + containers | Shipping in the LAB card image |
| Password Manager (vault / Safe-Type) | Flash band reserved (~5.5 MiB) | Open (M19) |
OpenPGP and PIV work on the LAB card image with GnuPG, OpenSC and Windows; the on-device password vault is visible in the layout and roadmap. None of them is sold as a ready product feature yet. Board family details · Open roadmap
Optional companion
The native Go companion inventories credentials, manages the encrypted microSD safe, RTC, Activity, display and firmware, and keeps approval on the device. Protected writes wait for the glass.
Current surfaces
Generated from the native companion and firmware renderers.



Current boundary
Registration, sign-in, management, HOTP/TOTP, SSH, encrypted files, Activity, and signed LAB update flows work in development builds. Release identity, hardening, hardware validation, and independent review still matter more than another feature checkbox.
Secure Boot v2, flash encryption, eFuse rollback policy, production signing and attestation, assigned AAGUID/VID/PID, interoperability, and certification are not complete. Use disposable test data only.
Open roadmapLicensing
Firmware, deploy tooling, documentation, and this site use
PolyForm Shield. The Go companion under
cmd/ and internal/ uses AGPL-3.0.
Shield permits reading, building, running, auditing, and internal
deployment — not shipping a competing authenticator product from this work.
Commercial use of the companion binaries we distribute for Windows,
Linux, and macOS needs a separate license to use that build. A
companion you build from source does not. There is no second edition.
Every published release converts to open source four years after
publication — code under GPL-3.0-or-later, documentation under CC
BY 4.0. The name is licensed to no one: forks ship under their own
name
(TRADEMARK.md).
Contributions require the CLA. For commercial licensing, OEM, custom board, or redistribution terms, write to the contact below.
Write to me
Anton A. Bespalov
Orders, OEM, custom boards, and commercial licensing start with an email — not a self-serve cart.