Guides and downloads

Build, flash, and update in the lab.

csiPass has no production release yet. These guides and download slots are for disposable LAB work. Open milestones live on the Roadmap.

Current development state

Unreleased

Windows/device slices through the early milestones are in tree: five WebAuthn signature algorithms, native companion, standalone HIL, signed application/recovery flows, encrypted microSD safe, fitted RTC, HOTP/TOTP, FIDO-sk SSH, operator Activity, and vault layout vNext. OpenPGP and PIV smart-card applications are done on the LAB card image (milestones 15 and 16, 2026-09-29). CTAP1/U2F remains lab-only. The project is unreleased and unprovisioned for production.

See the boundary

Guides

Short English steps. Deeper detail: deploy/README.md and tracked docs. Never burn eFuses from this page without reading efuse-provisioning.md.

  1. 1. Get the board and tools

    Measured board: Waveshare ESP32-S3-LCD-1.47 (ESP32-S3R8 class). Install Go 1.26+, PlatformIO, and PowerShell 7. Clone the repository.

  2. 2. Build companion / HIL

    From the repo root: go build -o temp/csipass.exe ./cmd/csipass and go build -o temp/csipass-hil.exe ./cmd/csipass-hil. Or download a published companion/HIL slot below when available.

  3. 3. Build firmware

    Application/lab: pio run under firmware/app. Rescue is a second PlatformIO project under firmware/rescue — build it when you change shared UI/management/app sources.

  4. 4. First flash

    Use pwsh -File deploy/flash-device.ps1 with the lab / FullFlash paths documented in deploy README. Prefer disposable boards and LAB images.

  5. 5. Update application via companion OTA / .csi

    Published firmware on this site is intended as a signed .csi release container, not a lone .bin on the storefront. Companion Firmware catalog installs LAB application images after glass confirmation.

  6. 6. Flash REC-LAB via companion

    Guarded ROM-bootloader flow: owner enters ROM mode, companion rediscovers one ESP32-S3 port, writes the factory partition, verifies, and restarts. Manual flash-device.ps1 -TargetRecovery remains available.

  7. 7. Stage / install from microSD

    Companion-less recovery stages a signed application image on the card, verifies on glass, installs, and reboots. Trust stays on the signature — the card is only transport.

Downloads

Only explicitly marked LAB, REC, and ALPHA test artifacts are published here. They are not production releases.

Loading download catalog…

Unavailable or deferred slots point to source; the site never invents a release link.

Follow the work