Guides and downloads
Build, flash, and update in the lab.
csiPass has no production release yet. These guides and download slots are for disposable LAB work. Open milestones live on the Roadmap.
Current development state
Windows/device slices through the early milestones are in tree: five WebAuthn signature algorithms, native companion, standalone HIL, signed application/recovery flows, encrypted microSD safe, fitted RTC, HOTP/TOTP, FIDO-sk SSH, operator Activity, and vault layout vNext. OpenPGP and PIV smart-card applications are done on the LAB card image (milestones 15 and 16, 2026-09-29). CTAP1/U2F remains lab-only. The project is unreleased and unprovisioned for production.
See the boundaryGuides
Short English steps. Deeper detail: deploy/README.md and tracked docs. Never burn eFuses from this page without reading efuse-provisioning.md.
-
1. Get the board and tools
Measured board: Waveshare ESP32-S3-LCD-1.47 (ESP32-S3R8 class). Install Go 1.26+, PlatformIO, and PowerShell 7. Clone the repository.
-
2. Build companion / HIL
From the repo root:
go build -o temp/csipass.exe ./cmd/csipassandgo build -o temp/csipass-hil.exe ./cmd/csipass-hil. Or download a published companion/HIL slot below when available. -
3. Build firmware
Application/lab:
pio rununderfirmware/app. Rescue is a second PlatformIO project underfirmware/rescue— build it when you change shared UI/management/app sources. -
4. First flash
Use
pwsh -File deploy/flash-device.ps1with the lab / FullFlash paths documented in deploy README. Prefer disposable boards and LAB images. -
5. Update application via companion OTA /
.csiPublished firmware on this site is intended as a signed .csi release container, not a lone
.binon the storefront. Companion Firmware catalog installs LAB application images after glass confirmation. -
6. Flash REC-LAB via companion
Guarded ROM-bootloader flow: owner enters ROM mode, companion rediscovers one ESP32-S3 port, writes the factory partition, verifies, and restarts. Manual
flash-device.ps1 -TargetRecoveryremains available. -
7. Stage / install from microSD
Companion-less recovery stages a signed application image on the card, verifies on glass, installs, and reboots. Trust stays on the signature — the card is only transport.
Downloads
Only explicitly marked LAB, REC, and ALPHA test artifacts are published here. They are not production releases.
Loading download catalog…
Unavailable or deferred slots point to source; the site never invents a release link.
Follow the work
- GitHub — source, issues, and future release tags
- CHANGELOG — public releases when they begin
- Build Journal — development builds and unnumbered slices
- Roadmap — open public scale
- Documents — manuals and threat models