{"repo":"danielinux/fidelio","free":true,"listed":false,"github":"https://github.com/danielinux/fidelio","clone":"git clone https://github.com/danielinux/fidelio.git","description":"Fido2+U2F token for 2FA with Raspberry Pi Pico","language":"C","stars":62,"topics":["authentication","fido","fido2","raspberry-pi-pico","rp2040","security","tinyusb","wolfssl"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Fidelio Fidelio turns a Raspberry Pi RP2040 board into a personal USB security key. It supports FIDO2/WebAuthn, discoverable credentials (passkeys), and legacy CTAP1/U2F, using wolfCrypt for cryptography and wolfCOSE for CBOR/COSE. You need an RP2040 board and one normally-open push-button. No secure element or other external component is required. What it supports - CTAP2/FIDO2 and WebAuthn, with CTAP1/U2F compatibility - Physical user presence through a push-button - FIDO2 PINs and PIN-protected operations - Up to 16 discoverable credentials, with one account per relying party - Unlimited non-discoverable credentials - The WebAuthn hmac-secret extension - ES256, Ed25519, ES384, ES512, ML-DSA-44, ML-DSA-65, and ML-DSA-87 - Raspberry Pi Pico and Waveshare RP2040-Zero boards - A master secret reconstructed from the chip's SRAM power-on state instead of stored in flash Fidelio chooses the strongest credential algorithm offered by the relying party. Most existing services will negotiate ES256; newer algorithms work only with clients and services that support them. Quick start 1. Prepare the hardware Connect a normally-open push-button between GND and the board's presence pin. The firmware cannot approve registration or authentication without it. BOARD value Board Presence button Indicator --- --- --- --- pico (default) Raspberry Pi Pico GPIO15 On-board LED rp2040-zero Waveshare RP2040-Zero v1.1 GPIO29 WS2812 on GPIO16 On a Raspberry Pi Pico, the button can be soldered directly i","default_branch":null,"files":null,"tree":[],"storefront":"/r/danielinux","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/danielinux/fidelio/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}