Skip to main content

Virt-FIDO2

A small, per-user FIDO2 authenticator for Linux. It appears to browsers and local applications as a virtual USB security key. Your desktop's Polkit agent verifies each real registration or login, and the TPM creates and signs with the passkey key. Browsers may also make silent up=false credential checks; those can use the TPM without a prompt and do not claim user presence or verification.

This is an early implementation. It supports ES256 CTAP2 passkeys, including discoverable credentials. It does not implement CTAP1/U2F or optional CTAP extensions. Its virtual USB transport is presented as a roaming security key, so sites that insist on a platform-only authenticator may not offer it.

The authenticator identifies its model with AAGUID 7849e707-af46-4b9c-a766-68f5938cd846 and appears locally as Virt-FIDO2. Websites can display that name only if their AAGUID metadata recognizes it; the USB name itself is not sent to websites.

Installation

uv tool install virt-fido2
virt-fido2 install
virt-fido2 enable

virt-fido2 install copies the bundled Polkit policy and udev rule into system directories and reloads udev.

virt-fido2 enable copies the bundled systemD service into the $HOME/.config/systemd/user and runs the equivalent to `systemctl --user enable --now virt-fido2.service" (just in python)

Run virt-fido2 --help for the other commands.

Development

Requirements

  • uv
  • tpm2-tss
  • systemd

The user service needs read/write access to the TPM resource manager and virtual HID device. The bundled udev rule grants it to the active local user, without tss group membership.

The credential index is stored at $XDG_DATA_HOME/virt-fido2/credentials.json, or ~/.local/share/virt-fido2/credentials.json by default. The index contains RP and user metadata plus opaque TPM-wrapped credential IDs. The private signing key remains protected by the TPM. Back up this file if you want discoverable credentials to remain findable after restoring your home directory. The TPM-bound credentials cannot be transferred to another TPM.

Polkit gates operations performed by this service; it is not part of the TPM key's authorization policy. A process that obtains both a credential ID and direct access to the same TPM could bypass this service's prompt. The TPM still prevents export of the private signing key. Protect your user session and credential index accordingly.

Commands

uv run -m unittest discover -s tests -v
uv run ty check
uv run ruff check

License

    Virt-FIDO2, a TPM-backed virtual FIDO2 passkey authenticator for Linux
    Copyright (C) 2026 VinVel


    This program is free software: you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation, either version 3 of the License, or
    (at your option) any later version.

    This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.

    You should have received a copy of the GNU General Public License
    along with this program. If not, see <https://www.gnu.org/licenses/>.

Metadata

Release files for virt-fido2 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for virt-fido2 0.1.0
File Size Uploaded
virt_fido2-0.1.0.tar.gz 35.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for virt-fido2 0.1.0
File Interpreter ABI Platform
virt_fido2-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 65.3 kB

Release files / virt_fido2-0.1.0.tar.gz

Download URL virt_fido2-0.1.0.tar.gz
Size 35.0 kB
Tags Source
SHA-256 checksum
How to use checksums
7c497e60d38fc0d9b45e1cab88181af4f11328c9219532ec040431e1a86d9d9e
BLAKE2b-256 checksum
How to use checksums
8489625d68fe997c5a95d6ee4e6ef28e300ac42588babd171b713ae71b7667cc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / virt_fido2-0.1.0-py3-none-any.whl

Download URL virt_fido2-0.1.0-py3-none-any.whl
Size 30.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a4ab455da87716ed936aea7c4d35ffe505b66b2f1012ed30e6a995bcdc080bab
BLAKE2b-256 checksum
How to use checksums
d32d053144ec004a6b46e7137ca2ddef8fce6c4b33a1ac2966c3d275fddb3754
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

0.2.0

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page