Virt-FIDO2
A small, per-user FIDO2 authenticator for Linux. It appears to browsers and local
applications as a virtual USB security key. Your desktop's Polkit agent verifies
each real registration or login, and the TPM creates and signs with the passkey key.
Browsers may also make silent up=false credential checks; those can use the
TPM without a prompt and do not claim user presence or verification.
This is an early implementation. It supports ES256 CTAP2 passkeys, including discoverable credentials. It does not implement CTAP1/U2F or optional CTAP extensions. Its virtual USB transport is presented as a roaming security key, so sites that insist on a platform-only authenticator may not offer it.
The authenticator identifies its model with AAGUID
7849e707-af46-4b9c-a766-68f5938cd846 and appears locally as
Virt-FIDO2. Websites can display that name only if their AAGUID metadata
recognizes it; the USB name itself is not sent to websites.
Installation
uv tool install virt-fido2
virt-fido2 install
virt-fido2 enable
virt-fido2 install copies the bundled Polkit policy and udev rule into
system directories and reloads udev.
virt-fido2 enable copies the bundled systemD service into the $HOME/.config/systemd/user
and runs the equivalent to `systemctl --user enable --now virt-fido2.service" (just in python)
Run virt-fido2 --help for the other commands.
Development
Requirements
uv- tpm2-tss
- systemd
The user service needs read/write access to the TPM resource manager and
virtual HID device. The bundled udev rule grants it to the active local user,
without tss group membership.
The credential index is stored at
$XDG_DATA_HOME/virt-fido2/credentials.json, or
~/.local/share/virt-fido2/credentials.json by default. The index
contains RP and user metadata plus opaque TPM-wrapped credential IDs. The
private signing key remains protected by the TPM. Back up this file if you
want discoverable credentials to remain findable after restoring your home
directory. The TPM-bound credentials cannot be transferred to another TPM.
Polkit gates operations performed by this service; it is not part of the TPM key's authorization policy. A process that obtains both a credential ID and direct access to the same TPM could bypass this service's prompt. The TPM still prevents export of the private signing key. Protect your user session and credential index accordingly.
Commands
uv run -m unittest discover -s tests -v
uv run ty check
uv run ruff check
License
Virt-FIDO2, a TPM-backed virtual FIDO2 passkey authenticator for Linux
Copyright (C) 2026 VinVel
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
Metadata
Release files for virt-fido2 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| virt_fido2-0.1.0.tar.gz | 35.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| virt_fido2-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 65.3 kB
Release files / virt_fido2-0.1.0.tar.gz
| Download URL | virt_fido2-0.1.0.tar.gz |
|---|---|
| Size | 35.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7c497e60d38fc0d9b45e1cab88181af4f11328c9219532ec040431e1a86d9d9e
|
|
BLAKE2b-256 checksum How to use checksums |
8489625d68fe997c5a95d6ee4e6ef28e300ac42588babd171b713ae71b7667cc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / virt_fido2-0.1.0-py3-none-any.whl
| Download URL | virt_fido2-0.1.0-py3-none-any.whl |
|---|---|
| Size | 30.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a4ab455da87716ed936aea7c4d35ffe505b66b2f1012ed30e6a995bcdc080bab
|
|
BLAKE2b-256 checksum How to use checksums |
d32d053144ec004a6b46e7137ca2ddef8fce6c4b33a1ac2966c3d275fddb3754
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.23 {"installer":{"name":"uv","version":"0.12.23","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|