Windows 11 (24H2+) & Windows 10 · FIDO2 · WebAuthn · TPM 2.0

TPM-backed passkeys, under your control.

Darks FIDO2 is an open-source, local-first virtual FIDO2/WebAuthn authenticator for Windows. It combines silicon hardware passkeys, AES-256-GCM encrypted profiles, an offline RFC 6238 TOTP engine, and a secure password generator into a unified Neumorphic desktop suite.

v0.6.4 Beta Released — Review the limitations before relying on it.

What it does

A Windows software authenticator built around local control.

Create and manage local hardware-isolated passkeys, respond to native WebAuthn ceremonies, and generate secure time-based 2FA codes without any cloud reliance.

01

FIDO2 and WebAuthn

Functions as a registered native Windows 11 passkey provider companion for browser and desktop WebAuthn create and get requests.

02

Silicon TPM 2.0 Enclave

Derives non-exportable ES256 hardware keys via Microsoft Platform Crypto Provider with direct TBS diagnostics and explicit key deletion.

03

Encrypted Multi-Profile Vaults

Protects credentials under independent AES-256-GCM vaults with PBKDF2 (600,000 rounds), optional 64-byte physical keyfiles, and DPAPI.

04

Flexible Password Generator

5 independent character sets (Digits, Lowercase, Uppercase, Symbols, Extended ASCII), CSPRNG shuffle, zero disk retention, and 10s clipboard wipe.

05

RFC 6238 TOTP & Screen Sniper

Offline 2FA authenticator with live countdown meters, image importing, and an instant on-screen visual QR code sniper.

06

Signed Audit Chain

Tamper-evident ECDSA-signed CSV audit logging with cryptographic in-memory key scrubbing upon vault lock or disposal.

Big Release

What's New in v0.6.4

Major usability, security, and interface enhancements across the entire stack:

NEW

5-Set Password Generator

Generate high-entropy passwords with independent toggles for all character sets. Zero disk persistence and 10s auto-clearing clipboard.

FIX

6-Character Master PIN

Standardized master PIN requirement to strictly 6 characters across UI, storage, and validation layers, eliminating creation lockouts.

CORE

Dynamic Vault Discovery

Automatically scans local app storage for unindexed vault directories to ensure no profiles are ever lost during transitions.

SEC

TPM Key Deletion

Safely erase silicon-derived TPM hardware keys from the UI with interactive confirmation, NCrypt cleanup, and audit logging.

SEC

PIN-Protected Secret Masking

Masks raw Credential IDs and Public Keys by default in the Credentials Inspector, requiring Master PIN verification to reveal.

UI

Neumorphic UI Polish

20px left-aligned table spacing, responsive wrapping toolbar, standardized status capsules, and 23/23 passing automated tests.

Interface Showcase

Tactile Soft UI with Zero OS Dialogs

Credentials Console

Main Credentials Console & Inspector Drawer

Secure Gate Screen

Biometric Gate & Profile Authentication

Quick start

Try the beta responsibly.

  1. Download the v0.6.4 release from the GitHub Releases page.
  2. Trust the attached Darkbyte-INC.cer public certificate in your Current User Trusted People store.
  3. Run DarksFIDO2-Setup.exe and enable Darks FIDO2 under Windows Settings > Accounts > Passkeys.
  4. Create an encrypted profile (min 6-character PIN) and test with disposable credentials first.

Trust and transparency

Open source, with clear limits.

Darks FIDO2 is Apache-2.0 licensed and experimental. Review the security policy, threat model, security audit (0.6.4), release notes, and compatibility notes before use.