Linux HID to PC/SC bridge for FIDO2 smart cards
cryptnox-fido2-bridge is a Linux-only Python bridge that creates a virtual USB-HID device, enabling browsers to use FIDO2 smart cards for WebAuthn/FIDO2 authentication. It translates CTAP2 commands from the browser into PC/SC APDUs for the card.
Works with Cryptnox smart cards and any other FIDO2-capable smart card over PC/SC.
| Smart card | Interface |
|---|---|
| Crypto Hardware Wallet – Dual Card Set | NFC + Contact |
| Cryptnox FIDO2 Security Key & MIFARE DESFire | NFC + Contact |
Works with Cryptnox readers and any other standard PC/SC smart card reader:
| Reader | Type | Interface |
|---|---|---|
| Cryptnox® Smartcard Reader | Contact (ID-1 + SIM) | USB-A |
| Compact USB Mini Smartcard Reader | Contact (ID-1) | USB-A |
| Cryptnox NFC Contactless Reader | Contactless (NFC/ISO 14443) | USB-C |
┌──────────────┐ USB-HID ┌────────────────────────┐ PC/SC ┌─────────────┐
│ Browser │ ◄──────────────► │ Cryptnox FIDO2 Bridge │ ◄────────────►│ Smart Card │
│ (Chrome) │ │ (Virtual Device) │ │ │
└──────────────┘ └────────────────────────┘ └─────────────┘
- The bridge creates a virtual USB-HID device using Linux's UHID facility
- When a browser sends a FIDO2/CTAP2 command via USB-HID
- The bridge translates it to PC/SC APDUs
- Commands are sent to your smart card via the card reader
- Responses are translated back and sent to the browser
This enables using PC/SC smartcards in browsers that only support USB-HID authenticators.
Important
Requires Linux (Ubuntu 22.04+, Debian 12+, or similar) and Python 3.12 or newer.
Check your version with python3 --version.
Install system dependencies (required for all installation methods below):
sudo apt update
sudo apt install -y pcscd pcsc-tools libpcsclite-dev swig \
python3-venv python3-dev build-essential libffi-dev
sudo systemctl enable --now pcscdgit clone https://github.com/Cryptnox/cryptnox-fido2-bridge.git
cd cryptnox-fido2-bridge
pip install poetry
poetry install
# Run
sudo -E env PATH=$PATH poetry run cryptnox-fido2-bridgesudo apt install -y pipx
pipx install git+https://github.com/Cryptnox/cryptnox-fido2-bridge.git
# Run (use full path or add ~/.local/bin to PATH)
sudo -E ~/.local/bin/cryptnox-fido2-bridgepython3 -m venv venv
source venv/bin/activate
pip install git+https://github.com/Cryptnox/cryptnox-fido2-bridge.git
# Run
sudo -E cryptnox-fido2-bridgeTip
Supported browsers: Chrome (recommended), Chromium. Firefox and Brave have limited support due to stricter security policies.
- Connect your smartcard reader to your computer
- Insert your card (or place on NFC reader)
- Run the bridge:
sudo -E cryptnox-fido2-bridge
- Open Chrome and navigate to a WebAuthn site:
- Register or Authenticate - the bridge will communicate with your card!
# Show help
cryptnox-fido2-bridge --help
# Enable debug logging
sudo -E cryptnox-fido2-bridge --debug
# Quiet mode (no banner)
sudo -E cryptnox-fido2-bridge --quiet
# Show version
cryptnox-fido2-bridge --versionIf you installed with pipx and get a "command not found" error when running with sudo, the system cannot find the binary in the root PATH:
# Use the full path
sudo -E ~/.local/bin/cryptnox-fido2-bridge
# Or add ~/.local/bin to your PATH (add to ~/.bashrc)
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
source ~/.bashrcsudo resets PATH, so poetry is often missing. Use the full path or preserve PATH:
sudo -E ~/.local/bin/poetry run cryptnox-fido2-bridge
# Or
sudo -E env "PATH=$PATH" poetry run cryptnox-fido2-bridgeIf you get a permission error when running the bridge, the current user does not have access to the UHID device. You can fix this temporarily or permanently:
# Fix permissions
sudo chmod 666 /dev/uhid
# Or create udev rule (permanent fix)
sudo tee /etc/udev/rules.d/70-cryptnox-fido2.rules << 'EOF'
KERNEL=="uhid", MODE="0666"
EOF
sudo udevadm control --reload-rules
sudo udevadm triggerIf the bridge cannot find your card, pcscd may not be running or the reader is not properly recognized:
# Check if pcscd is running
sudo systemctl status pcscd
# Restart pcscd
sudo systemctl restart pcscd
# Test card detection
pcsc_scanThe CryptnoxCR USB contact reader (0x05F8:0x0018) is included in upstream CCID from version 1.7.1 onward. That driver is what pcscd uses (via the libccid / ifd-ccid bundle on Debian and Ubuntu).
Check your installed version:
dpkg -l libccidIf it is older than 1.7.1, build and install from source as Ubuntu does not yet package a newer version.
Installs the driver files but dpkg will still report the old version.
sudo apt install -y meson libusb-1.0-0-dev flex libpcsclite-dev
wget https://ccid.apdu.fr/files/ccid-1.8.0.tar.xz
tar -xf ccid-1.8.0.tar.xz
cd ccid-1.8.0
meson setup builddir
cd builddir
meson compile
sudo meson install
sudo systemctl restart pcscd.socket pcscd
pcsc_scan -rCreates a .deb and registers it with dpkg so the version is correctly tracked and can be removed with apt remove.
sudo apt install -y meson libusb-1.0-0-dev flex libpcsclite-dev checkinstall
wget https://ccid.apdu.fr/files/ccid-1.8.0.tar.xz
tar -xf ccid-1.8.0.tar.xz
cd ccid-1.8.0
meson setup builddir
cd builddir
meson compile
sudo checkinstall --pkgname=libccid --pkgversion=1.8.0 --pkgrelease=1 --nodoc meson install
sudo systemctl restart pcscd.socket pcscd
pcsc_scan -rcryptnox-fido2-bridge is licensed under the MIT License — see LICENSE for details.
This project is based on fido2-hid-bridge by Bryan Jacobs, also MIT-licensed.
