auc-tool 0.1.1

Machine-local software passkey authenticator exposed through Linux UHID.
Documentation

auc

auc is a machine-local Linux software passkey authenticator. A persistent auc-agent system service exposes one external FIDO2 authenticator through Linux UHID; the ordinary auc touch command supplies one explicit user-presence gesture to one pending browser operation.

Requirements

  • Linux with systemd, logind, and /dev/uhid
  • a browser or client that supports external FIDO2 authenticators
  • Rust and Cargo
  • sudo access for installation and removal

Install

cargo install --locked auc-tool
auc system install

Start a new login session after installation so membership in the auc group takes effect.

Use

auc status
auc touch
auc credentials list
auc credentials delete CREDENTIAL_ID

Run auc touch while a browser is waiting for its security-key touch. Credential deletion is permanent.

Maintenance

auc system repair
auc system redeploy
auc system redeploy --version VERSION
auc system job JOB_ID

Redeploy waits for completion by default. Add --no-wait to return after scheduling.

Uninstall

auc system uninstall

This preserves the encrypted vault. To destroy it as well:

auc system uninstall --purge-vault

Vault removal is irreversible.

See DESIGN.md for architecture, protocol, storage, and threat-model details.