A DO-IT-YOURSELF FINGERPRINT UNLOCK FOR A MAC, BUILT TO AVOID APPLE'S 149 DOLLAR TOUCH ID KEYBOARD
A ZW101-style sensor and an ESP32-S3 in a 3D-printed case unlock your Mac with your fingerprint, and the creator tells you plainly when Apple's 149-dollar Touch ID keyboard is worth it instead.
by Zimeng Xiong
Open-hardwareAutomation
Built withESP323D printing
- difficulty
- ●●●○○
- time
- a weekend
- license
- MIT
- repo
- repo ACTIVE1,585 stars
●●●○○ · a weekend · MIT · 1,585 stars · repo ACTIVE
WHAT YOU’LL NEED
Jump to section
COMPAREE VERDICT
tinyTouch is a straightforward weekend build if you have soldered before and are comfortable in a Mac terminal. The appeal is not just saving money against Apple's 149-dollar Magic Keyboard with Touch ID; it is seeing how the authentication works, and the author's honesty about where it falls short. The hardware is an ESP32-S3 (a Seeed XIAO in the reference build) wired to a ZW101-style fingerprint sensor in a small 3D-printed case. In HID mode the helper keeps your password in the Mac's login Keychain and the device types it after a fingerprint match over an encrypted, replay-protected exchange; a second PIV/PAM mode uses smart-card authentication instead. The author strongly recommends enabling Secure Boot and Flash Encryption on the ESP32-S3, because without them the keys can be dumped from flash. What makes the project unusual is that he documents the weak spot himself: the sensor talks to the board over unauthenticated UART, so it can be spoofed with physical access; he suggests filling the case with black epoxy as a basic countermeasure and a better sensor as the real fix, and says that for sensitive data or a company device Apple's keyboard is excellent value. The most likely thing to go wrong is a sensor that does not speak the 0xef01 protocol the firmware expects.
IN THE REPO
GOOD TO KNOW
- —MIT licence, permits commercial use without restriction.
- —3D printed enclosure files for the sensor and ESP32 are in the repo (STL).
- —Complete firmware for ESP32-S3 and macOS helper app are present, with setup instructions.
- —Author documents the major weakness himself: unauthenticated UART between sensor and board can be spoofed.
- —HID mode keeps passwords on the Mac encrypted; PIV/PAM mode uses challenge-response but does not cover Keychain.
- —No PCB Gerbers because this is a direct wire build between the sensor module and the XIAO board.
Parts to buy
4 itemsFrom our check of the build. Exact quantities and part numbers are in the creator’s BOM.
Can I build this?
Build at your own risk. Projects involve tools, electronics and sometimes mains voltage — follow the creator’s safety notes.
Videos
The creator's own assembly guide video on his Alpaca Engineering channel, linked from the top of the README; short demo clips of HID and PIV unlocks are embedded in the README too.
More builds like this
All projectsGallery
Start here
Navigation into the creator’s own docs — we don’t rewrite the guide, we route you to the source.
- 1.Check the ZW101 datasheet before buying(Several modules share the name but use incompatible UART command sets; the firmware expects specific responses.)
- 2.Print the enclosure (STL files are in the hardware folder, designed for the XIAO and ZW101 form factor.)
- 3.Wire sensor to XIAO (TX and RX (XIAO D6 and D7, crossed to the sensor), the touch-detect line on D1, both sensor power pins to 3.3 V, and ground. The pinout is in the README and docs.)
- 4.Flash the ESP32 firmware (Hold BOOT while plugging in, then install the Factory firmware from the browser-based Flash center (Chrome or Edge); building from source needs ESP-IDF 5.3.)
- 5.Install macOS helper app and pair (Helper runs in the background, handles pairing key storage and password encryption. Terminal commands in the README.)
- 6.Enroll fingerprints and test (Use the helper to enroll; HID mode works immediately, PIV/PAM mode requires additional PAM configuration.)
Resources
Documentation, files and community threads for this build — we link straight to the original sources and never rehost the creator’s files.
KNOWN ISSUES
- Buy a sensor that speaks the protocol the firmware expects: the README specifies a ZW101-style UART sensor using the common 0xef01 packet protocol, and other sensors only work if they use the same protocol.
- The unauthenticated UART link between sensor and board means someone with physical access to your case can spoof it; if you work with sensitive data or company machines, this is not a theoretical risk.
- PIV/PAM mode is stronger against keyloggers but does not unlock Keychain or settings panels—HID mode covers more use cases but stores the password encrypted on the Mac, not on a challenge-response token.
- Enable Secure Boot and Flash Encryption on the ESP32-S3, as the README strongly recommends; without them the pairing keys can be dumped from flash.
- If the Mac does not see the device after flashing, check the USB-C cable (some are charge-only), reflash from the web Flash center, and rerun tinytouch setup.
- The project is Mac-only; there is no Windows or Linux helper and adapting it would require rewriting the password encryption and PAM integration from scratch.
How does this compare to Apple's Magic Keyboard with Touch ID in terms of security?
Apple's uses a Secure Enclave and authenticated communication between sensor and controller, so the entire chain is cryptographically verified. tinyTouch uses encrypted storage and nonce-based replay protection, but the sensor-to-board link over UART is unauthenticated, which the author documents as the major weakness. For sensitive or company machines, he recommends buying Apple's.
Can I use this with a Windows or Linux machine?
No. The helper app and password encryption are written for macOS only. Porting would require rewriting the PAM integration and Keychain interface, which is not a weekend job.
What happens if someone steals the device?
If Secure Boot and Flash Encryption are enabled, dumping the chip does not reveal the pairing key. But the encrypted password is still on your Mac, so if they also have access to your machine they can pair a new device by enrolling a new fingerprint. Physical security of both matters.
Do I need to solder surface-mount components?
No. You solder a handful of wires between the ZW101-style sensor and the ESP32-S3 board (TX, RX, touch detect, 3.3 V and ground). Basic soldering skill is enough.
How long does a fingerprint recognition take?
The README does not give a timing; the demo clips show login and sudo prompts unlocking with a finger touch.
Community builds
No community builds yet — be the first, we feature the best ones.
Discussion1
FROM THE COMPAREE TEAM
The author documents the unauthenticated UART as the major weakness and recommends Apple's keyboard for sensitive machines—have you built something where you had to write the honest limitation yourself?
Zimeng Xiong
Zimeng built tinyTouch to avoid paying 149 dollars for Apple's Magic Keyboard with Touch ID, then documented the security trade-offs plainly enough that he tells readers when Apple's is worth the money. The project is MIT licensed, and preassembled units are available for pre-order at tinytouch.dev.
DISCLAIMER
- Comparee is not the author of the projects featured here. All rights to each project belong to its creator — every page links to the original source, and we never host creators’ files.
- Information is provided without warranty and may become outdated as projects evolve. Prices are indicative bands only — always check the creator’s parts list for current costs.
- Building and operating any project is at your own responsibility. Protective equipment, safe workshop practice and compliance with local regulations are the builder’s responsibility.
CompareeTEAM2mo agoedited
Practical notes from our verification: the README has demo clips of fingerprint login at the lock screen and of sudo prompts, plus a build guide video on YouTube. Firmware is installed from the browser-based Flash center in Chrome or Edge, or built from source with ESP-IDF 5.3; the old Arduino sketch is no longer part of the repository. The hardware table lists a Seeed Studio ESP32-S3 and says Secure Boot and Flash Encryption are strongly recommended — without them, the keys can be dumped from flash. For the sensor, the README specifies a ZW101-style UART sensor using the common 0xef01 packet protocol, so check that before you buy. The author's own security table, which marks the unauthenticated UART link as a weakness and recommends Apple's keyboard for sensitive or company machines, is the most honest part of the whole project. Pre-assembled versions are also offered. Correction (4 October 2026): we re-checked this page line by line against the project's own repository, documentation and videos, and fixed errors in earlier versions.