A DO-IT-YOURSELF FINGERPRINT UNLOCK FOR A MAC, BUILT TO AVOID APPLE'S 149 DOLLAR TOUCH ID KEYBOARD

A ZW101-style sensor and an ESP32-S3 in a 3D-printed case unlock your Mac with your fingerprint, and the creator tells you plainly when Apple's 149-dollar Touch ID keyboard is worth it instead.

by Zimeng Xiong

FULL CAD BOM FIRMWARE DOCS

Open-hardwareAutomation

Built withESP323D printing

difficulty
●●●○○
time
a weekend
license
MIT
repo
repo ACTIVE1,585 stars
1
Jump to section

COMPAREE VERDICT

tinyTouch is a straightforward weekend build if you have soldered before and are comfortable in a Mac terminal. The appeal is not just saving money against Apple's 149-dollar Magic Keyboard with Touch ID; it is seeing how the authentication works, and the author's honesty about where it falls short. The hardware is an ESP32-S3 (a Seeed XIAO in the reference build) wired to a ZW101-style fingerprint sensor in a small 3D-printed case. In HID mode the helper keeps your password in the Mac's login Keychain and the device types it after a fingerprint match over an encrypted, replay-protected exchange; a second PIV/PAM mode uses smart-card authentication instead. The author strongly recommends enabling Secure Boot and Flash Encryption on the ESP32-S3, because without them the keys can be dumped from flash. What makes the project unusual is that he documents the weak spot himself: the sensor talks to the board over unauthenticated UART, so it can be spoofed with physical access; he suggests filling the case with black epoxy as a basic countermeasure and a better sensor as the real fix, and says that for sensitive data or a company device Apple's keyboard is excellent value. The most likely thing to go wrong is a sensor that does not speak the 0xef01 protocol the firmware expects.

GOOD TO KNOW

  • —MIT licence, permits commercial use without restriction.
  • —3D printed enclosure files for the sensor and ESP32 are in the repo (STL).
  • —Complete firmware for ESP32-S3 and macOS helper app are present, with setup instructions.
  • —Author documents the major weakness himself: unauthenticated UART between sensor and board can be spoofed.
  • —HID mode keeps passwords on the Mac encrypted; PIV/PAM mode uses challenge-response but does not cover Keychain.
  • —No PCB Gerbers because this is a direct wire build between the sensor module and the XIAO board.

Parts to buy

4 items

From our check of the build. Exact quantities and part numbers are in the creator’s BOM.

  • Seeed XIAO ESP32-S3Find
  • ZW101-style UART fingerprint sensor using the common 0xef01 packet protocolFind
  • USB-C data cableFind
  • Few short wiresFind

BUILDS OF THE WEEK

Five open-source builds worth your weekend, every week.

Checked like this one: what’s really in the repo, what it costs, how hard it is. One email, unsubscribe anytime.

Can I build this?

PrintSmall enclosure for sensor and ESP32 board (STL files in repo)
BuySeeed XIAO ESP32-S3 (or another ESP32-S3 with native USB and hardware UART), a ZW101-style UART fingerprint sensor using the common 0xef01 packet protocol, a USB-C data cable, and a few short wires.
ToolsSoldering iron, 3D printer or access to one, a Mac, Chrome or Edge for the web flasher, and terminal comfort for the tinytouch CLI
SkillsBasic soldering, command-line comfort on macOS, willingness to troubleshoot USB enumeration if the Mac does not recognise the board immediately
TimeFour to six hours across a weekend: printing the case, soldering four wires, flashing the ESP32, pairing with the helper app, and enrolling fingerprints
CostLow band: an ESP32-S3 board and a ZW101-style sensor are inexpensive parts; the README compares the project with Apple's 149-dollar keyboard.
SafetyNo mains voltage, no high-energy cells. The security trade-off is real: unauthenticated UART means physical access to the case allows spoofing. Do not use this for machines where unauthorised access has regulatory or employment consequences.

Build at your own risk. Projects involve tools, electronics and sometimes mains voltage — follow the creator’s safety notes.

Videos

The creator's own assembly guide video on his Alpaca Engineering channel, linked from the top of the README; short demo clips of HID and PIV unlocks are embedded in the README too.

More builds like this

All projects

Gallery

Start here

Navigation into the creator’s own docs — we don’t rewrite the guide, we route you to the source.

  1. 1.Check the ZW101 datasheet before buying(Several modules share the name but use incompatible UART command sets; the firmware expects specific responses.)
  2. 2.Print the enclosure (STL files are in the hardware folder, designed for the XIAO and ZW101 form factor.)
  3. 3.Wire sensor to XIAO (TX and RX (XIAO D6 and D7, crossed to the sensor), the touch-detect line on D1, both sensor power pins to 3.3 V, and ground. The pinout is in the README and docs.)
  4. 4.Flash the ESP32 firmware (Hold BOOT while plugging in, then install the Factory firmware from the browser-based Flash center (Chrome or Edge); building from source needs ESP-IDF 5.3.)
  5. 5.Install macOS helper app and pair (Helper runs in the background, handles pairing key storage and password encryption. Terminal commands in the README.)
  6. 6.Enroll fingerprints and test (Use the helper to enroll; HID mode works immediately, PIV/PAM mode requires additional PAM configuration.)

Resources

Documentation, files and community threads for this build — we link straight to the original sources and never rehost the creator’s files.

KNOWN ISSUES

  • Buy a sensor that speaks the protocol the firmware expects: the README specifies a ZW101-style UART sensor using the common 0xef01 packet protocol, and other sensors only work if they use the same protocol.
  • The unauthenticated UART link between sensor and board means someone with physical access to your case can spoof it; if you work with sensitive data or company machines, this is not a theoretical risk.
  • PIV/PAM mode is stronger against keyloggers but does not unlock Keychain or settings panels—HID mode covers more use cases but stores the password encrypted on the Mac, not on a challenge-response token.
  • Enable Secure Boot and Flash Encryption on the ESP32-S3, as the README strongly recommends; without them the pairing keys can be dumped from flash.
  • If the Mac does not see the device after flashing, check the USB-C cable (some are charge-only), reflash from the web Flash center, and rerun tinytouch setup.
  • The project is Mac-only; there is no Windows or Linux helper and adapting it would require rewriting the password encryption and PAM integration from scratch.

How does this compare to Apple's Magic Keyboard with Touch ID in terms of security?

Apple's uses a Secure Enclave and authenticated communication between sensor and controller, so the entire chain is cryptographically verified. tinyTouch uses encrypted storage and nonce-based replay protection, but the sensor-to-board link over UART is unauthenticated, which the author documents as the major weakness. For sensitive or company machines, he recommends buying Apple's.

Can I use this with a Windows or Linux machine?

No. The helper app and password encryption are written for macOS only. Porting would require rewriting the PAM integration and Keychain interface, which is not a weekend job.

What happens if someone steals the device?

If Secure Boot and Flash Encryption are enabled, dumping the chip does not reveal the pairing key. But the encrypted password is still on your Mac, so if they also have access to your machine they can pair a new device by enrolling a new fingerprint. Physical security of both matters.

Do I need to solder surface-mount components?

No. You solder a handful of wires between the ZW101-style sensor and the ESP32-S3 board (TX, RX, touch detect, 3.3 V and ground). Basic soldering skill is enough.

How long does a fingerprint recognition take?

The README does not give a timing; the demo clips show login and sudo prompts unlocking with a finger touch.

Community builds

No community builds yet — be the first, we feature the best ones.

Discussion1

FROM THE COMPAREE TEAM

The author documents the unauthenticated UART as the major weakness and recommends Apple's keyboard for sensitive machines—have you built something where you had to write the honest limitation yourself?

CompareeTEAM2mo agoedited

Practical notes from our verification: the README has demo clips of fingerprint login at the lock screen and of sudo prompts, plus a build guide video on YouTube. Firmware is installed from the browser-based Flash center in Chrome or Edge, or built from source with ESP-IDF 5.3; the old Arduino sketch is no longer part of the repository. The hardware table lists a Seeed Studio ESP32-S3 and says Secure Boot and Flash Encryption are strongly recommended — without them, the keys can be dumped from flash. For the sensor, the README specifies a ZW101-style UART sensor using the common 0xef01 packet protocol, so check that before you buy. The author's own security table, which marks the unauthenticated UART link as a weakness and recommends Apple's keyboard for sensitive or company machines, is the most honest part of the whole project. Pre-assembled versions are also offered. Correction (4 October 2026): we re-checked this page line by line against the project's own repository, documentation and videos, and fixed errors in earlier versions.

Zimeng Xiong

Zimeng built tinyTouch to avoid paying 149 dollars for Apple's Magic Keyboard with Touch ID, then documented the security trade-offs plainly enough that he tells readers when Apple's is worth the money. The project is MIT licensed, and preassembled units are available for pre-order at tinytouch.dev.

GitHub

Star the project on GitHub

DISCLAIMER

  • Comparee is not the author of the projects featured here. All rights to each project belong to its creator — every page links to the original source, and we never host creators’ files.
  • Information is provided without warranty and may become outdated as projects evolve. Prices are indicative bands only — always check the creator’s parts list for current costs.
  • Building and operating any project is at your own responsibility. Protective equipment, safe workshop practice and compliance with local regulations are the builder’s responsibility.