The console in your browser
The same console, with your passkey as its key.
The firmware a Pico runs, file for file, running in this page. It reads your Safes' queue, says what each transaction does, works out the hash itself, and asks your passkey to sign only what you have seen here.
worked out in your browser, over the files it runs
What your passkey's signatures count as, the same on every chain: add this address to a Safe as an owner, and deploy its signer on that chain (any wallet can: share the deploy link to one with MetaMask or Rabby).
What you approve is this screen. Your browser draws it, and Touch ID won't show the transaction. On a computer you don't trust, use a hardware key, and keep passkey owners below the Safe's threshold.
Keyboard: arrows or W A S D move, Enter or space presses; 9 6 3 . are A B X Y.
Console output
One folder you can read
This page loads nothing from the rest of the site. Everything it runs sits in one folder, and the firmware in it is the console image a Pico runs, as plain files. Save a copy, check it, and sign from your own.
| In the folder | Size |
|---|---|
firmware/The console image: the same 50 files a Pico runs, in MicroPython. They hash to the release fingerprint. | 10,883 lines, and 10 data files |
shims/Python in place of the Pico's hardware: its pins, screen and Wi-Fi, and your passkey as its key. | 638 lines |
console.js, worker.js, web/, core/, shared/, coi.js, sw.jsThe page's JavaScript: the buttons, your passkey, and the worker MicroPython runs in. | 1,107 lines |
vendor/micropython/MicroPython 1.26.0 for WebAssembly, the one part built elsewhere: by the MicroPython project, from npm, pinned by its hash. | 522 KB |
index.html, console.css, fonts/, brand/This page: its words, its look, the site's typeface and mark. |
- 1
Save a copy
SHA256SUMSlists every file. Fetch them, thensha256sum -c SHA256SUMS. No build step: these are the files that run. - 2
Hold it up to the README
Hash
firmware/the way a release is hashed. It gives the fingerprint above, the one in the README's build table and on a Pico's Device screen. - 3
Run your copy
python3 -m http.serverin the folder, then openlocalhost:8000. A site can change its page on any visit. Your copy changes only when you change it. - 4
Make its own passkey
A passkey belongs to the site that made it. One made on your copy can be asked to sign by your copy, on
localhost, and never by this site.