If Touch ID is under your thumb every time your Mac asks, you don't need this.
Plenty of Macs are not like that:
In each case you are back to typing your password, several times a day, for the rest of the machine's life.
OpenHanko puts the sensor where your hand already is. It plugs in over USB-C and macOS treats it as a smart card: rest a finger on it and the lock screen, sudo and authorisation prompts let you through. Nothing to type, nothing to install.
After a restart the login screen takes it too, with or without FileVault — two taps rather than one when the disk is encrypted, and no password. Which is worth stating plainly, because it cuts both ways: whoever holds your OpenHanko and your Mac can open it. Keep them apart when they are not in use together.
Same hardware either way — pick one above.
Locked is the default. Secure boot is on and the debug port is fused, so only firmware signed with the project key will run, and the secret that unwraps your key material is readable by that firmware and by nothing else.
Unlocked leaves those two fuses unburned, so you can build, sign and run your own firmware — and burn the fuses yourself later, with our boot keys or your own. The trade is not subtle: anyone holding an unlocked unit can flash firmware that reads the secret and decrypts the key, so the at-rest encryption stops meaning anything. Buy it to tinker with, not to guard something.
It enumerates as a PIV smart card over USB CCID. macOS reads its certificate, you approve the pairing once, and after that a touch is the whole interaction. The signing key is generated on the device itself at first power-up and has no representation anywhere else — not on a provisioning machine, not in a backup, not with us.
Three steps, once:
Full instructions: openhanko.io/setup
An untouched Mac binds Apple's own smart-card driver, and a touch fills in the PIN for you. The optional OpenHanko app adds guided enrolment, diagnostics, an adjustable idle light, and a touch-only mode with no PIN box at all, wherever macOS allows it.
On a locked unit, which is what ships unless you choose otherwise:
A fingerprint proves an enrolled finger, not a person, and the link to the sensor is not authenticated: someone who opens the case can drive it. A stolen OpenHanko is therefore not inert. This is a key for unlocking your own Mac, where the exposure is bounded by needing that Mac as well. It is not the right place for remote-usable credentials such as SSH keys. The full threat model is published alongside the firmware, in those words.
The firmware and the protocol it speaks are MIT licensed and published at github.com/openhanko. The hardware design is not published.
A hanko (はんこ) is a personal seal — the small stamp you press onto a document to say, unmistakably, that it was you. This one is pressed with a finger, and the open is the firmware.
Mac, macOS and Touch ID are trademarks of Apple Inc., registered in the U.S. and other countries. OpenHanko is not affiliated with, endorsed by or sponsored by Apple Inc.
Ships from Bilbao, Spain, to EU member states only.
Not to the Canary Islands, Ceuta or Melilla. They sit outside the EU customs area, and every carrier prices them as an export — several times the rate shown here.
Tracked and delivered to your door: 2-5 working days in Spain, 4-10 days across most of the EU, 5-12 days to Ireland, Greece, Finland, the Baltics, the Balkans, Malta and Cyprus. Every unit is assembled and provisioned by hand, so allow a few working days for dispatch.
Checkout asks for a phone number because the carriers require one for door delivery. It is passed to the carrier for that delivery and used for nothing else.