Skip to content

About

🗝️ Windows 11 tray utility that automatically selects USB security keys in FIDO2/WebAuthn prompts, with authenticator priorities and optional PIN handling.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

AuthenticatorChooser

Build Release .NET 8 Windows 11 License

Windows 11 asks “phone or security key?” every time you use a USB key. This program sits in the tray and clicks Security key for you. You can pause it, autostart it, rank other authenticators, and optionally handle the USB-key PIN by length or a temporary in-memory cache (never saved to disk).

Windows asking to choose a phone or a security key

The phone screen disappearing as Security key is chosen

Status window

Local preview (this repo)

From the repo root, double-click run-local.cmd or:

.\scripts\run-local.ps1

That stops the running tray process, publishes a single exe to artifacts\local\AuthenticatorChooser.exe, and opens the status window (--show-window). Use that folder as the local preview; do not dig through bin\Release\net8.0-windows\win-x64\publish.

artifacts\ is gitignored build output:

  • artifacts\local\ — daily preview (this script)
  • artifacts\AuthenticatorChooser-Setup-*.exe — installer from release-gate
  • artifacts\sandbox-in\ / sandbox-out\ — Windows Sandbox checks, not for running the app

Install

Needs Windows 11 (22H2 Moment 4 or newer) and the .NET 8 Desktop Runtime. On Remote Desktop, run it on the client PC, not the remote one.

  1. Download AuthenticatorChooser-Setup-win-x64.exe from Releases (or win-arm64 on ARM PCs).
  2. Run the setup (UAC). It puts the program in Program Files and adds a Start Menu shortcut.
  3. It stays in the tray — double-click the key icon for the window. Leave Start when I sign in on if you want it after logon.

Uninstall from Settings → Apps. That stops the program and removes Program Files, the shortcut, the logon task, and %AppData%\AuthenticatorChooser (settings and logs).

Try it on webauthn.io → Authenticate.

Updates

Installed from Setup, it checks GitHub for a newer installer when you sign in to Windows and applies it in the background. Check for updates on the computer tab does the same check even if automatic updates are off. If the PC is offline, it waits for a connection. Portable copies (no Setup) do not auto-update.

Turn this off with Install updates silently from GitHub in the status window.

Using it

Closing the window does not quit; use Exit. A second launch opens the same window.

Pause Stops auto-clicks until you resume. Hold Shift to skip one click without pausing.
Authenticator priority Ordered Select / Ask / Ignore rules. USB is Select by default; pairing a new phone is Ignore; Windows Hello is Ask. Unknown names (password-manager plugins, a paired phone’s own label, …) stay on Ask and stop automatic clicks. Names are learned only after they appear in a real FIDO prompt, never auto-preferred. Open Manage priorities to reorder, add, or restore defaults. Built-in rows cannot be renamed or removed.
PIN: Off No PIN handling.
PIN: Submit by length Type a PIN of the length you use → Turn on. Only the character count is kept. USB-key PIN only.
PIN: Remember PIN this session Turn this on, then type the USB-key PIN once in the normal Windows Security prompt and press Enter. This program remembers the length (not a number you type in the app) and caches the PIN in this process (CryptProtectMemory, never on disk). Later prompts fill automatically. After a restart you type the PIN again; OK is pressed when the length matches. Pick how long (1 / 2 / 5 / 10 minutes, or until lock or Exit). Lock, sleep, hibernate, Pause, Reset, a debugger, or Exit forgets the PIN. A rejected PIN also forgets the remembered length so you can type a different one. Needs exactly one USB key and a trusted Windows Security dialog.
Start when I sign in Starts with Windows.
Install updates silently from GitHub Downloads and applies a newer Setup with no notifications.

--skip-all-non-security-key-options and --autosubmit-pin-length still work as session overrides. Skip-all forces USB Select and treats other known options as Ignore for that process.

If it still highlights Security key but does not click Next, press Enter.

Build from source

Install the .NET SDK 8 or later (or Visual Studio 2022/2026). Clone this repository, not an old upstream tag, if you want the tray UI.

git clone https://github.com/AryaPaw/AuthenticatorChooser.git
cd AuthenticatorChooser
dotnet publish AuthenticatorChooser -c Release --runtime win-x64 --no-self-contained -p:PublishSingleFile=true
dotnet test /p:CollectCoverage=true

Output: AuthenticatorChooser\bin\Release\net8.0-windows\win-x64\publish\AuthenticatorChooser.exe. Installer script: installer\AuthenticatorChooser.iss.

CI (.github/workflows/dotnet.yml) publishes the same non-self-contained build. A GitHub Release with Setup and portable exes is created when you push a v* tag.

Unit tests cover settings migration, PIN cache policy, authenticator priority, title/caption mapping, autostart helpers, and the status window. UI Automation against live Windows Security dialogs is not part of CI.

Related

Creating new passkeys

When you try to create a passkey in your browser, the website may force it to be stored only in the TPM or only on a security key, rather than letting you freely choose between the two destinations. To override the site's mandate and put yourself back in control of where your new passkey will be saved, you can install Create Passkeys Anywhere (requires Tampermonkey or a similar browser extension). It also works on Firefox for Android.

With this script installed, you will by default always be asked whether to save each new passkey on a security key or in the TPM. To change that, edit options.allowedPasskeyCreationStorage in the script: securityKey or tpm instead of anywhere.

Stargazers over time

Star History Chart

Original program © Ben Hutchison (Apache-2.0). This repository is an independent fork licensed under AGPL-3.0. Upstream Apache-2.0 text is kept in LICENSES/Apache-2.0.txt. See NOTICE.

About

🗝️ Windows 11 tray utility that automatically selects USB security keys in FIDO2/WebAuthn prompts, with authenticator priorities and optional PIN handling.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages