tech from europe

Tillitis TKey

🇸🇪 SE

Open-source RISC-V USB security key for SSH, FIDO2 and digital signing

Open sourceCEFCC
Tillitis TKey is a Swedish open-source hardware security key built on a RISC-V FPGA platform. It runs stateless applications in RAM, supports SSH, Ed25519 signing and FIDO2, and uses touch confirmation for user presence. All firmware, software and hardware designs are open source.

Features

Security Architecture & Isolation

  • Measured Boot with BLAKE2s-256 hash digest for application integrity
  • Deterministic key derivation using Unique Device Secret (UDS) and optional user-supplied secrets (USS)
  • Stateless, isolated execution of applications in memory without permanent on-device storage

Hardware & Form Factor

  • USB-C stick form factor with injection-molded plastic case (PA12-Grilamid TR 90)
  • FPGA-based architecture (locked end-user or unlocked developer version)
  • Physical user presence detection via touch sensor and RGB status LED

Cryptographic & Device Applications

  • SSH agent support (tkey-ssh-agent)
  • U2F/FIDO protocol support for authentication
  • TOTP generation for time-based one-time passwords
  • Ed25519 signing for files and messages (tkey-sign)
  • Device verification (tkey-device-verification) for supply-chain authenticity
  • Hardware-backed True Random Number Generator (TRNG) with signable output

Developer & Extensibility Tools

  • Open framing protocols for host-to-device client applications
  • Open-source SDKs and client libraries (e.g., Go tkeyclient module)
  • TKey Unlocked platform with TKey Programmer Board for custom FPGA bitstreams and firmware development

Pricing

TKey (End-user locked version)
880 SEK one-time purchase, taxes included
  • Physical hardware token
  • Open-source software and tools
  • No recurring fees
TKey Unlocked (User-programmable PCB assembly)
880 SEK one-time purchase, taxes included
  • User-programmable FPGA
  • Custom firmware development
  • Open-source hardware
TKey Programmer Board
500 SEK one-time purchase, taxes included
  • Programming accessory for TKey Unlocked
  • Enables custom FPGA bitstream flashing
  • Non-volatile configuration memory (NVCM) support

Enterprise orders or invoice requests require direct contact with Tillitis sales.

EU Trust Profile

What we verified against public sources, last checked 2026-09-13. Every point links to its evidence.

  • Open source

    All software, firmware, FPGA Verilog source code, and hardware design files are public.

    Evidence

We list only what we could verify against a public source on the check date. A point that is absent was not established either way — it is not a finding against the vendor. The vendor's own information prevails.

Work at Tillitis TKey?

This badge is free for every vendor we list and has no bearing on the order of any list. It is issued on the basis of a verified European headquarters (SE) and the compliance points we checked against public sources — the date on it is the date we last checked.

Tillitis TKey — verified European company on tech-from-europe.euTillitis TKey — verified European company on tech-from-europe.eu

Embed code

<a href="https://tech-from-europe.eu/product/tillitis-tkey"><img src="https://tech-from-europe.eu/badge/tillitis-tkey.svg" alt="Tillitis TKey — verified European company on tech-from-europe.eu" height="164"></a>

Plain HTML: an SVG served from our domain, with no JavaScript, no cookies and no tracking of your visitors. Add ?style=card for the wide variant, or swap .svg for .png where a CMS refuses SVG. Whether you nofollow the link is your call — we do not check.

Claiming the profile with a work email gets you the artwork as PNG, a form for correcting anything we got wrong, and a note whenever we re-check you.

Claim this profile →

Something wrong on this page? Write to hello@tech-from-europe.eu with a public link and we will re-check it.

Reviews

Recurring themes, synthesized from public reviews across portals.

What users value

  • End-to-end open-source design (Verilog FPGA code, PCB schematics, firmware, and software tools)
  • Stateless measured boot with DICE-like implementation and no persistent private key storage
  • Dynamic key derivation from Unique Device Secret (UDS), User Supplied Secret (USS), and binary hash
  • Flexibility to write custom C/Go applications (SSH authentication, code signing, Sigsum logging, TRNG entropy)
  • Hardware transparency and auditability for security researchers

Where users see room to improve

  • · No out-of-the-box FIDO2/passkey or native browser support
  • · Steep learning curve: CLI tooling, manual configuration, and custom compilation required
  • · Hardware constraints (18 MHz PicoRV32 core, 128 KiB RAM) limit application complexity

Integrations

GitHubGitLabBitbucketOpenSSHFIDO/U2FTOTPEd25519LinuxmacOSWindowstillitis-ethereum

Feature, pricing and integration details are based on web research (as of 2026-09-13), without guarantee, errors are possible. The vendor's website prevails.