Give Linux USB HID devices the access they need for WebHID, keyboard configurators, firmware tools, and desktop utilities.
Linux applications usually cannot open /dev/hidraw* directly. hidpass scans connected USB HID devices, shows what it found, and creates a focused udev rule for the devices you approve.
It works with USB keyboards, mice, QMK/VIA devices, NuPhy and Keychron keyboards, Stream Decks, macro pads, and other HID hardware. Bluetooth devices are ignored.
Download hidpass-linux-amd64 from the latest release, then install it:
chmod +x hidpass-linux-amd64
sudo install -m 0755 hidpass-linux-amd64 /usr/local/bin/hidpass
hidpass doctorThe release also includes a SHA-256 checksum file.
To build from source:
git clone https://github.com/MixaDoDs/hidpass.git
cd hidpass
make test
sudo make installConnect a USB HID device, then run:
hidpass scan
hidpass auto
hidpass listauto asks before granting access. Keyboards and mice default to No because raw HID access can expose reports for the whole seat, including keystrokes or pointer events. Use --yes only when you understand the implications.
After the rules are applied, reconnect the device if the browser or configuration tool still cannot see it.
| Command | Description |
|---|---|
hidpass scan |
Find and classify connected USB HID devices |
hidpass scan --debug |
Show udev and sysfs diagnostics |
hidpass auto |
Select devices interactively |
hidpass auto --yes |
Allow eligible devices without prompts |
hidpass allow VID:PID |
Explicitly allow one device |
hidpass list |
Show configured devices |
hidpass remove VID:PID |
Remove one device from the configuration |
hidpass apply |
Rebuild the rules and reload udev |
hidpass uninstall |
Remove hidpass rules and saved state |
hidpass doctor |
Check the local hidraw and udev setup |
hidpass version |
Print the installed version |
Example:
hidpass allow 19f5:fee0
hidpass remove 19f5:fee019f5:fee0 is the USB ID used by the NuPhy Air60 HE.
hidpassstarts with the available/dev/hidraw*nodes.- It reads udev properties and resolves the corresponding sysfs device.
- Multiple HID interfaces from one physical USB device are grouped together.
- Bluetooth HID devices behind USB adapters are rejected.
- Approved VID:PID pairs are written to
/etc/udev/rules.d/70-hidpass.rules. - udev rules are reloaded, the relevant devices are triggered, and
udevadm settlewaits for the events to finish.
Security keys and hardware wallets such as YubiKey, FIDO, Ledger, Trezor, and Nitrokey devices are skipped by auto. An explicit allow VID:PID command is still available for unusual hardware.
go test ./...
go vet ./...
make build
./bin/hidpass versionThe test suite covers device discovery, sysfs fallback, HID classification, duplicate interface handling, Bluetooth filtering, state validation, udev rule generation, privilege checks, and transactional installation.
For the detailed Russian documentation, see docs/README.ru.md.
MIT


