msgctl 0.2.7 · YubiKey identities
Built-in YubiKey PIV Ed25519 identity signer, with on-device generation, refusal to overwrite occupied slots, non-exportable identity keys, public local stubs, signed on-card account directories, and clean-configuration login recovery.
Physical case: MSG account light created using a YubiKey 5C NFC (5.8.0) on Linux; restored the same account in a fresh config directory; an 8-second Agent token allowed the specified profile read, rejected out-of-scope reads/writes, and expired. See docs/YUBIKEY_CASE.md. A second physical computer and Windows/macOS are not yet acceptance-tested.
Requires PIV firmware 5.7+ and PC/SC; the SDK ships by default. Linux source builds need libpcsclite development headers and SWIG. Existing age decryption keys remain separate. Hardware frames are limited to 2800 bytes; unattended signed Agent writes are not a new feature in this release.
Validation: 101 focused tests, Ruff, artifact consistency and an isolated client-only install passed. PyPI digests verified. Full GitHub CI has separate status. Source: 6dc67e5; native Arch build: 0.2.7-20261002.19.