Skip to content

Placeholders ​

Templates in [templates] and [[rules]] substitute values from the current touch request. [[rules]] match on the same names.

Grammar ​

text
{path}               value at path
{a|b|"literal"}      first of a, b that has a non-empty value, otherwise the literal
{{ and }}            a literal { and }

Inside a literal, \" and \\ are the only escapes. An unknown name or a syntax error is a configuration error.

Names ​

NamespaceFields
appname, id, icon, exe, pid, cmdline, wm_class, container
processname, exe, pid, cmdline, uid
devicevendor, model, product, vid, pid, kind, transport
requestmethod, op, source, class, confidence, elapsed, count, state, detail

app is the application the request is attributed to, and process the client process. A value that is not known is empty, so give a fallback, as in {app.name|process.name|"An application"}.

Values ​

NameValues
request.methodfido2, u2f, openpgp
request.opsign, decrypt, auth for OpenPGP; empty for FIDO
request.sourcefido; for OpenPGP ssh when an auth operation runs while a client is connected to gpg-agent's ssh socket, else gpg
request.classasserted for FIDO, activity for OpenPGP
request.statewaiting, touched, cancelled, failed, timed_out
request.confidencehigh, medium, low
request.elapsedwhole seconds since the request started
request.countnumber of client attempts merged into this request, starting at 1
request.detailextra text from a reporter, at most 200 characters
device.kindfido, openpgp
device.transportusb, bluetooth, nfc, other
device.vid, device.pidUSB vendor and product id, four lowercase hex digits
device.vendorvendor name, for example Yubico; for an OpenPGP card, its manufacturer

request.confidence is high when the application holds the FIDO device open, medium when it is the newest client of gpg-agent at the time of an OpenPGP request, and low otherwise.

request.detail is empty unless a reporter sent it. touchcue askpass sets it for OpenSSH security keys, for example ED25519-SK SHA256:… → user git; see OpenSSH security keys.

There is no device.serial.