Haudi Crypto, Inc.
Openloop Connect is the companion application for the Openloop hardware wallet. It provides the following five features that let apps and operating systems talk to your Openloop.
| # | Feature | Description | Supported platforms |
|---|---|---|---|
| 1 | Firmware update | Update the Openloop firmware to the latest version over BLE (mobile) or USB (desktop) | Mobile / Desktop |
| 2 | WalletConnect relay | Use your Openloop from any WalletConnect-compatible dApp | Mobile / Desktop |
| 3 | Openloop API server | A local WebSocket server that lets web apps and native apps use your Openloop | Desktop / Android |
| 4 | Safari Web Extension | Container for the extension that lets Safari use your Openloop | iOS |
| 5 | PKCS#11 library | Bundles the PKCS#11 dynamic library used for PIV signing | Desktop |
| Feature | iOS | Android | macOS | Windows | Linux |
|---|---|---|---|---|---|
| Firmware update | ✓ | ✓ | ✓ | ✓ | ✓ |
| WalletConnect relay | ✓ | ✓ | ✓ | ✓ | ✓ |
| Openloop API server | — | ✓ | ✓ | ✓ | ✓ |
| Safari Web Extension | ✓ ※ | — | — | — | — |
| PKCS#11 library | — | — | ✓ | ✓ | ✓ |
※ The Safari Web Extension requires iOS 26.2 or later (see Chapter 10).
| Platform | Connection | Used for |
|---|---|---|
| Mobile (iOS / Android) | BLE (Bluetooth Low Energy) | Wallet features, WalletConnect, firmware updates |
| Desktop (macOS / Windows / Linux) | USB HID | Wallet features, WalletConnect, firmware updates, PIV/PKCS#11, API server |
Openloop supports Air Gap mode, in which crypto-asset transactions are signed without any communication link. Openloop Connect is not used in Air Gap mode — everything happens on the Openloop device itself. See the Openloop User Manual for details.
| Platform | Required version | Notes |
|---|---|---|
| iOS | iOS 15.1 or later | Passkey features require iOS 17 or later; the Safari extension requires iOS 26.2 or later |
| Android | Android 7.0 or later | Passkey features require Android 14 or later |
| macOS | macOS 12 (Monterey) or later | Apple Silicon and Intel both supported |
| Windows | Windows 10 / 11 (64-bit) | — |
| Linux | Debian / Ubuntu family (64-bit) | DEB package |
| OS | Where to get it |
|---|---|
| iOS | Search the App Store for “Openloop Connect” and install |
| Android | Search Google Play for “Openloop Connect” and install |
The app is free.
Go to the Openloop downloads page and download the file for your OS.
The downloads page lists the following files.
| File | OS | Description |
|---|---|---|
| DMG (arm64) | macOS (Apple Silicon) | For Macs with M1/M2/M3/M4 |
| DMG (x64) | macOS (Intel) | For Intel-based Macs |
| Microsoft Store | Windows 10/11 (x64) | MSIX build with automatic updates (recommended) |
| EXE | Windows (x64) | Windows installer |
| DEB | Linux (x64) | Package for Debian/Ubuntu |
/ApplicationsOption 1: Microsoft Store (recommended)
The Microsoft Store build updates itself automatically.
Option 2: Installer (EXE)
sudo dpkg -i openloop-connect-*.debℹ On Linux, connecting the Openloop over USB may require a udev rule. The DEB package includes a script that installs the udev rule for you.
This is the screen you see when you launch the app. It consists of a header bar and three sections.
The top of the screen (a blue bar on mobile) shows:
This section shows information about the connected Openloop device.
When a device is registered:
0x62f54E...57474f); desktop shows
it in fullWhen no device is registered (mobile):
On desktop:
Openloop Connect v0.9.3)This modal appears when you tap the “Change” link.
This section shows the WalletConnect connection status.
When not connected:
When connected:
ℹ You normally do not need to enter a WalletConnect URI by hand. Selecting “Openloop Connect” in a dApp connects automatically via a deep link. See Chapter 5 for details.
ℹ If the dApp disconnects while a signing confirmation is on screen, the confirmation closes automatically (a disconnected dApp can never receive a signature).
This section lists the applications currently connected to the local
WebSocket server (ws://127.0.0.1:21320).
When nothing is connected:
When connected:
▲ On iOS the local WebSocket server does not work, because of OS restrictions. This section will always show as not connected. On iOS, use the Safari Web Extension instead.
You can start device registration from the “+ Add Wallet” button on the main screen, “+ Add new device” in the device selection modal, or “+ Add new device” in the Settings screen.
A BLE scan starts automatically and lists nearby Openloop devices.
||||)If no device is found, the screen shows “No devices found” and prompts you to check that the device is powered on. The “Retry” button restarts the scan.
The “Cancel” button at the top of the screen returns to the previous screen.
Tapping “Connect” on a device shows a connection overlay.
Once pairing finishes, the registration complete screen appears.
Tap “Done” to return to the main screen.
ℹ Registering a device in Openloop Connect also performs the phone’s BLE pairing at the same time. There is no separate step.
The most common problem is stale pairing data left on your phone. After a factory reset of the Openloop, or after unpairing and reconnecting, remnants of the old pairing can remain on the phone side.
How to fix it:
On desktop, you connect the device with a USB cable. There is no registration or pairing step.
▲ Charge-only USB cables will not work. Use a cable that supports data transfer.
WalletConnect is the global standard protocol for connecting wallets to dApps (decentralized applications) and Web3 platforms. With Openloop Connect running, you can use your Openloop from the many dApps that support WalletConnect.
Use any of the following methods to connect a dApp to your Openloop.
This is the easiest approach. You connect directly from a dApp on your phone (in a browser or as an app).
Once connected, the WalletConnect section on the main screen shows “Connected to: [dApp name]”.
ℹ With this method, the dApp’s deep link (
openloop:///wc://) or Universal Link (https://www.crypto.haudi.jp/wc..., WalletConnect Link Mode) handles the WalletConnect URI automatically.
Handy when you want to connect a dApp running on a PC to Openloop Connect on your phone.
A fallback for when the methods above are not available.
Before you approve a connection, an account selection screen appears. For each dApp you can expose one account per currency (chain).
When you are done, tap “Approve”. From then on, signing for that dApp uses the account you selected.
How the selection is remembered:
| Platform | Scope |
|---|---|
| Desktop (USB) | Remembered per device, and preserved across disconnect/reconnect and app restarts. Connecting a different Openloop switches to that device’s own memory (account 0 the first time). |
| Mobile (BLE) | Remembered per device, and kept until you delete that wallet’s registration. Reconnecting to the same dApp preselects your previous account. |
When you perform a transaction in a dApp, the signing request is delivered to Openloop Connect automatically and the signing request screen appears. Signing uses the account you selected when connecting.
Tap the “Disconnect” button in the WalletConnect section of the main screen to end the connection to the dApp.
When a signing request arrives from a dApp, this screen appears as a modal.
bip122:000000000019d6689c085ae165831e93)The message or transaction data to be signed, shown as scrollable monospace text. Hex-encoded data is decoded to UTF-8 text.
On a yellow background: “Only sign messages from sources you trust. Signing a malicious message can result in loss of funds.”
When you tap “Approve”:
Tap or click the ⚙ (gear) icon in the header bar to open it.
The layout differs by platform.
| Platform | Sections |
|---|---|
| Mobile (iOS / Android) | Devices / Local WebSocket Server (Android only) / About |
| Desktop (macOS / Windows / Linux) | Firmware / Local WebSocket Server / PKCS#11 Cryptographic Module |
On mobile, the “Close” button at the top returns you to the main screen; on desktop, use the “×” button at the top right (both are disabled during a firmware update).
The “Devices” section lists your registered Openloop devices. Each row shows:
Tapping “+ Add new device” (mobile only) starts device registration.
Tapping “About” opens the About screen.
Opens when you tap a device in the settings screen.
The recovery firmware restores the device if the main firmware becomes corrupted. A “Recovery Firmware” section appears below the main firmware only when an update is needed. It shows the same items as the main firmware (current version, latest version, update button).
▲ Deleting a device does not remove the Bluetooth pairing from your phone. If you hit pairing problems when re-registering, see “If Pairing Fails” in section 4.1.
On desktop, a “Firmware” section appears at the top of the settings screen. There is no device list or device detail screen as on mobile — you update the firmware of the USB-connected device directly from this section.
While updating:
A progress bar and the text below it change as the update proceeds.
The “Cancel” button aborts the update, though this is not recommended. On success, “Update complete!” appears. On failure, the error details and a “Retry” button are shown.
A “Recovery” section appears below the main firmware only when the recovery firmware has an update available (the main firmware’s heading then becomes “Main”). It shows the current version, the latest version, and an “Update Recovery Firmware” button; the progress display is the same as for the main firmware. On success, “Recovery firmware updated!” appears.
A “Device Log” appears at the end of the section only when log output has been received from the device. It is normally not shown.
On mobile, this opens from the “Update Firmware” button on the device detail screen. The screen changes as the update proceeds. The “Close” button at the top returns you to the previous screen (it is disabled during the update).
When you tap “Update Firmware” on the device detail screen, a confirmation dialog appears first.
Tapping “Start Update” moves to the firmware update screen and the download begins automatically.
A spinner and “Checking version…” appear briefly.
The update runs in three steps:
A progress bar and percentage are shown as each step proceeds. Completed steps turn green. The red warning “Do not power off the device during the update.” is shown throughout. The “Cancel” button aborts the update, though this is not recommended.
A green checkmark and the message “Update complete!” appear. For the main firmware it says “The device will restart automatically.”; for the recovery firmware it says “The device will not restart.” Tap “Done” to return to the previous screen.
A red ✗ icon, the message “Update failed”, and the error details appear. If the update can be retried, a “Retry” button is shown. Tap “Close” to return to the previous screen.
▲ While a firmware update is in progress:
- Do not power off the device
- Do not close the app
- Keep the device close by
The “Local WebSocket Server” section of the settings screen controls whether local apps (dApps in a web browser, native apps, and so on) may connect to your wallet.
| Platform | Shown | Notes |
|---|---|---|
| Desktop | ✓ | Local WS + allowed sites |
| Android | ✓ | Local WS + allowed sites |
| iOS | – | Hidden, because the local WebSocket server cannot work under OS restrictions |
▲ The switch is OFF right after you install the app. Turn it ON before connecting from a local app (a dApp in your browser, a mini wallet, and so on).
ℹ Active sessions are protected: turning the switch OFF does not drop WebSocket sessions that are already established — only new connections are refused. This keeps something like Acrobat from breaking in the middle of signing a PDF.
Shown when the switch is ON.
Operations:
https://example.com) and press “Add”× button on the
rowℹ Origin normalization: when you enter a URL, only the
scheme://host[:port]part is stored. Enteringhttps://example.com/foostoreshttps://example.com. This follows the web security specifications (WebSocket / WebAuthn), in which an origin never includes a path. If you need to distinguish individual pages on the same domain, separate them into different subdomains.
▲ An origin means the whole site: if the same domain also hosts untrusted content (for example pages that users can upload), allowing the origin allows all of it. Take care with sites on shared hosting.
The “PKCS#11 Cryptographic Module” section of the desktop settings screen controls device access through the PKCS#11 library (Firefox TLS client authentication, Adobe Acrobat PDF signing, SSH authentication, and so on).
▲ The switch is OFF right after you install the app. Turn it ON before using PIV from Firefox, Adobe Acrobat, or SSH. If it stays OFF, the device is treated as having no token and your certificates and keys will not appear in the list.
ℹ Active sessions are protected: turning the switch OFF leaves already-open PKCS#11 sessions running. For example, turning it OFF while Adobe Acrobat is signing a PDF does not interrupt that operation — only new
C_Initializecalls are refused.
▲ When a restart is needed: Firefox and Adobe Acrobat cache the state of PKCS#11 modules, so after flipping the switch you may need to restart Firefox or Acrobat before the device list is re-read.
Opens from the ⓘ (info) icon in the header bar, or from “About” in the Settings screen. On mobile, the “Close” button at the top returns you to the previous screen; on desktop, use the “×” button at the top right.
An overview of Openloop Connect.
The basic workflow for Openloop Connect, in five steps:
Tapping each row opens it in your browser. It is shown in Japanese or English according to your device’s language setting.
“© 2026 Haudi Crypto, Inc. / All rights reserved.”
The mobile version of Openloop Connect includes a passkey provider that integrates with your operating system’s Credential Manager. This lets you complete passkey authentication for websites in your iPhone or Android browser by communicating with the Openloop device over BLE.
[Browser (iOS Safari / Android Chrome, etc.)]
↓ navigator.credentials API
[OS Credential Manager]
↓ provider selection (by the user)
[Openloop Connect's credential provider]
↓ BLE
[Openloop device (passkey signing)]
| OS | Implementation | Required OS version |
|---|---|---|
| iOS | ASCredentialProviderViewController (Credential Provider
Extension) |
iOS 17 or later |
| Android | CredentialProviderService (Credential Manager API) |
Android 14 or later |
Openloop passkey authentication has two paths. The Connect Credential Manager feature handles the BLE path only.
| Path | Communication | Connect involved? | Where it is used |
|---|---|---|---|
| USB CTAPHID | The OS’s built-in security key support | No | Desktop (Windows / macOS / Linux) |
| BLE (via Connect) | Implemented by Connect itself | Yes | Mobile (iOS / Android) |
▲ About the name shown in the iOS picker: the iOS WebAuthn picker shows “Openloop Connect”. This is by design in iOS — an extension’s display name is fixed to the containing app’s name (
CFBundleDisplayName). The actual communication is over BLE, not USB. Please do not let the name mislead you.
ℹ On Android the list shows “Openloop via Bluetooth” rather than the app name “Openloop Connect”. The name indicates that this is a passkey provider that works over BLE.
With most relying parties, a single registration works over both USB and BLE. Verified with Monex, Nikko, JAL, Microsoft, SBI VC Trade, and others.
However, some relying parties (Google being the prime example) manage transport hints strictly per credential, so a passkey registered over USB CTAPHID is not visible to Connect’s BLE flow (and vice versa). Only for such relying parties do you need to register the passkey twice with the same Openloop device — once over USB and once over BLE. Openloop issues a distinct credential ID per transport even on the same hardware, so the server records two independent credentials.
| Relying party | USB registration usable over BLE | BLE registration usable over USB | Dual use |
|---|---|---|---|
| Monex / JAL / Microsoft / SBI VC and most others | ✓ | ✓ | One registration covers both |
| ✗ | △ | Register over both USB and BLE |
See Chapter 2 of the Security Key Guide for details.
| Symptom | What to check |
|---|---|
| Openloop does not appear in the picker | Is the provider turned ON in your iOS/Android settings (“Openloop Connect” on iOS, “Openloop via Bluetooth” on Android)? Right after installing Connect, the OS may need to be restarted |
| Nothing happens after choosing it | Is the Openloop within Bluetooth range, is it paired, and is Bluetooth turned on? |
| “No matching credential” error with Google | That Google account only has a passkey registered over USB. Register again for BLE (see §9.7 above) |
| It says “Openloop Connect”, so I assumed it was USB | This is the iOS display-name limitation. The communication is over BLE (see §9.2 above) |
The iOS version of Openloop Connect includes a Safari Web Extension. This extension lets Safari communicate directly with the Openloop device over BLE.
Openloop Connect acts as the container app for the Safari Web Extension. Once the extension is enabled, you can use your Openloop from Safari even when the Connect app is not running.
ℹ On iOS every browser is WebKit-based, which restricts local WebSocket connections. The Safari Web Extension is the alternative that works around this limitation.
▲ The Safari Web Extension requires iOS 26.2 or later. On earlier versions of iOS you can still install Openloop Connect itself, but Openloop Connect will not appear in Safari’s “Extensions” list.
Because of iOS privacy protections, a Safari Web Extension needs two permission steps. Step 1 alone is not enough, so be sure to complete both.
Even after step 1, the extension may still be inaccessible from a website you open in Safari. This is by design in iOS: each site needs explicit permission.
▲ This setting is required per site. You only do it once per site, but you may need to repeat it when you start using a different dApp.
If “Openloop Connect Safari Extension” does not appear in the “Aa” menu, or the extension does not work even after choosing “Always Allow”:
With the Safari Web Extension enabled, visiting a web app that supports the Openloop API lets you communicate with the Openloop device through the extension.
If a button cannot be pressed on your first visit, or the Openloop device is not recognized, complete step 2 “Per-site access permission” in section 10.2.
Openloop Connect includes a local WebSocket server that lets web apps and native apps access the Openloop device. The server starts automatically when Openloop Connect launches.
You can enable or disable the server, and manage which origins may connect, from the “Local WebSocket Server” section of the settings screen.
ws://127.0.0.1:21320
APDU commands are exchanged using the JSON-RPC 2.0 protocol.
| Platform | Supported | Notes |
|---|---|---|
| macOS | ✓ | |
| Windows | ✓ | |
| Linux | ✓ | |
| Android | ✓ | A foreground service keeps the BLE connection alive |
| iOS | ✗ | Not available under OS restrictions (use the Safari Web Extension instead) |
When an application connects to the local WebSocket server, its origin (URL) appears with a green dot in the “Local Apps” section of the main screen. The “Disconnect” button next to each app disconnects it individually.
For the full API reference, see the Openloop Connect Specification.
The desktop version of Openloop Connect bundles a PKCS#11 dynamic library for using the PIV (Personal Identity Verification) feature. It can be used for SSH authentication, TLS client authentication, PDF signing, code signing, and more.
The PKCS#11 library is bundled in the pkcs11/ folder
under the application’s installation path:
| OS | Relative to the app |
|---|---|
| macOS | <app>/Contents/Resources/pkcs11/libopenloop-pkcs11.dylib |
| Windows | <app>/resources/pkcs11/libopenloop-pkcs11.dll |
| Linux | <app>/resources/pkcs11/libopenloop-pkcs11.so |
The installation path <app> depends on how you
installed the app:
| Installation method | Location |
|---|---|
| macOS (DMG) | /Applications/Openloop Connect.app |
| Windows (official installer) | C:\Program Files\Openloop Connect |
| Windows (Microsoft Store) | In PowerShell:
(Get-AppxPackage 7CA75049.OpenloopConnect).InstallLocation |
| Linux (deb) | /opt/Openloop Connect |
For example, the full path for the macOS DMG build is
/Applications/Openloop Connect.app/Contents/Resources/pkcs11/libopenloop-pkcs11.dylib.
The PKCS#11 library talks to the device through Openloop Connect. Before using it, check that:
For detailed usage of the PKCS#11 library, see the Security Key Guide. It covers SSH authentication, Firefox TLS client authentication, key management with pkcs11-tool, setting the PIV PIN, and more.
ws://127.0.0.1:21320Copyright © 2026 Haudi Crypto, Inc. All rights reserved.