Secure remote-desktop gateway

RDP-FIDO-GATE

Zero-trust RDP, gated by a hardware key.

A lightweight gateway that puts hardware FIDO2 two-factor authentication in front of Windows Remote Desktop. Users tap a security key before a session opens — there is no password left to steal.

Security by design

Three guarantees that make a stolen password worthless.

A hardware key, not a password

Opening a session requires a physical FIDO2 / WebAuthn key touch. A stolen or phished password is useless on its own, and no password is ever sent over the wire — the key proves possession, cryptographically.

Enforced by Windows itself

The gate is built entirely on native Windows security mechanisms — the Windows Firewall to open and close the port, the Windows WebAuthn API to check the key, and DPAPI to encrypt stored secrets. There is nothing to trust beyond the operating system.

Default-deny, time-boxed access

RDP port 3389 stays firewall-blocked and invisible to the internet. Only after a registered key proves possession does the gate open a narrow, single-IP hole for about 90 seconds — then it re-blocks the port and re-asserts the block every 30 seconds.

How it works

One key touch opens a single-IP firewall hole for about 90 seconds — then the port closes again.

Port 3389 closed by default
1
RdpFidoClient
Saved session tiles on the user PC
2
FIDO2 key touch
Prove possession of a registered key
3
RdpFidoGate service
Verifies the WebAuthn signature
4
Windows Firewall
Opens access for your IP for about 90 seconds
5
RDP 3389 to mstsc
Session launches with stored credentials
Closed by default Open about 90s for your IP only Re-blocked after about 90s, re-asserted every 30s

Free vs Pro

Start free. Upgrade once for unlimited sessions and no ads.

FeatureFree Pro
Saved sessions10Unlimited
FIDO2 hardware-key gate
Windows Firewall enforcement
Ad tile
Activation14 days for free activation
PriceFree$49 one-time
Buy Pro — $49

After activation you keep using it for free, within the Free plan's limits (up to 10 sessions).

Setup & requirements

No hosting — install the gate on the target PC and the client on yours. Ports: gate 7440/TCP, RDP 3389/TCP.

  1. Host — unpack RdpFidoGate-Host.zip and run Install-Gate.ps1 as admin. Note the host address, port 7440 and the one-time code.
  2. Port forwarding (for internet access) — if the host is behind a router/NAT, forward 7440/TCP and 3389/TCP to the host's LAN IP. Reserve a static LAN IP; use DDNS if your public IP is dynamic.
  3. Client — install RdpFidoClient, activate by e-mail, add a session (host public IP/DDNS, gate port 7440, the one-time code) and register your FIDO2 key.
  4. Connect — pick the session and touch the key — the gate opens 3389 for your IP for ~90s and mstsc connects.

⚠️ Without forwarding ports 7440 and 3389 on the router, internet access will not work. RDP is closed from outside until you confirm with the key.

Full step-by-step guide →

Lock down Remote Desktop today

Download the gate and client for free, or unlock everything with Pro.

$49 one-time · unlimited sessions · no ads