RDP-FIDO-GATE Phishing-resistant FIDO2 two-factor for Windows Remote Desktop

Zero-trust RDP, gated by a hardware key.

A lightweight gateway that puts hardware FIDO2 two-factor authentication in front of Windows Remote Desktop. Users tap a security key before a session opens — there is no password left to steal.

Security by design

Three guarantees that make a stolen password worthless.

A hardware key, not a password

Opening a session requires a physical FIDO2 / WebAuthn key touch. A stolen or phished password is useless on its own, and no password is ever sent over the wire — the key proves possession, cryptographically.

Enforced by Windows itself

The gate is built entirely on native Windows security mechanisms — the Windows Firewall to open and close the port, the Windows WebAuthn API to check the key, and DPAPI to encrypt stored secrets. There is nothing to trust beyond the operating system.

Default-deny, time-boxed access

RDP port 3389 stays firewall-blocked and invisible to the internet. Only after a registered key proves possession does the gate open a narrow, single-IP hole for about 90 seconds — then it re-blocks the port and re-asserts the block every 30 seconds.

How it works

One key touch opens a single-IP firewall hole for about 90 seconds — then the port closes again.

Port 3389 closed by default
1
RdpFidoClient
Saved session tiles on the user PC
2
FIDO2 key touch
Prove possession of a registered key
3
RdpFidoGate service
Verifies the WebAuthn signature
4
Windows Firewall
Opens access for your IP for about 90 seconds
5
RDP 3389 to mstsc
Session launches with stored credentials
Closed by default Open about 90s for your IP only Re-blocked after about 90s, re-asserted every 30s

Screenshots

The session manager and the gate installer — this is the whole product.

Client — one click on a tile, one touch of the key
Client — one click on a tile, one touch of the key
Gate installer — the one-time key enrollment code
Gate installer — the one-time key enrollment code

Free vs Pro

Start free. Upgrade once for unlimited sessions and no ads.

FeatureFree Pro
Saved sessions10Unlimited
FIDO2 hardware-key gate
Windows Firewall enforcement
Ad tile
Activation14 days for free activation
PriceFree$49 one-time
Buy Pro — $49

After activation you keep using it for free, within the Free plan's limits (up to 10 sessions).

Setup & requirements

No hosting — install the gate on the target PC and the client on yours. Ports: gate 7440/TCP, RDP 3389/TCP.

  1. Host — run RdpFidoGate-Setup.msi as admin. The last page of the installer shows the host address, port 7440 and the one-time key enrollment code.
  2. Port forwarding (for internet access) — if the host is behind a router/NAT, forward 7440/TCP and 3389/TCP to the host's LAN IP. Reserve a static LAN IP; use DDNS if your public IP is dynamic.
  3. Client — install RdpFidoClient, activate by e-mail, add a session (host public IP/DDNS, gate port 7440, the one-time code) and register your FIDO2 key.
  4. Connect — pick the session and touch the key — the gate opens 3389 for your IP for ~90s and mstsc connects.

⚠️ Without forwarding ports 7440 and 3389 on the router, internet access will not work. RDP is closed from outside until you confirm with the key.

Full step-by-step guide →

RDP-FIDO-GATE for remote access in the US and worldwide

Exposed RDP is the most common way ransomware enters small businesses and MSP-managed networks. RDP-FIDO-GATE keeps port 3389 closed and opens it only after a hardware key touch — for one IP, for about 90 seconds.

Meets the MFA requirements of cyber insurers

Insurers, NIST SP 800-63 and CISA guidance ask for phishing-resistant MFA on remote access. A FIDO2 hardware key in front of RDP is exactly that — no SMS codes and no authenticator apps to phish.

Nothing to change on your servers

The gate installs from an MSI on the Windows host and uses the Windows Firewall, the Windows WebAuthn API and DPAPI. Your existing RDP hosts, domain and policies stay as they are.

One-time price in USD

The Free edition covers 10 saved sessions; Pro is $49 one-time with unlimited sessions and no ads — no per-user subscription for a small office or an MSP's tool kit.

Frequently asked questions

Which security keys work?

Any FIDO2 / WebAuthn hardware key that Windows recognises — YubiKey, Feitian, SoloKeys and similar. The key is registered once per session in the client; the gate checks it through the Windows WebAuthn API.

Does it work with Windows Server and cloud VMs?

The gate runs on any Windows host with Remote Desktop enabled — Windows 10/11 or Windows Server, on-premises or in a cloud VM. If the host sits behind a router, forward 7440/TCP and 3389/TCP to it.

Is RDP-FIDO-GATE enough for compliance?

It is a technical control: phishing-resistant MFA plus a default-deny firewall in front of remote access, which is what HIPAA, PCI DSS and cyber-insurance questionnaires ask about. It is not legal advice — validate your specific obligations.

How much does it cost?

Free: FIDO2 gate, firewall enforcement, up to 10 saved sessions, an ad tile, activation within 14 days. Pro: $49 one-time, unlimited sessions, no ads. Regional prices are shown at checkout.

Lock down Remote Desktop today

Download the gate and client for free, or unlock everything with Pro.

$49 one-time · unlimited sessions · no ads