RFIDIOt
RFID IO tools — an open-source Python toolkit for exploring RFID & NFC
RFIDIOt is a Python library and a set of command-line tools for reading, writing, emulating and investigating RFID and NFC devices — MIFARE and ISO 14443/15693 cards, 125 kHz LF tags, ICAO 9303 ePassports, and contact / contactless EMV payment cards. It has been going, in one form or another, since 2006.
A potted history
When RFIDIOt started, RFID was still exotic. The readers were expensive serial boxes, the cards turned up in places people hadn't thought about yet — transit passes, hotel keys, the first biometric passports — and there was almost no free tooling to look at any of it. So RFIDIOt began as a way to drive those early ACG and Frosch serial readers from Python and actually see what the tags were doing.
Over the years it grew to cover a lot of ground: MIFARE Classic and Ultralight
key handling and cloning; ISO 14443 A/B and 15693; 125 kHz LF tags and Hitag;
full ICAO 9303 ePassport reading with BAC, PACE and secure messaging, and Passive
Authentication against a CSCA master list; EMV "Chip And Pin" reading with
ChAP.py, decoding the card's data and recovering and verifying the
offline SDA/DDA/CDA certificate chain; and PN532 card emulation and man-in-the-middle
relaying. Along the way it picked up support for PC/SC readers, libnfc PN53x devices,
Android, and most recently the Chameleon family.
October 2026: the move to Python 3
RFIDIOt is now a Python 3 toolkit. The master branch is
the Python 3 code; the original Python 2.7 toolkit is preserved on the
python2.7 branch (tag v1.0-python2.7), and the first Python 3
release is tagged v1.0-python3. Huge thanks to Pete Shipley (evilpete),
who did the bulk of the port.
What RFIDIOt is for now
The reason RFIDIOt existed in the first place has quietly changed. Twenty years ago the job was to provide tooling at all, for a technology that was new and under-explored. That job is largely done: RFID and NFC are now everywhere, and so are readers, libraries and apps for them.
So RFIDIOt's role has shifted. Rather than being the tool of last resort for a bare tag, it increasingly works as a smooth, uniform control surface over a lot of disparate hardware and tooling. The same small API and the same command-line scripts drive an old ACG serial reader, a PC/SC contactless slot, a libnfc PN53x stick, an ACR122U, an Android phone, a Frosch Hitag reader or a Chameleon — and present one consistent way to select a card, exchange APDUs, and run the higher-level passport and EMV logic on top. The value is less in any single reader and more in tying the whole messy ecosystem together behind one clean interface.
Getting it
Everything lives on GitHub:
github.com/AdamLaurie/RFIDIOt.
Run it with python3; see the documentation
for the individual tools. The full original website, including the tag gallery and the
historical release notes going back to 2006, is kept in the
archive.