New Matter bridge: start smart-home routines from a tap

A tap you can trust that can do anything.

Knura is an open-source platform for NTAG 424 DNA tags. It checks that every tap came from a genuine tag, then runs the action you set up: a webhook, a smart-home routine, your own code.

Public source release coming soon

NTAG 424 DNA tags AES-128 CMAC Standard Webhooks signatures Matter bridge Java 21, self-hostable
Features

Security first, then everything a tap can do

A plain NFC sticker holds a link anyone can copy. Knura tags prove themselves on every tap, so copied, forged and reused links get refused before any action runs.

Cryptographic taps

Each tap the tag encrypts its ID and counter and signs them with an AES key that never leaves the chip (Secure Dynamic Messaging).

Replay protection

Every tap carries a counter that must go up. A link opened twice, from history or a screenshot, is refused. Counters survive restarts.

A key for every tag

Each tag's keys come from one master key and the tag's ID (NXP AN10922). Copying the keys out of one tag doesn't help with any other.

Actions engine

knurgN runs a rule for each verified tag, with retries and a 30 second cutoff so nothing runs late. Nothing in the link can change the action.

Works with your smart home

The Matter bridge shows each tag as a contact sensor in Apple Home, Google Home, Alexa and SmartThings, so a tap can start a routine.

Self-hosted

Runs the same on a home computer or a cloud server. The tap daemon uses only the JDK, with no third-party libraries.

How it works

Every tap is checked before anything happens

  1. The tag signs the tap

    Set up with knurctl, the tag writes a fresh link for every tap: its ID and counter, encrypted, plus a MAC only that tag can make.

  2. knurd verifies it

    The daemon works out that tag's key, checks the signature and refuses any counter it has already seen. Phones get a small "Tap verified" page.

  3. knurgN runs the action

    Only verified, first-time taps reach the actions engine, which looks up the tag's rule and delivers a signed event.

StatusHTTPMeaning
ok200Genuine tag and a new counter. The action runs.
replay409The link was opened before. Nothing runs.
rejected403Bad signature or unknown tag: a forged or edited link.
malformed400Not a tap link at all.
Connectors

Send a tap wherever it needs to go

Every event is signed in the Standard Webhooks format, so whatever receives it can check it really came from your Knura.

Signed webhook

Available

A JSON POST to any address you choose: your own code, Node-RED, a home server.

Matter bridge

Available

Tags as contact sensors in Apple Home, Google Home, Alexa and SmartThings.

MQTT

Planned

Publish taps to your broker.

Home Assistant

Planned

Trigger automations through HA webhooks.

Node-RED

Planned

A ready-made node for tap flows.

ntfy

Planned

Push a notification to your phone.

Run a script

Planned

Start a local command on a tap.

Local log

Planned

Keep a record of every tap.

Self-hosting

Your taps, your server

Set up tags with a USB reader, run the daemon wherever you like, and give phones an HTTPS address to reach it.

  • knurctl sets up tags on a PC/SC reader such as the ACR122U and checks them afterwards.
  • knurd runs on a home computer or a cloud server, with the same config.
  • Tailscale Funnel or any HTTPS reverse proxy lets phones reach it, with no router changes.
  • Secrets stay local, in files Knura refuses to read if other users can, and never in logs.
Early development

Knura is being built in the open

Tag setup, tap verification, signed webhooks and the Matter bridge work today. More connectors are on the way, and the source goes public soon.

Explore the features