HoggorminoandClaude Opus 5 6aa67962b6 NFC scan: describe what the tag data shows, not the vendor
The scan only sees NFC data. It cannot sense whether a label's display
listens for infrared or radio, so the messages now say what was found
instead of naming a vendor or a transport as fact.

- "VUSION tag / SES-imagotag uses radio, not IR" becomes "Likely radio
  tag / Link: nfc.imagotag.com / TagTinker is IR-only".
- Match an http:// or https:// link whose host is nfc.imagotag.com
  (case-insensitive), as prefix code 0x03/0x04 or inline after 0x00,
  instead of the substring "imagotag" anywhere in the URL. A "://"
  inside a path, query or fragment is not taken as the scheme.
- "Not a Pricer tag" becomes "Unrecognized tag / No ID TagTinker can
  decode"; "Unsupported chip" becomes "Unreadable chip / Chip answered
  but no data was read".
- Move the decision into tagtinker_nfc_classify() so it can be tested
  off-device.
- De-duplicate on UID and result together. The firmware reports a read
  that stops partway as a success with fewer pages, so a UID-only check
  could keep a tag stuck on "Unrecognized tag" after a partial first
  read.
- Announce an unreadable chip once until the field is empty. Those reads
  carry no UID, so UID de-duplication never applied and the message
  repeated on every poll.
- Bring the prompt back from the scene tick instead of a popup callback.
  A popup with a callback consumes every short press, so Back only
  dismissed the message and a second Back was needed to leave.
- Stop the scanner on the Back event rather than waiting for on_exit, so
  the poll loop is already winding down when the scene is popped and the
  join there is as short as possible. On device, leaving from a message
  takes exactly one Back.
- Move custom event ids to 200+. NfcScanEventSuccess was 100, the same
  id as the target menu's "+ Type Barcode" item.
- Stop the scan LED when "Target list full" ends scanning.
- README: add "Which tags work", with vendor-documented radio examples
  and a table of what each scan message means.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-16 21:59:32 +02:00
2026-04-06 03:09:39 +02:00
2026-04-06 03:09:39 +02:00
2026-04-24 20:42:36 +02:00

TagTinker V2.1

Infrared ESL Research Toolkit for Flipper Zero
Protocol study • Signal analysis • Digital Art

License: GPL-3.0 Platform: Flipper Zero Image Prep

→ Launch the TagTinker Image Prep web app ←

Demo Image

Overview

TagTinker is a Flipper Zero app for exploring infrared electronic shelf-label (ESL) protocols. It allows you to transmit custom images and text to supported graphics tags. A companion web image preparer runs entirely in the browser and lets you drop, dither and download Flipper-ready BMPs without any install.

As the Flipper Zero team notes:

"FYI: this is pure infrared signal, same that you use in TV remotes. The whole security was relying on obscurity of protocol."

This tool is built for IoT security curiosity, learning about obscure protocols, and displaying digital art on e-ink hardware.

Warning

Hardware Warning: Many infrared ESL tags store their firmware, address, and display data in volatile RAM to save cost and energy. If you remove the battery or let it fully discharge, the tag will lose all programming and become unresponsive ("dead"). It usually cannot be recovered without the original base station.

Which tags work

TagTinker only transmits infrared, through the Flipper's IR LED. It works with infrared ESLs whose type code is in the app's profile table. The type code is digits 13 to 16 of the 17-character barcode, and the image preparer lists the graphics types.

TagTinker has no way to drive ESLs that are updated over radio, whatever their barcode or NFC tag says. For example:

What + Scan NFC tells you

The scan only reads the tag's NFC data. It cannot sense whether the display listens for infrared or radio.

Message What the Flipper found
Tag actions open The NFC link carries an ID TagTinker decodes. Show Tag Info shows the model, or Model: Unknown when the type code is not in the profile table.
Likely radio tag No decodable ID, and the NFC link points to nfc.imagotag.com, the host in the public VUSION label dump. The link alone does not prove the model.
Unrecognized tag The chip was read, but its NFC data holds no ID TagTinker can decode. Everyday NFC cards land here too. For an infrared tag, try + Type Barcode.
Unreadable chip An NFC-A chip answered, but no page could be read. The scan reads only NTAG/Ultralight chips; other chip types give this or "Unrecognized tag", depending on how they answer. If the tag moved during the read, take it away and present it again.
Target list full All 16 target slots are in use. Delete a saved tag first.
Nothing happens No NFC-A chip answered. The tag may have no NFC chip, or one of a type the scan does not look for.

Only test tags you own or are allowed to test.

Features

  • TagTinker Flipper App: High-performance, zero-allocation RLE streaming IR engine.

  • TagTinker Image Prep (web): Single-file, dependency-free HTML page that lists every supported tag profile, runs a full image pipeline (tone, contrast, detail, sharpen, dither, photo-grade Oklab 3-colour quantisation) and exports a Flipper-ready BMP. Hosted at i12bp8.github.io/TagTinker (source: web-image-prep/).

  • Drop-folder image flow: Drop a prepared BMP into apps_data/tagtinker/dropped/ on the Flipper SD card, then open Targeted Payloads → <tag> → Set Image and pick it. The Flipper rescales any BMP on the fly so a single file can target any tag and any page.

  • NFC Tag Scan: Instantly identify ESL targets by scanning their NFC tag — no manual barcode entry needed.

  • WiFi Plugins (optional): Plug a Flipper WiFi Dev Board (ESP32-S2) into the GPIO header to unlock live, network-rendered tag designs — crypto price cards, weather tiles, identicons, and more — auto-discovered by the FAP. New plugins live entirely on the cloud worker; the Flipper firmware never has to be re-flashed to add one. image

  • Display text, custom images, and test-patterns.

  • Support for monochrome and accent-color (red/yellow) graphics tags.

Getting Started

  1. Build the Flipper app from this repository and install it via ufbt. The first launch creates apps_data/tagtinker/dropped/ on your SD card.
  2. Open i12bp8.github.io/TagTinker in any browser, pick your tag profile, drop an image, tweak, and download the BMP.
  3. Copy the BMP into apps_data/tagtinker/dropped/ on the SD card (over qFlipper, USB MTP, or whatever you use).
  4. On the Flipper open Targeted Payloads → <your tag> → Set Image, pick the BMP, choose a page, send.

FAQ

Does this require a Flipper Zero?

No, not at all! You can do this with less than $5 worth of microcontroller hardware (like an ESP32 and an IR LED). The Flipper Zero just happens to be my favorite security research tool, which is why I built the app for this platform.

Where is the .fap release?

The Flipper app is source-first. Build the .fap yourself from this repository with ufbt so it matches your firmware and local toolchain.

What if it crashes or behaves oddly?

If you are using a custom firmware branch, custom asset packs, or a heavily modified device setup, start by testing from a clean baseline firmware.

Credits & Background

This project is deeply indebted to the incredible public reverse-engineering work by furrtek. To understand the underlying protocol, signal structure, and history, please read his research:

NFC tag decoding contributed by 7h30th3r0n3.

Disclaimer

Caution

STRICTLY PROHIBITED FOR ILLEGAL USE

TagTinker is an independent project intended strictly for educational research, security curiosity, and displaying digital art on hardware that you legally own.

Under no circumstances is this software allowed to be used for illegal activities. You are strictly prohibited from using TagTinker to alter retail displays, modify electronic shelf labels in stores, interfere with third-party infrastructure, or cause any form of vandalism or financial harm.

The creator of TagTinker assumes absolutely no liability for any misuse of this software. By using this software, you agree to take full responsibility for your actions and use it responsibly and legally.

License

Licensed under the GNU General Public License v3.0 (GPL-3.0). See the LICENSE file for details.

S
Description
No description provided
Readme GPL-3.0
16 MiB
Languages
C 73.3%
TypeScript 15.8%
HTML 8.8%
Makefile 1.9%
CMake 0.2%