SLI Writer
April 25, 2026 ยท View on GitHub
I made a simple Flipper app to write magic ISO15693 tags with changeable UID using .nfc files.
I also developed an Android version of the app, available as an .apk.
Sadly it is impossible to read a tag in privacy mode due to Android limitations.
๐ท๏ธ Supported Tags
SLIX2 / ISO15693 (Magic UID)
rfidfriend.com in normal mode or AliExpress โ PiSwords in special mode.
These are weird tags that need to be configured back to their original UID to unlock data write.
The old rectangulars tags were working fine with the normal mode - always try it first.
Save the original UID (usually the same if you order several tags from the same batch) and use Write Special.
โ ๏ธ Back up the original UID โ if you lose it, you will never be able to rewrite the tags.
SLIX-L Tags
rfidfriend.com in normal mode.
โ๏ธ Write Sequence
Normal mode
1. Write data blocks
- Command:
WRITE_SINGLE_BLOCK - Mode: non-addressed
- Flags:
0x02
2. Write UID (Gen2 vendor commands)
02 E0 09 40 <uid_high> โ sets bytes 0โ3
02 E0 09 41 <uid_low> โ sets bytes 4โ7
Equivalent to:
proxmark hf 15 csetuid -u <uid> --v2
Special mode (TAG-it TI2048 / AliExpress batch)
These tags require the original factory UID to be present before data blocks can be written.
Step 1 โ Restore factory UID (skipped automatically if card already has it)
02 E0 09 40 <factory_uid_high>
02 E0 09 41 <factory_uid_low>
Step 2 โ Write data blocks (addressed + option flag)
- Command:
WRITE_SINGLE_BLOCK - Mode: addressed
- Flags:
0x62(high data rate0x02+ addressed0x20+ option0x40) - Frame format:
62 21 <UID[8] LSB-first> <block_num> <data[4]>
Example for UID E0 07 81 2B 4F 10 4B 15, block 0, data 11 11 11 11:
62 21 15 4B 10 4F 2B 81 07 E0 00 11 11 11 11
Note: With Option flag (
0x62), NXP cards use a 2-phase response. The Flipper will log timeouts after each block write โ this is normal and does not indicate a failure.
Step 3 โ Write target UID
02 E0 09 40 <target_uid_high>
02 E0 09 41 <target_uid_low>
โ ๏ธ Important
The Gen2 layout command (0x47) is intentionally NOT sent.
- Not required for most readers
- Will brick SLIX-L magic cards
๐จ Build from source
# Install ufbt
pip3 install ufbt
# Pull Unleashed SDK
ufbt update --index-url=https://up.unleashedflip.com/directory.json
# Build
cd sli_writer
ufbt build
# Copy .fap to your Flipper SD card
cp /home/$USER/.ufbt/build/sli_writer.fap /path/to/SD/apps/NFC/
๐ ๏ธ Debugging
If writing fails:
- Connect your Flipper via USB
- Open a serial console (Putty, screen, etc.)
- Set baud rate to
230400
Enable debug logs:
> log debug
Then look for [SLI_Writer] lines.
Key debug messages
iso_send_raw: err=0 rxbytes=2 resp=[XX YY]
Command received โ card returned an error. YY = ISO15693 error code.
iso_send_raw: err=6 rxbytes=0
No response โ likely timeout or CRC issue.
block N: err=6 rxbytes=0
Normal behavior with Option flag (0x62) โ not an error.
Write block N failed
Block write failed after all retries.