Skip to main content

Flint — Windows-native Bootable USB & Disk Image Writer

Write ISO/DD disk images to USB drives on Windows, then verify the result.

Platform Website

Flint is a lightweight, Windows-native utility for writing ISO and DD disk images to USB drives. It writes raw images directly to the physical disk, optionally re-reads the drive afterwards to confirm the write, and requires explicit typed confirmation before any destructive action.

Flint flashing an ISO to a USB drive

The full manual — user guide, CLI reference, troubleshooting and FAQ — lives on the Flint website.

Features

  • Drag & drop or browse for an image — a SHA-256 hash is computed for verification
  • Drive picker with model, size and serial for each detected USB drive
  • Optional post-write verification (SHA-256 compare with mismatch offsets)
  • Bad-block scan that retries unreadable sectors and reports their locations
  • Expert mode: partition scheme, target system, filesystem and write mode
  • Persistence for Linux live images and Windows To Go for Windows images
  • Flash history with export/import and per-flash reports
  • Back up a drive to an image file, or clone a drive onto another drive
  • SHA-256 sidecar files (image.iso.sha256) validate the image before flashing
  • Wipe with selectable standards: zero fill, single random pass (NIST), or DoD 5220.22-M (three passes: zeros, ones, random)
  • Headless/scriptable mode (flint flash, verify, wipe, backup, clone, queue, flash-all) for automation and IT imaging workflows

Download

  • Latest release — download flint.exe (portable, no installation required).
  • Windows 10/11, 64-bit.

SmartScreen: the executable is currently unsigned, so Windows may show a "Windows protected your PC" warning. Click More info → Run anyway. Verify the download against the published SHA-256 checksum first:

certutil -hashfile flint.exe SHA256

and compare the result with flint.exe.sha256 on the release page.

Install via pip

Windows users with Python 3.10+ can install Flint from PyPI:

pip install flint-usb

This installs both a GUI and a CLI — no SmartScreen warning, no download verification needed (pip generates the launcher locally):

flint          # open the GUI
flintw         # GUI without console window
flint --help   # CLI usage

The installer pulls in PyQt6, psutil, pywin32 and wmi. On first run Flint prompts for administrator privileges automatically. The native writer extension is compiled into the wheel for full write performance.

Quick start

  1. Pick an image — drag & drop an ISO/IMG onto the drop zone, or click it to browse (Ctrl+O).
  2. Choose a target drive — click the drive card and select from the list (F5 refreshes).
  3. Flash — click "Flash drive". Confirm the target by typing the drive serial or name when prompted.

Flint runs elevated, so it will ask for administrator permission when started. Every write and wipe is irreversible — the typed confirmation is your last guard against wiping the wrong drive.

Verification

  • Verify after write re-reads the drive after writing (streaming SHA-256, live speed and remaining time).
  • Verify using SHA256 compares the read-back digest against the image and reports the offsets of any mismatched regions.
  • Bad-block scan retries failed reads up to the configured number of times (default 3) and reports the 4096-aligned offsets of sectors that never read back; unreadable chunks are skipped so the rest of the image is still checked.
  • On mismatch, Flint offers to retry the write or abort. A cancelled verification is reported as completed-but-unverified — never as a false success.

Expert mode

Expert mode is enabled by default and can be turned off with the toggle on the write page. It adds:

  • Partition scheme (GPT / MBR / Auto), target system (UEFI / Legacy / Auto) and filesystem (FAT32 / NTFS / exFAT).
  • Write mode: raw (DD) or file copy. File-copy mode repartitions and formats the drive, then copies the image contents onto it — it is Windows-only, requires elevation, and is skipped for hybrid ISOs, which are always written raw so their boot record survives.
  • Buffer size for raw writes (4–64 MiB) and an optional native writer using unbuffered disk I/O for maximum throughput.
  • Persistence (Linux) and Windows To Go (Windows) options — see below.
  • Inline ? buttons beside every option open the in-app reference.

Security warning: every option on this panel repartitions or rewrites a physical drive. Wrong combinations can make a drive unbootable or erase it without recovery. Only use these options when you know what your target firmware and bootloader require; back up data first.

Persistence and Windows To Go

  • Persistence keeps changes between reboots on live Linux sticks (Ubuntu casper-rw, Debian live overlay). It requires WSL with an ext4 tool to format the persistence image.
  • Windows To Go applies a Windows installation ISO to the drive so it boots as a portable Windows installation (requires NTFS and elevation).
  • Both features require file-copy mode, are mutually exclusive, and are only shown for supported images.

Safety & limitations

  • 64-bit Windows only.
  • Flint writes raw images directly to disks — this irreversibly erases data. Always confirm the target and back up important data before use.
  • Before a raw write to a FAT32 target, Flint refuses images containing files over 4 GiB (impossible on FAT32) unless you switch to NTFS/exFAT.
  • Flash history is stored locally on your machine.

Back up, clone and wipe

  • Back up (drive picker → "Backup this drive to an image…") streams a USB drive into a .img file, locking the drive's volumes while reading. The backup's SHA-256 is shown in the completion report.
  • Clone (drive picker → "Clone this drive to another…") copies a drive onto a second drive byte-for-byte. The target must be at least as large as the source, must be a different drive, and requires the same typed confirmation as a flash.
  • Wipe methods (the ▾ menu next to "Wipe drive"):
    • Zero fill (fast) — single pass of zeros
    • Random data (NIST) — single pass of random data (NIST SP 800-88 clear)
    • DoD 5220.22-M (3 passes) — zeros, then ones, then random data

Checksum sidecars

If a *.sha256 file sits next to your image (ubuntu.iso.sha256 or ubuntu.sha256), Flint reads it, verifies the image digest against it, and shows the result under the image source. A mismatch blocks flashing — a corrupt or wrong image can never erase a drive by accident.

Headless mode

Every feature is available headless for imaging labs, scripts and CI. flint below is the flint.exe you downloaded. Commands that need it relaunch elevated automatically (one UAC prompt); list, doctor and completions need no privileges at all. The older --cli prefix is still accepted as a compatibility alias:

flint list
flint flash  --image image.iso --drive E: --confirm <serial> [--verify]
flint verify --drive E: [--sha256 <hex> --image image.iso]
flint wipe   --drive E: --confirm <serial> [--method zero|random|nist|dod]
flint backup --drive E: --out backup.img [--confirm <serial>]
flint clone  --from E: --to F: --confirm <serial of --to>
flint queue  --file list.txt --drive E: --confirm <serial>
flint flash-all --image image.iso [--image image2.iso ...] --confirm ARM [--timeout <seconds>]
flint doctor
flint completions | Out-File -Append $PROFILE
flint help [<command>]
  • --drive accepts a serial number, volume letter (E:) or physical path (\\.\PHYSICALDRIVE1); it only selects the drive. --confirm is the safety check: it must match the full serial of the drive being destroyed, validated against the live drive list — a wrong serial can never match another drive. flint list prints every detected drive with the exact serial --confirm expects.
  • flash-all is fleet mode: it writes every --image to every drive that is — or becomes — plugged in, until the time budget expires (default 3600 s). Arming requires the literal word ARM.
  • When --confirm is omitted on an interactive terminal, the serial is prompted for; a piped command without --confirm is refused, never guessed.
  • verify without a digest runs a read-only bad-block scan; with --sha256 it compares only the image's byte range against the drive, so --image is required to know how many bytes to check.
  • The queue file holds one image path per line (# comments allowed); images are flashed to the same drive in order, stopping on the first failure.
  • --json switches all output to NDJSON (progress, results, drive lists); FLINT_PROGRESS=json is equivalent and FLINT_VERIFY=1 makes flash verify by default.
  • Streams are split: data and the final RESULT ok|fail|canceled: … line go to stdout; FLINT <pct> <speed>MB/s ETA <s>s progress and notes go to stderr, so scripts capture stdout as pure data without 2>&1 noise.
  • Exit codes: 0 ok, 1 failure, 2 cancelled, 3 usage/validation, 4 elevation denied.

Signing

The release workflow signs flint.exe automatically when the WINDOWS_SIGNING_PFX (base64 PFX) and WINDOWS_SIGNING_PASSWORD repository secrets are set. To sign locally once you have a certificate:

.\scripts\sign.ps1 -PfxPath .\cert.pfx -PfxPassword 'secret'

Support

License

Metadata

Release files for flint-usb 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flint-usb 1.1.0
File Size Uploaded
flint_usb-1.1.0.tar.gz 148.6 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for flint-usb 1.1.0
File
flint_usb-1.1.0-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
flint_usb-1.1.0-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
flint_usb-1.1.0-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
flint_usb-1.1.0-cp310-cp310-win_amd64.whl CPython 3.10 CPython 3.10 Windows x86-64 Details

Total release size: 653.5 kB

Release files / flint_usb-1.1.0.tar.gz

Download URL flint_usb-1.1.0.tar.gz
Size 148.6 kB
Tags Source
SHA-256 checksum
How to use checksums
f9197a0445cf2cfc0af3a4d59b46d11de7fa2570da058f78cc81db5b95f6b003
BLAKE2b-256 checksum
How to use checksums
b7db91554437b48a5fa2f7583d08a5ddfc3d60717150f47c28aa55e97c11fb5a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / flint_usb-1.1.0-cp313-cp313-win_amd64.whl

Download URL flint_usb-1.1.0-cp313-cp313-win_amd64.whl
Size 126.2 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
17571c8f8410ec1f92db9fe9d9c2a65852cb30b0165d45f09c37ed48eb465fda
BLAKE2b-256 checksum
How to use checksums
c7a582b1d22a62bab4127f93f7656010e64ba03b5986c0e394a6e45a761f0a23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / flint_usb-1.1.0-cp312-cp312-win_amd64.whl

Download URL flint_usb-1.1.0-cp312-cp312-win_amd64.whl
Size 126.2 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
7abd1efba866b4ecfe570ae481ad3e4c7ba5a375dffcc088eca1a365876b6a5c
BLAKE2b-256 checksum
How to use checksums
d31d40bcca9a797ef3af284c19d27b15f65690ee699f7f457508bac1d9d6710e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / flint_usb-1.1.0-cp311-cp311-win_amd64.whl

Download URL flint_usb-1.1.0-cp311-cp311-win_amd64.whl
Size 126.2 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
5058d6ac0a95a798d6795a80c2dec46aadeb2734a35e740f8c58324a5140f67d
BLAKE2b-256 checksum
How to use checksums
7d140ab66a2782e78cd1063d62d444994c6348f1b8d42137166a40f0f61a9d7a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / flint_usb-1.1.0-cp310-cp310-win_amd64.whl

Download URL flint_usb-1.1.0-cp310-cp310-win_amd64.whl
Size 126.2 kB
Tags CPython 3.10 Windows x86-64
SHA-256 checksum
How to use checksums
23a8f3ca7d40d428243e61301e70b0847e24d6553135bc858115b7c142375045
BLAKE2b-256 checksum
How to use checksums
da5d9ebb65866e401a650ec51730ef73f3fc2079e9dd0d2f5b13a2beebee01a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release history Release notifications | RSS feed

2.0.1

1 release file

2.0.0

1 release file

1.9.0

1 release file

1.8.0

1 release file

1.7.0

1 release file

1.5.0

5 release files

1.4.0

5 release files

1.3.0

5 release files

1.2.2

5 release files

1.2.1

5 release files

1.2.0

5 release files

1.1.2

5 release files

This release

1.1.0 This release

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page