Skip to main content

Python library for communicating with Trezor Hardware Wallet

Project description


repology image

Python library and command-line client for communicating with Trezor Hardware Wallet.

See for more information.


Python Trezor tools require Python 3.6 or higher, and libusb 1.0. The easiest way to install it is with pip. The rest of this guide assumes you have a working pip; if not, you can refer to this guide.

On a typical system, you already have all you need. Install trezor with:

pip3 install trezor

On Windows, you also need to either install Trezor Bridge, or libusb and the appropriate drivers.

Firmware version requirements

Current trezorlib version supports Trezor One version 1.8.0 and up, and Trezor T version 2.1.0 and up.

For firmware versions below 1.8.0 and 2.1.0 respectively, the only supported operation is "upgrade firmware".

Trezor One with firmware older than 1.7.0 and bootloader older than 1.6.0 (including pre-2021 fresh-out-of-the-box units) will not be recognized, unless you install HIDAPI support (see below).

Installation options

  • Ethereum: To support Ethereum signing from command line, additional packages are needed. Install with:

    pip3 install trezor[ethereum]
  • Stellar: To support Stellar signing from command line, additional packages are needed. Install with:

    pip3 install trezor[stellar]
  • Firmware-less Trezor One: If you are setting up a brand new Trezor One manufactured before 2021 (with pre-installed bootloader older than 1.6.0), you will need HIDAPI support. On Linux, you will need the following packages (or their equivalents) as prerequisites: python3-dev, cython3, libusb-1.0-0-dev, libudev-dev.

    Install with:

    pip3 install trezor[hidapi]

To install all three, use pip3 install trezor[hidapi,ethereum,stellar].

Distro packages

Check out Repology to see if your operating system has an up-to-date python-trezor package.

Installing latest version from GitHub

pip3 install "git+"

Running from source

Install the Poetry tool, checkout trezor-firmware from git, and enter the poetry shell:

pip3 install poetry
git clone
cd trezor-firmware
poetry install
poetry shell

In this environment, trezorlib and the trezorctl tool is running from the live sources, so your changes are immediately effective.

Command line client (trezorctl)

The included trezorctl python script can perform various tasks such as changing setting in the Trezor, signing transactions, retrieving account info and addresses. See the docs/ sub folder for detailed examples and options.

NOTE: An older version of the trezorctl command is available for Debian Stretch (and comes pre-installed on Tails OS).

Python Library

You can use this python library to interact with a Trezor and use its capabilities in your application. See examples here in the tools/ sub folder.

PIN Entering

When you are asked for PIN, you have to enter scrambled PIN. Follow the numbers shown on Trezor display and enter the their positions using the numeric keyboard mapping:

7 8 9
4 5 6
1 2 3

Example: your PIN is 1234 and Trezor is displaying the following:

2 8 3
5 4 6
7 9 1

You have to enter: 3795


If you want to change protobuf or coin definitions, you will need to regenerate definitions in the python/ subdirectory.

First, make sure your submodules are up-to-date with:

git submodule update --init --recursive

Then, rebuild the protobuf messages by running, from the trezor-firmware top-level directory:

make gen

To get support for BTC-like coins, these steps are enough and no further changes to the library are necessary.


All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

0.13.3 (2022-07-13)


  • Support for Cardano Babbage era transaction items #2354


  • Fix Click 7.x compatibility. #2364

0.13.2 (2022-06-30)


  • Fixed dependency error when running trezorctl without PIL.
  • Fixed dependency error when running trezorctl on Python 3.6 without rlp.
  • Fix trezorctl --version crash. #1702

0.13.1 (2022-06-29)


  • New exception type DeviceIsBusy indicates that the device is in use by another process. #1026
  • Support payment requests and GetNonce command. #1430
  • Add press_info() to DebugLink. #1430
  • Add support for blind EIP-712 signing for Trezor One #1970
  • Add ScriptUI for trezorctl, spawned by --script option #2023
  • Support T1 screenshot saving in Debuglink #2093
  • Support generating Electrum-compatible message signatures in CLI. #2100
  • Support Cardano Alonzo-era transaction items and --include-network-id flag #2114
  • trezorctl: Bitcoin commands can detect script type from derivation path. #2159
  • Add support for model R #2230
  • Add firmware get-hash command. #2239
  • Jump and stay in bootloader from firmware through SVC call reverse trampoline. #2284


  • Unify boolean arguments/options in trezorlib commands to on/off #2123
  • Rename normalize_nfc to prepare_message_bytes in #2126
  • trezorctl monero network type arguments now accept symbolic names instead of numbers. #2219


  • trezorctl will correctly report that device is in use. #1026
  • Allow passing empty message_hash for domain-only EIP-712 hashes for Trezor T1 (i.e. when primaryType=EIP712Domain) #2036
  • Fixed error when printing protobuf message with a missing required field. #2135
  • Add compatibility with Click 8.1 #2199

0.13.0 - 2021-12-09


  • trezorctl firmware update shows progress bar (Model T only)
  • Enabled session management via EndSession #1227
  • Added parameters to enable Cardano derivation when calling init_device(). #1231
  • two new trezorctl commands - trezorctl firmware download and trezorctl firmware verify #1258
  • Support no_script_type option in SignMessage. #1586
  • Support for Ethereum EIP1559 transactions #1604
  • Debuglink can automatically scroll through paginated views. #1671
  • Support for Taproot descriptors #1710
  • trezorlib.stellar.from_envelope was added, it includes support for the Stellar TransactionV1 format transaction. #1745
  • Ethereum: support 64-bit chain IDs #1771
  • Support for Cardano multi-sig transactions, token minting, script addresses, multi-sig keys, minting keys and native script verification #1772
  • Added parameters to specify kind of Cardano derivation to all functions and trezorctl commands. #1783
  • Support for EIP-712 in library and trezorctl ethereum sign-typed-data #1835
  • Add script_pubkey field to TxInput message. #1857
  • Full type hinting checkable with pyright #1893


  • protobuf is aware of required fields and default values #379
  • trezorctl firmware-update command changed to trezorctl firmware update #1258
  • btc.sign_tx() accepts keyword arguments for transaction metadata #1266
  • Raise ValueError when the txid for an input is not present in prev_txes during btc.sign_tx #1442
  • trezorlib.mappings was refactored for easier customization #1449
  • Refactor protobuf codec for better clarity #1541
  • UdpTransport.wait_until_ready no longer sets socket to nonblocking #1668
  • Cardano transaction parameters are now streamed into the device one by one instead of being sent as one large object #1683
  • trezorlib.stellar will refuse to process transactions containing MuxedAccount #1838
  • Use unified descriptors format. #1885
  • Introduce Trezor models as an abstraction over USB IDs, vendor strings, and possibly protobuf mappings. #1967


  • instantiating protobuf objects with positional arguments is deprecated #379
  • details argument to btc.sign_tx() is deprecated. Use keyword arguments instead. #379
  • values of required fields must be supplied at instantiation time. Omitting them is deprecated. #379


  • dropped Python 3.5 support #810
  • dropped debug-only trezorctl debug show-text functionality #1531
  • Removed support for Lisk #1765


  • fix operator precedence issue for ethereum sign-tx command #1867
  • Updated tools/ to work with Blockbook's API protections. #1896
  • Fix PIN and passphrase entry in certain terminals on Windows #1959

Incompatible changes

  • client.init_device(derive_cardano=True) must be used before calling Cardano functions. #1231
  • The type of argument to ui.button_request(x) is changed from int to ButtonRequest. The original int value can be accessed as x.code #1671
  • Due to transaction streaming in Cardano, it isn't possible to return the whole serialized transaction anymore. Instead the transaction hash, transaction witnesses and auxiliary data supplement are returned and the serialized transaction needs to be assembled by the client. #1683
  • trezorlib.stellar was reworked to use stellar-sdk instead of providing local implementations #1745
  • Cardano derivation now defaults to Icarus method. This will result in different keys for users with 24-word seed. #1783

0.12.4 - 2021-09-07


  • trezorctl: fixed "Invalid value for <param>" when using Click 8 and param is not specified #1798

0.12.3 - 2021-07-29


  • trezorctl btc get-descriptor support #1363
  • trezorctl btc reboot-to-bootloader support #1738
  • distinguishing between temporary and permanent safety checks
  • trezorctl accepts PIN entered by letters (useful on laptops)
  • support for 50-digit PIN for T1


  • allowed Click 8.x as a requirement
  • replaced all references to Trezor Wallet with Trezor Suite, and modified all mentions of Beta Wallet


  • added missing requirement attrs
  • properly parse big numbers in tools/ #1257, #1296
  • it is now possible to set safety checks for T1

0.12.2 - 2020-08-27


  • trezorlib.toif module (moved from internal) can encode and decode TOIF image format
  • trezorctl set homescreen was improved and extended to support PNG images for Trezor T


  • trezorctl will correctly notify the user if the image decoding library is missing


  • fix exception in trezorctl btc get-address #1179
  • fix exception in trezorctl lisk sign-message
  • fix exception in trezorctl commands that accept filenames #1196
  • fix "Invalid homescreen" error when un-setting homescreen


  • removed option --skip-vendor-header from trezorctl firmware-update which did nothing #1210

0.12.1 - 2020-08-05


  • trezorctl set safety-checks controls the new "safety checks" feature. #1126
  • trezorctl btc get-address can create multisig addresses.
  • the following commands are now equivalent in trezorctl: firmware-update, firmware-upgrade, update-firmware, upgrade-firmware
  • support for EXTERNAL input type #38, #1052
  • support for ownership proofs
  • support for pre-authorized CoinJoin transactions #37
  • support for Cardano Shelley #948


  • do not allow setting auto-lock delay unless PIN is configured


  • correctly calculate hashes for very small firmwares f#1082
  • unified file arguments in trezorctl
  • does not crash when device is PIN-locked

0.12.0 - 2020-04-01

Incompatible changes

  • trezorlib.coins, trezorlib.tx_api, and the file coins.json, were removed
  • TrezorClient argument ui is now mandatory. state argument was renamed to session_id.
  • UI callback get_passphrase() has a new argument available_on_device.
  • API for cosi module was changed
  • other changes may also introduce incompatibilities, please review the full list below


  • support for firmwares 1.9.0 and 2.3.0
  • Model T now defaults to entering passphrase on device. New trezorctl option -P enforces entering passphrase on host.
  • support for "passphrase always on device" mode on model T
  • new trezorctl command get-session and option -s allows entering passphrase once for multiple subsequent trezorctl operations
  • built-in functionality of UdpTransport to wait until an emulator comes up, and the related command trezorctl wait-for-emulator
  • trezorctl debug send-bytes can send raw messages to the device f#116
  • when updating firmware, user is warned that the requested version does not match their device f#823
  • trezorctl list can now show name, model and id of device


  • trezorlib.tx_api.json_to_tx was reduced to only support Bitcoin fields, and moved to trezorlib.btc.from_json.
  • API for cosi module was streamlined: verify_m_of_n is now verify, the old verify is verify_combined
  • internals of firmware parsing were reworked to support signing firmware headers
  • get_default_client respects TREZOR_PATH environment variable
  • UI callback get_passphrase has an additional argument available_on_device, indicating that the connected Trezor is capable of on-device entry
  • Transport.write and read method signatures changed to accept bytes instead of protobuf messages
  • trezorctl subcommands have a common @with_client decorator that manages exception handling and connecting to device


  • trezorctl does not print empty line when there is no output
  • trezorctl cleanly reports wire exceptions f#226


  • trezorlib.tx_api was removed
  • trezorlib.coins and coin data was removed
  • trezorlib.ckd_public, which was deprecated in 0.10, was now removed.
  • btc.sign_tx will not preload transaction data from prev_txes, as usage with TxApi is being removed
  • PIN protection and passphrase protection for ping() command was removed
  • compatibility no-op code from trezorlib 0.9 was removed from trezorlib.client
  • was dropped, use trezorlib.exceptions.TrezorFailure instead

0.11.6 - 2019-12-30


  • support for get-and-increase FIDO counter operation
  • support for setting wipe code
  • trezorctl device recover supports --u2f-counter option to set the FIDO counter to a custom value


  • trezorctl command was reworked for ease of use and maintenance. See trezorctl --help and OPTIONS.rst for details. f#510
  • updated EOS transaction parser to match cleos in delegatebw and undelegatebw actions f#680 f#681
  • RecoveryDevice does not set fields when doing dry-run recovery f#666


  • fixed "expand words" functionality in trezorctl device recover f#778


  • trezorctl no longer interactively signs Bitcoin-like transactions, the only allowed input format is JSON. See docs/ for details.
  • support for "load device by xprv" was removed from firmware and trezorlib

0.11.5 - 2019-09-26


  • trezorctl can dump raw protobuf bytes in debug output f#117
  • trezorctl shows a warning when activating Shamir Backup if the device does not support it f#445
  • warnings are emitted when encountering unknown value for a protobuf enum f#363
  • debug messages show enum value names instead of raw numbers
  • support for packed repeated encoding in the protobuf decoder
  • in trezorctl firmware-update, the new --beta switch enables downloading beta firmwares. By default, only stable firmware is used. f#411, f#420
  • in trezorctl firmware-update, the new --bitcoin-only switch enables downloading Bitcoin-only firmware
  • support for FIDO2 resident credential management
  • support for SD-protect features


  • package directory structure was changed: src subdirectory contains sources and tests subdirectory contains tests, so that cwd is not cluttered
  • trezorctl script was moved into a module trezorlib.cli.trezorctl and is launched through the entry_points mechanism. This makes it usable on Windows
  • pyblake2 is no longer required on Python 3.6 and up
  • input flows can only be used in with-block (only relevant for unit tests)
  • if not specified, trezorctl will set label to "SLIP-0014" in SLIP-0014 mode
  • in clear_session the client also forgets the passphrase state for TT f#525


  • trezorctl will properly check if a firmware is present on a new T1 f#224


  • device test suite was moved out of trezor package

0.11.4 - 2019-07-31


  • trezorctl support for SLIP-39 Shamir Backup
  • support for Binance Chain

0.11.3 - 2019-05-29


  • trezorctl can now send ERC20 tokens
  • trezorctl usb-reset will perform USB reset on devices in inconsistent state
  • set-display-rotation command added for TT firmware 2.1.1
  • EOS support f#87
  • Tezos: add voting support f#41
  • dict_to_proto now allows enum values as strings


  • Minimum firmware versions bumped to 1.8.0 and 2.1.0
  • Cleaner errors when UI object is not supplied
  • Generated files are now part of the source tarball again. That means that protoc is no longer required.


  • Ethereum commands in trezorctl now work
  • Memory debugging tools now work again


  • Tron and Ontology support removed until implementations exist in Trezor firmware

0.11.2 - 2019-02-27


  • full support for bootloader 1.8.0 and relevant firmware upgrade functionality
  • trezorctl: support fully offline signing JSON-encoded transaction data
  • trezorctl: dry-run for firmware upgrade command
  • client: new convenience function get_default_client for simple script usage
  • Dash: support DIP-2 special inputs #351
  • Ethereum: add get_public_key methods


  • coins with BIP-143 fork id (BCH, BTG) won't require prev_tx #352
  • device recovery will restore U2F counter
  • Cardano: change network to protocol_magic
  • tests can run interactively when INTERACT=1 environment variable is set
  • protobuf: improved to_dict function


  • trezorctl: interactive signing with sign-tx is considered deprecated

0.11.1 - 2018-12-28


  • crash when entering passphrase on device with Trezor T
  • Qt widgets should only import QtCore #349

0.11.0 - 2018-12-06

Incompatible changes

  • removed support for Python 3.3 and 3.4
  • major refactor of TrezorClient and UI handling. Implementers must now provide a "UI" object instead of overriding callbacks #307, #314
  • protobuf classes now use a get_fields() method instead of FIELDS field #312
  • all methods on TrezorClient class are now in separate modules and take a TrezorClient instance as argument #276
  • mixin classes are also removed, you are not supposed to extend TrezorClient anymore
  • TrezorClientDebugLink was moved to debuglink module
  • changed signature of trezorlib.btc.sign_tx
  • @field decorator was replaced by an argument to @expect


  • trezorlib now has a hardcoded check preventing use of outdated firmware versions #283
  • Ripple support #286
  • Zencash support #287
  • Cardano support #300
  • Ontology support #301
  • Tezos support #302
  • Capricoin support #325
  • limited Monero support (can only get address/watch key, monerowallet is required for signing)
  • support for input flow in tests makes it easier to control complex UI workflows #314
  • protobuf.dict_to_proto can create a protobuf instance from a plain dict
  • support for smarter methods in trezord 2.0.25 and up
  • support for seedless setup
  • trezorctl: firmware handling is greatly improved #304, #308
  • trezorctl: Bitcoin-like signing flow is more user-friendly
  • tx_api now supports Blockbook backend servers


  • better reporting for debuglink expected messages
  • replaced Ed25519 module with a cleaner, optimized version
  • further reorganization of transports makes them more robust when dependencies are missing
  • codebase now follows Black code style
  • in Qt modules, Qt5 is imported first #315
  • TxApiInsight is just TxApi
  • device.reset and device.recover now have reasonable defaults for all arguments
  • protobuf classes are no longer part of the source distribution and must be compiled locally #284
  • Stellar: addresses are always strings


  • set_tx_api method on TrezorClient is replaced by an argument for sign_tx
  • caching functionality of TxApi was moved to a separate test-support class
  • Stellar: public key methods removed
  • EncryptMessage and DecryptMessage actions are gone


  • TrezorClient can now detect when a HID device is removed and a different one is plugged in on the same path
  • trezorctl now works with Click 7.0 and considers "_" and "-" as same in command names #314
  • bash completion fixed
  • Stellar: several bugs in the XDR parser were fixed

0.10.2 - 2018-06-21


  • stellar_get_address and _public_key functions support show_display parameter
  • trezorctl: stellar_get_address and _public_key commands for the respective functionality


  • trezorctl: list_coins is removed because we no longer parse the relevant protobuf field (and newer Trezor firmwares don't send it) #277


  • test support module was not included in the release, so code relying on the deprecated ckd_public module would fail #280

0.10.1 - 2018-06-11


  • previous release fails to build on Windows #274

0.10.0 - 2018-06-08


  • Lisk support #197
  • Stellar support #167, #268
  • Wanchain support #230
  • support for "auto lock delay" feature
  • TrezorClient takes an additional argument state that allows reusing the previously entered passphrase #241
  • USB transports mention udev rules in exception messages #245
  • log.enable_debug_output function turns on wire logging, instead of having to use TrezorClientVerbose
  • BIP32 paths now support 123h in addition to 123' to indicate hardening
  • trezorctl: -p now supports prefix search for device path #226
  • trezorctl: smarter handling of firmware updates #242, #269


  • reorganized transports and moved into their own transport submodule
  • protobuf messages and coins info is now regenerated at build time from the trezor-common repository #248
  • renamed ed25519raw to _ed25519 to indicate its privateness
  • renamed ed25519cosi to cosi and expanded its API
  • protobuf messages are now logged through Python's logging facility instead of custom printing through VerboseWireMixin
  • client.format_protobuf is moved to protobuf.format_message
  • tools.Hash is renamed to tools.btc_hash
  • coins module coins_txapi is renamed to tx_api. coins_slip44 is renamed to slip44.
  • build: stricter flake8 checks
  • build: split requirements to separate files
  • tests: unified finding test device, while respecting TREZOR_PATH env variable.
  • tests: auto-skip appropriately marked tests based on Trezor device version
  • tests: only show wire output when run with -v
  • tests: allow running xfailed tests selectively based on pytest.ini
  • docs: updated README with clearer install instructions #185
  • docs: switched changelog to Keep a Changelog format #94


  • ckd_public is only maintained in submodule and considered private
  • TrezorClient.expand_path is moved to plain function tools.parse_path
  • TrezorDevice is deprecated in favor of transport.enumerate_devices and transport.get_transport
  • XPUB-related handling in tools is slated for removal


  • most Python 2 compatibility constructs are gone #229
  • TrezorClientVerbose and VerboseWireMixin is removed
  • specific tx_api.TxApi* classes removed in favor of coins.tx_api
  • client.PRIME_DERIVATION_FLAG is removed in favor of tools.HARDENED_FLAG and tools.H_()
  • hard dependency on Ethereum libraries and HIDAPI is changed into extras that need to be specified explicitly. Require trezor[hidapi] or trezor[ethereum] to get them.


  • WebUSB enumeration returning bad devices on Windows 10 #223
  • sign_tx operation sending empty address string #237
  • Wrongly formatted Ethereum signatures #236
  • protobuf layer would wrongly encode signed integers #249, #250
  • protobuf pretty-printing broken on Python 3.4 #256
  • trezorctl: Matrix recovery on Windows wouldn't allow backspace #207
  • fixed Python 3 bug #169

0.9.1 - 2018-03-05


  • proper support for Trezor model T
  • support for Monacoin
  • improvements to trezorctl:
    • add pretty-printing of features and protobuf debug dumps (fixes #199)
    • support TREZOR_PATH environment variable to preselect a Trezor device.


  • gradually dropping Python 2 compatibility (pypi package will now be marked as Python 3 only)

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

trezor-0.13.3.tar.gz (187.9 kB view hashes)

Uploaded source

Built Distribution

trezor-0.13.3-py3-none-any.whl (185.0 kB view hashes)

Uploaded py3

Supported by

AWS AWS Cloud computing Datadog Datadog Monitoring Facebook / Instagram Facebook / Instagram PSF Sponsor Fastly Fastly CDN Google Google Object Storage and Download Analytics Huawei Huawei PSF Sponsor Microsoft Microsoft PSF Sponsor NVIDIA NVIDIA PSF Sponsor Pingdom Pingdom Monitoring Salesforce Salesforce PSF Sponsor Sentry Sentry Error logging StatusPage StatusPage Status page