espefuse - ESP32 efuse get/set tool

usage: espefuse [OPTION] COMMAND

Burn the efuse with the specified name
Disable readback for the efuse with the specified name
Disable writing to the efuse with the specified name
Burn non-key data to EFUSE blocks. (Don't use this command to burn key data for Flash Encryption or ESP32 Secure Boot V1, as the byte order of keys is swapped (use burn_key)).
Burn bit in the efuse block.
Display information about ADC calibration data stored in efuse.
Dump raw hex values of all efuses
Print human-readable summary of efuse values
Executes scripts to burn at one time.
Checks eFuse errors
Burn a 256-bit key to EFUSE: BLOCK1, flash_encryption, BLOCK2, secure_boot_v1, secure_boot_v2, BLOCK3
Parse a RSA public key and burn the digest to eFuse for use with Secure Boot V2
Permanently set the internal flash voltage regulator to either 1.8V, 3.3V or OFF. This means GPIO12 can be high or low at reset without changing the flash voltage.
Burn a 48-bit Custom MAC Address to EFUSE BLOCK3.
Prints the Custom MAC Address.

show this help message and exit
Target chip type
Serial port baud rate used when flashing/reading
Serial port device
What to do before connecting to the chip
Show debugging information (loglevel=DEBUG)
For host tests, the tool will work in the virtual mode (without connecting to a chip).
For host tests, saves efuse memory to file.
Do not pause for confirmation before permanently writing efuses. Use with caution.

Display device features, SPI flash manufacturer and device ID:

esptool flash_id

Flash ESP8266 Espressif AT v1.6.2 firmware to ESP-WROOM-02 board:

esptool write_flash --flash_mode dio --flash_size 4MB-c1 0x00 boot_v1.7.bin 0x1000 at/1024+1024/ 0xfe000 blank.bin 0x3fc000 esp_init_data_default_v08.bin 0x3fe000 blank.bin

Flash ESP32 Espressif AT v1.1.1 firmware to ESP-WROOM-32 board:

esptool write_flash --flash_mode dio --flash_freq 40m --flash_size detect 0x1000 bootloader/bootloader.bin 0x20000 at_customize.bin 0x21000 customized_partitions/ble_data.bin 0x24000 customized_partitions/server_cert.bin 0x26000 customized_partitions/server_key.bin 0x28000 customized_partitions/server_ca.bin 0x2a000 customized_partitions/client_cert.bin 0x2c000 customized_partitions/client_key.bin 0x2e000 customized_partitions/client_ca.bin 0xf000 phy_init_data.bin 0x100000 esp-at.bin 0x8000 partitions_at.bin

Display ESP32 efuse state summary:

espefuse --port /dev/ttyUSB0 summary

Generate a flash encryption key:

espsecure generate_flash_encryption_key key.bin

Burn the key to the device (WARNING: one time only operation):

espefuse --port /dev/ttyUSB1 burn_key flash_encryption key.bin

Encrypt flash data:

espsecure encrypt_flash_data --keyfile key.bin --address 0x10000 -o my-app-encrypted.bin my-app.bin was started by Fredrik Ahlberg as an unofficial community project, currently maintained by Angus Gratton and supported by Espressif Systems (Shanghai) PTE LTD. This manual page has been produced by Milan Kupcevic <> for the Debian project and can be used by others.

Review: <>
Known issues: <>
Report new issues at: <>

Copyright © 2014-2017 Fredrik Ahlberg, Angus Gratton, Espressif Systems (Shanghai) PTE LTD, other contributors as noted. License GPLv2+: GNU GPL version 2 or later <>. This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law.

esptool(1), espefuse(1), espsecure(1)

January 2024 4.7.0