Skip to content


Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?


Failed to load latest commit information.
Latest commit message
Commit time
January 14, 2020 09:04
April 14, 2023 13:50
January 6, 2023 11:02
October 1, 2020 16:36
January 7, 2023 15:10
October 1, 2020 16:36
August 11, 2021 16:46
February 3, 2020 14:46
June 13, 2014 12:09
April 11, 2023 14:54
January 6, 2023 13:07


KeepKey Build Procedure

Toolchain Installation

Install Docker Community Edition from:

$ docker pull kktech/firmware:v5-beta

Clone the Source

The sources can be obtained from github:

$ git clone
$ git submodule update --init --recursive


To build the firmware using the docker container, use the provided script:

$ ./scripts/build/docker/device/

Verifying Published Binaries

Compare the hash of a given tagged build:

$ git checkout v6.2.0
$ git submodule update --init --recursive
$ ./scripts/build/docker/device/
$ tail -c +257 ./bin/firmware.keepkey.bin | shasum -a 256

With that of the signed v6.2.0 binary on github, ignoring signatures and firmware metadata:

$ tail -c +257 firmware.keepkey.bin | shasum -a 256

Then inspect the metadata itself by comparing against the structure described here:

$ head -c +256 signed_firmware.bin | xxd -


  1. v6.2.2 and v6.3.0 had an issue with build reproducibility. See #212.
  2. As of v6.1.0 and later, we started prepending empty slots for signatures as part of the build, and prior firmwares were emitted without that metadata section. See 87b9ebb84


Documentation can be found here.


If license is not specified in the header of a file, it can be assumed that it is licensed under LGPLv3.