Summary

The espefuse summary command reads the eFuses from the chip and outputs them in text or json format. It is also possible to save it to a file. The command also supports eFuse filtering by name.

Optional arguments:

  • --format - Select the summary format:
    • summary - text format (default option).

    • json - json format. Usage --format json.

    • value_only - only the value of the eFuse specified as an argument will be displayed. For more information, refer to the Filtering eFuses section.

  • --active - Show only those fields that are active (i.e., have at least one bit set, read or write protected, or have an encoding error).

  • --file - File to save the eFuse summary. Usage --file efuses.json.

  • List of eFuses to filter. For more information, refer to the Filtering eFuses section.

Text Format Summary

The text format of summary consists of 3 main columns:

  1. This column consists of the eFuse name and additional information: the block name associated with this eFuse field and encoding errors (if any).

  2. Description of eFuse field.

  3. This column has human readable value, read/write protection status, raw value (hexadecimal or binary).

Read and Write Protection Status

The R/W output indicates a protection status of a specific eFuse field/block:

  • -/W indicates that read protection is set. Value of such eFuse field will always show all-zeroes, even though hardware may use the correct value. In espefuse v2.6 and newer, read-protected eFuse values are displayed as question marks (??). On earlier versions, they are displayed as zeroes.

    BLOCK1 (BLOCK1):
    = ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? -/W
    
  • R/- indicates that write protection is set. No further bits can be set.

  • -/- means both read and write protection are set.

Some eFuses have no protection at all, and some eFuses have only one read or write protection. There is no mark in the summary to expose it.

Display Efuse Summary

The eFuse summary may vary from version to version of this tool and differ for different chips. Below is the summary for the ESP32-H4 chip.

For details on the meaning of each eFuse value, refer to the Technical Reference Manual.

> espefuse -p PORT summary
Connecting....
Detecting chip type... ESP32-H4

=== Run "summary" command ===
EFUSE_NAME (Block) Description  = [Meaningful Value] [Readable/Writeable] (Hex Value)
----------------------------------------------------------------------------------------
Config fuses:
WR_DIS (BLOCK0)                                    Disable programming of individual eFuses           = 0 R/W (0x00000000)
RD_DIS (BLOCK0)                                    Disable reading from BlOCK4-10                     = 0 R/W (0b0000000)
DIS_TWAI (BLOCK0)                                  Represents whether TWAI function is disabled or en = False R/W (0b0)
                                                   abled. 1: disabled 0: enabled
PVT_GLITCH_EN (BLOCK0)                             Represents whether to enable PVT power glitch moni = False R/W (0b0)
                                                   tor function.1:Enable. 0:Disable
PVT_GLITCH_MODE (BLOCK0)                           Use to configure glitch mode                       = 0 R/W (0b00)
DIS_CORE1 (BLOCK0)                                 Represents whether the CPU-Core1 is disabled.  1:  = False R/W (0b0)
                                                   Disabled.  0: Not disable
ECC_FORCE_CONST_TIME (BLOCK0)                      Represents whether to force ecc to use const-time  = False R/W (0b0)
                                                   calculation mode.  1: Enable.  0: Disable
KM_DISABLE_DEPLOY_MODE (BLOCK0)                    Represents whether the new key deployment of key m = 0 R/W (0b00000)
                                                   anager is disabled. Bit0: Represents whether the n
                                                   ew ECDSA key deployment is disabled0: Enabled1: Di
                                                   sabledBit1: Represents whether the new XTS-AES (fl
                                                   ash and PSRAM) key deployment is disabled0: Enable
                                                   d1: DisabledBit2: Represents whether the new HMAC
                                                   key deployment is disabled0: Enabled1: DisabledBit
                                                   3: Represents whether the new DS key deployment is
                                                    disabled0: Enabled1: Disabled
KM_RND_SWITCH_CYCLE (BLOCK0)                       Represents the cycle at which the Key Manager swit = 0 R/W (0b00)
                                                   ches random numbers.0: Controlled by the \hyperref
                                                   [fielddesc:KEYMNGRNDSWITCHCYCLE]{KEYMNG\_RND\_SWIT
                                                   CH\_CYCLE} register. For more information; please
                                                   refer to Chapter \ref{mod:keymng} \textit{\nameref
                                                   {mod:keymng}}1: 8 Key Manager clock cycles2: 16 Ke
                                                   y Manager clock cycles3: 32 Key Manager clock cycl
                                                   es
KM_DEPLOY_ONLY_ONCE (BLOCK0)                       Represents whether the corresponding key can be de = 0 R/W (0b00000)
                                                   ployed only once.Bit0: Represents whether the ECDS
                                                   A key can be deployed only once0: The key can be d
                                                   eployed multiple times1: The key can be deployed o
                                                   nly onceBit1: Represents whether the XTS-AES (flas
                                                   h and PSRAM) key can be deployed only once0: The k
                                                   ey can be deployed multiple times1: The key can be
                                                    deployed only onceBit2: Represents whether the HM
                                                   AC key can be deployed only once0: The key can be
                                                   deployed multiple times1: The key can be deployed
                                                   only onceBit3: Represents whether the DS key can b
                                                   e deployed only once0: The key can be deployed mul
                                                   tiple times1: The key can be deployed only once
DIS_DIRECT_BOOT (BLOCK0)                           Represents whether direct boot mode is disabled or = False R/W (0b0)
                                                    enabled. 1: disabled 0: enabled
UART_PRINT_CONTROL (BLOCK0)                        Represents the type of UART printing. 00: force en = 0 R/W (0b00)
                                                   able printing 01: enable printing when GPIO8 is re
                                                   set at low level 10: enable printing when GPIO8 is
                                                    reset at high level 11: force disable printing
HUK_GEN_STATE (BLOCK0)                             Represents whether the HUK generate mode is valid. = 0 R/W (0b00000)
                                                   Odd count of bits with a value of 1: InvalidEven c
                                                   ount of bits with a value of 1: Valid
DCDC_CCM_EN (BLOCK0)                               Represents whether change DCDC to CCM mode         = False R/W (0b0)
PVT_LIMIT (BLOCK1)                                 Power glitch monitor threthold                     = 0 R/W (0x0000)
PVT_CELL_SELECT (BLOCK1)                           Power glitch monitor PVT cell select               = 0 R/W (0b0000000)
PVT_PUMP_LIMIT (BLOCK1)                            Use to configure voltage monitor limit for charge  = 0 R/W (0x00)
                                                   pump
PUMP_DRV (BLOCK1)                                  Use to configure charge pump voltage gain          = 0 R/W (0x0)
HYS_EN_PAD (BLOCK1)                                Represents whether the hysteresis function of corr = False R/W (0b0)
                                                   esponding PAD is enabled. 1: enabled 0:disabled
PVT_GLITCH_CHARGE_RESET (BLOCK1)                   Represents whether to trigger reset or charge pump = False R/W (0b0)
                                                    when PVT power glitch happened.1:Trigger charge p
                                                   ump. 0:Trigger reset
BLOCK_USR_DATA (BLOCK3)                            User data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_SYS_DATA2 (BLOCK10)                          System data part 2 (reserved)
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W

Flash fuses:
FLASH_TPUW (BLOCK0)                                Represents the flash waiting time after power-up;  = 0 R/W (0b000)
                                                   in unit of ms. When the value less than 15; the wa
                                                   iting time is the programmed value. Otherwise; the
                                                    waiting time is 2 times the programmed value
FORCE_SEND_RESUME (BLOCK0)                         Represents whether ROM code is forced to send a re = False R/W (0b0)
                                                   sume command during SPI boot. 1: forced 0:not forc
                                                   ed
FLASH_LDO_EFUSE_SEL (BLOCK0)                       Represents whether to select efuse control flash l = False R/W (0b0)
                                                   do default voltage.  1 : efuse 0 : strapping
FLASH_LDO_POWER_SEL (BLOCK1)                       Represents which flash ldo be select: 1: FLASH LDO = False R/W (0b0)
                                                    1P2 0 : FLASH LDO 1P8

Jtag fuses:
JTAG_SEL_ENABLE (BLOCK0)                           Represents whether the selection between usb_to_jt = False R/W (0b0)
                                                   ag and pad_to_jtag through strapping gpio15 when b
                                                   oth EFUSE_DIS_PAD_JTAG and EFUSE_DIS_USB_JTAG are
                                                   equal to 0 is enabled or disabled. 1: enabled 0: d
                                                   isabled
DIS_PAD_JTAG (BLOCK0)                              Represents whether JTAG is disabled in the hard wa = False R/W (0b0)
                                                   y(permanently). 1: disabled 0: enabled
SOFT_DIS_JTAG (BLOCK0)                             Represents whether JTAG is disabled in soft way. O = 0 R/W (0b000)
                                                   dd number: disabled Even number: enabled

Mac fuses:
MAC (BLOCK1)                                       MAC address
   = 00:00:00:00:00:00 (OK) R/W
MAC_EXT (BLOCK1)                                   Represents the extended bits of MAC address        = 00:00 (OK) R/W
CUSTOM_MAC (BLOCK3)                                Custom MAC
   = 00:00:00:00:00:00 (OK) R/W
MAC_EUI64 (BLOCK1)                                 calc MAC_EUI64 = MAC[0]:MAC[1]:MAC[2]:MAC_EXT[0]:M
   = 00:00:00:00:00:00:00:00 (OK) R/W
                                                   AC_EXT[1]:MAC[3]:MAC[4]:MAC[5]

Security fuses:
DIS_FORCE_DOWNLOAD (BLOCK0)                        Represents whether the function that forces chip i = False R/W (0b0)
                                                   nto download mode is disabled or enabled. 1: disab
                                                   led 0: enabled
SPI_DOWNLOAD_MSPI_DIS (BLOCK0)                     Represents whether SPI0 controller during boot_mod = False R/W (0b0)
                                                   e_download is disabled or enabled. 1: disabled 0:
                                                   enabled
DIS_DOWNLOAD_MANUAL_ENCRYPT (BLOCK0)               Represents whether flash encrypt function is disab = False R/W (0b0)
                                                   led or enabled(except in SPI boot mode). 1: disabl
                                                   ed 0: enabled
SPI_BOOT_CRYPT_CNT (BLOCK0)                        Enables flash encryption when 1 or 3 bits are set  = Disable R/W (0b000)
                                                   and disables otherwise
SECURE_BOOT_KEY_REVOKE0 (BLOCK0)                   Revoke 1st secure boot key                         = False R/W (0b0)
SECURE_BOOT_KEY_REVOKE1 (BLOCK0)                   Revoke 2nd secure boot key                         = False R/W (0b0)
SECURE_BOOT_KEY_REVOKE2 (BLOCK0)                   Revoke 3rd secure boot key                         = False R/W (0b0)
KEY_PURPOSE_0 (BLOCK0)                             Represents the purpose of Key0                     = USER R/W (0b00000)
KEY_PURPOSE_1 (BLOCK0)                             Represents the purpose of Key1                     = USER R/W (0b00000)
KEY_PURPOSE_2 (BLOCK0)                             Represents the purpose of Key2                     = USER R/W (0b00000)
KEY_PURPOSE_3 (BLOCK0)                             Represents the purpose of Key3                     = USER R/W (0b00000)
KEY_PURPOSE_4 (BLOCK0)                             Represents the purpose of Key4                     = USER R/W (0b00000)
KEY_PURPOSE_5 (BLOCK0)                             Represents the purpose of Key5                     = USER R/W (0b00000)
SEC_DPA_LEVEL (BLOCK0)                             Represents the spa secure level by configuring the = 0 R/W (0b00)
                                                    clock random divide mode
XTS_DPA_PSEUDO_LEVEL (BLOCK0)                      Represents the pseudo round level of xts-aes anti- = 0 R/W (0b00)
                                                   dpa attack. 3: High. 2: Moderate 1. Low 0: Disable
                                                   d
XTS_DPA_CLK_ENABLE (BLOCK0)                        Represents whether xts-aes anti-dpa attack clock i = False R/W (0b0)
                                                   s enabled. 1. Enable. 0: Disable.
ECDSA_P384_ENABLE (BLOCK0)                         Represents if the chip supports ECDSA P384         = False R/W (0b0)
SECURE_BOOT_EN (BLOCK0)                            Represents whether secure boot is enabled or disab = False R/W (0b0)
                                                   led. 1: enabled 0: disabled
SECURE_BOOT_AGGRESSIVE_REVOKE (BLOCK0)             Represents whether revoking aggressive secure boot = False R/W (0b0)
                                                    is enabled or disabled. 1: enabled. 0: disabled
FORCE_USE_KEY_MANAGER_KEY (BLOCK0)                 Represents whether the corresponding key must come = 0 R/W (0b00000)
                                                    from Key Manager. Bit0: Represents whether the EC
                                                   DSA key must come from Key Manager.0: The key does
                                                    not need to come from Key Manager1: The key must
                                                   come from Key ManagerBit1: Represents whether the
                                                   XTS-AES (flash and PSRAM) key must come from Key M
                                                   anager.0: The key does not need to come from Key M
                                                   anager1: The key must come from Key ManagerBit2: R
                                                   epresents whether the HMAC key must come from Key
                                                   Manager.0: The key does not need to come from Key
                                                   Manager1: The key must come from Key ManagerBit3:
                                                   Represents whether the DS key must come from Key M
                                                   anager.0: The key does not need to come from Key M
                                                   anager1: The key must come from Key Manager
FORCE_DISABLE_SW_INIT_KEY (BLOCK0)                 Represents whether to disable the use of the initi = False R/W (0b0)
                                                   alization key written by software and instead forc
                                                   e use efuse\_init\_key.0: Enable1: Disable
KM_XTS_KEY_LENGTH_256 (BLOCK0)                     Represents which key flash encryption uses.0: XTS- = False R/W (0b0)
                                                   AES-256 key1: XTS-AES-128 key
LOCK_KM_KEY (BLOCK0)                               Represents whether the keys in the Key Manager are = False R/W (0b0)
                                                    locked after deployment.0: Not locked1: Locked
DIS_DOWNLOAD_MODE (BLOCK0)                         Represents whether Download mode is disabled or en = False R/W (0b0)
                                                   abled. 1: disabled 0: enabled
ENABLE_SECURITY_DOWNLOAD (BLOCK0)                  Represents whether security download is enabled or = False R/W (0b0)
                                                    disabled. 1: enabled 0: disabled
SECURE_VERSION (BLOCK0)                            Represents the version used by ESP-IDF anti-rollba = 0 R/W (0x0000)
                                                   ck feature
BLOCK_KEY0 (BLOCK4)
  Purpose: USER
               Key0 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_KEY1 (BLOCK5)
  Purpose: USER
               Key1 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_KEY2 (BLOCK6)
  Purpose: USER
               Key2 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_KEY3 (BLOCK7)
  Purpose: USER
               Key3 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_KEY4 (BLOCK8)
  Purpose: USER
               Key4 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W
BLOCK_KEY5 (BLOCK9)
  Purpose: USER
               Key5 or user data
   = 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W

Usb fuses:
DIS_USB_JTAG (BLOCK0)                              Represents whether the function of usb switch to j = False R/W (0b0)
                                                   tag is disabled or enabled. 1: disabled 0: enabled
DIS_USB_SERIAL_JTAG_ROM_PRINT (BLOCK0)             Represents whether print from USB-Serial-JTAG is d = False R/W (0b0)
                                                   isabled or enabled. 1: disabled 0: enabled
DIS_USB_SERIAL_JTAG_DOWNLOAD_MODE (BLOCK0)         Represents whether the USB-Serial-JTAG download fu = False R/W (0b0)
                                                   nction is disabled or enabled. 1: Disable 0: Enabl
                                                   e
USB_EXCHG_PINS (BLOCK0)                            Represents whether the D+ and D- pins of USB_SERIA = False R/W (0b0)
                                                   L_JTAG PHY is exchanged. 1: exchanged 0: not excha
                                                   nged
USB_OTG_FS_EXCHG_PINS (BLOCK0)                     Represents whether the D+ and D- pins of USB_OTG_F = False R/W (0b0)
                                                   S PHY is exchanged. 1: exchanged 0: not exchanged
USB_PHY_SEL (BLOCK0)                               Represents whether to exchange the USB_SERIAL_JTAG = False R/W (0b0)
                                                    PHY with USB_OTG_FS PHY.  1: exchanged.  0: not e
                                                   xchanged

Vdd fuses:
VDD_SPI_LDO_ADJUST (BLOCK1)                        Represents configuration of FLASH LDO mode and vol = 0 R/W (0x00)
                                                   tage.

Wdt fuses:
WDT_DELAY_SEL (BLOCK1)                             Represents the threshold level of the RTC watchdog = 0 R/W (0b00)
                                                    STG0 timeout. 0: Original threshold configuration
                                                    value of STG0 *2 1: Original threshold configurat
                                                   ion value of STG0 *4 2: Original threshold configu
                                                   ration value of STG0 *8 3: Original threshold conf
                                                   iguration value of STG0 *16

Json Format Summary

The json representation of eFuses for the ESP32 chip is shown below.

Each field includes raw_value: a lowercase hexadecimal string of the fuse bits with a 0x prefix. The format is the same for every field: non-bytes fields are padded with leading zero bits to a nibble (4-bit) boundary; bytes fields use the same byte order as the value hex (see the text format summary), as a continuous digit string after the 0x prefix (no spaces).

> espefuse summary --format json

{
    "ABS_DONE_0": {
        "bit_len": 1,
        "block": 0,
        "category": "security",
        "description": "Secure boot V1 is enabled for bootloader image",
        "efuse_type": "bool",
        "name": "ABS_DONE_0",
        "pos": 4,
        "raw_value": "0x0",
        "readable": true,
        "value": false,
        "word": 6,
        "writeable": true
    },
    "BLOCK1": {
        "bit_len": 256,
        "block": 1,
        "category": "security",
        "description": "Flash encryption key",
        "efuse_type": "bytes:32",
        "name": "BLOCK1",
        "pos": 0,
        "raw_value": "0x0000000000000000000000000000000000000000000000000000000000000000",
        "readable": true,
        "value": "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
        "word": 0,
        "writeable": true
    },
...
    "CODING_SCHEME": {
        "bit_len": 2,
        "block": 0,
        "category": "config",
        "description": "Efuse variable block length scheme",
        "efuse_type": "uint:2",
        "name": "CODING_SCHEME",
        "pos": 0,
        "raw_value": "0x0",
        "readable": true,
        "value": "NONE (BLK1-3 len=256 bits)",
        "word": 6,
        "writeable": true
    },
....
}

Save Json Format Summary To File

> espefuse summary --format json --file efuses.json

Connecting....
Detecting chip type... ESP32

=== Run "summary" command ===
Saving efuse values to efuses.json

Filtering Efuses and Displaying Only the Value

The espefuse summary command supports filtering eFuses by name. The eFuses to filter needs to be specified as positional arguments. If no eFuses are specified, complete summary will be displayed. Example:

> espefuse summary ABS_DONE_0 BLOCK1

=== Run "summary" command ===
EFUSE_NAME (Block) Description  = [Meaningful Value] [Readable/Writeable] (Hex Value)
----------------------------------------------------------------------------------------
Security fuses:
ABS_DONE_0 (BLOCK0)                                Secure boot V1 is enabled for bootloader image     = False R/W (0b0)
BLOCK1 (BLOCK1)                                    Flash encryption key
= 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 R/W

If --format value_only is specified, only the value of the eFuse specified as an argument will be displayed. Only one eFuse can be specified as an argument for this format. Example:

When the eFuse table is large, finding specific set values can be time-consuming. Use the --active flag to display only active fields (those with at least one bit set, read or write protected, or has a coding error). This produces a shorter, more readable table.

> espefuse summary --format value_only MAC

=== Run "summary" command ===
00:00:00:00:00:00 (CRC 0x00 OK)