{"_id":"@asylia/hw-trezor","_rev":"3-6533cd349d2086322c8e58649e2ef87b","name":"@asylia/hw-trezor","dist-tags":{"latest":"1.0.1"},"versions":{"0.1.0":{"name":"@asylia/hw-trezor","version":"0.1.0","keywords":["bitcoin","trezor","trezor-connect","hardware-wallet","xpub","bip48","bip380","p2wsh","multisig","psbt","psbt-signing","typescript","self-custody","asylia"],"author":{"name":"Asylia"},"license":"MIT","_id":"@asylia/hw-trezor@0.1.0","maintainers":[{"name":"asylion21","email":"infodavidzita@gmail.com"}],"homepage":"https://github.com/Asylia/bitcoin-toolkit/tree/main/packages/hw-trezor#readme","bugs":{"url":"https://github.com/Asylia/bitcoin-toolkit/issues"},"dist":{"shasum":"06dd7a3ab7edd6b235df7f28264995a39310199d","tarball":"https://registry.npmjs.org/@asylia/hw-trezor/-/hw-trezor-0.1.0.tgz","fileCount":8,"integrity":"sha512-0sSpu+dsCsLx5zxA1epYyCk5Ug5tz2qh+90kLQsvNKhgqjR+WTW1g4MRl43ecYan2u04Yb3UM3yh6rwwYOqYgg==","signatures":[{"sig":"MEUCIQCMiJz8goIqDfoXAWltdUWnv7Q1sM+Has3tkjQ04TO6GAIgWlmzwwaiw+Uid0TcPmcHhrRZlsGcRii/OQq8qL80AMM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":241474},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsup src/index.ts --format esm --dts --sourcemap --clean --out-dir dist --tsconfig tsconfig.build.json","clean":"rimraf dist .turbo node_modules/.tmp","type-check":"tsc --noEmit","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"asylion21","email":"infodavidzita@gmail.com"},"repository":{"url":"git+https://github.com/Asylia/bitcoin-toolkit.git","type":"git","directory":"packages/hw-trezor"},"_npmVersion":"10.9.2","description":"Auditable Trezor hardware-wallet TypeScript adapter for Connect initialization, environment checks, xpub export, address display, and P2WSH multisig PSBT signing.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"tslib":"^2.8.1","bs58check":"^4.0.0","@trezor/connect-web":"^9.7.3"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.3","vitest":"^4.1.5","typescript":"^6.0.3","@asylia/btc-core":"*","@vitest/coverage-v8":"^4.1.5"},"peerDependencies":{"@asylia/btc-core":"^0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/hw-trezor_0.1.0_1777723337111_0.8449869587563337","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@asylia/hw-trezor","version":"1.0.0","keywords":["bitcoin","trezor","trezor-connect","hardware-wallet","xpub","bip48","bip380","p2wsh","multisig","psbt","psbt-signing","typescript","self-custody","asylia"],"author":{"name":"Asylia"},"license":"MIT","_id":"@asylia/hw-trezor@1.0.0","maintainers":[{"name":"asylion21","email":"infodavidzita@gmail.com"}],"homepage":"https://github.com/Asylia/bitcoin-toolkit/tree/main/packages/hw-trezor#readme","bugs":{"url":"https://github.com/Asylia/bitcoin-toolkit/issues"},"dist":{"shasum":"c323dc3f466ed99012ddb57a223a7bd6d9a58c7d","tarball":"https://registry.npmjs.org/@asylia/hw-trezor/-/hw-trezor-1.0.0.tgz","fileCount":8,"integrity":"sha512-Olag6FeZ2AF0NrP/5kUNsfxULDexliC2ozlt6GgzUN6sTWUJNvZfOKefJS5aVLGLb7sXlxKcvZUxGEwZ3hPiJQ==","signatures":[{"sig":"MEUCIQCEtOgAQtp4tn1FGyAP8OGU7ohsmIy+ORY4DrmSQJlTMQIgPWWLTE4CltM5n9hKeadqgaYnpZT953lM+ZiPab8t244=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":244764},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"9472028259c7ecd4e1becd42fd837267dfdd7fca","scripts":{"lint":"eslint .","test":"vitest run","build":"tsup --config tsup.config.ts","clean":"rimraf dist .turbo node_modules/.tmp","type-check":"tsc --noEmit","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"asylion21","email":"infodavidzita@gmail.com"},"repository":{"url":"git+https://github.com/Asylia/bitcoin-toolkit.git","type":"git","directory":"packages/hw-trezor"},"_npmVersion":"10.9.2","description":"Auditable Trezor hardware-wallet TypeScript adapter for Connect initialization, environment checks, xpub export, address display, and P2WSH multisig PSBT signing.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"tslib":"^2.8.1","bs58check":"^4.0.0","@trezor/connect-web":"^9.7.3"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","rimraf":"^6.1.3","vitest":"^4.1.5","typescript":"^6.0.3","@asylia/btc-core":"^1.0.0","@vitest/coverage-v8":"^4.1.5"},"peerDependencies":{"@asylia/btc-core":"^1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/hw-trezor_1.0.0_1777891164754_0.41452983141436084","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@asylia/hw-trezor","version":"1.0.1","type":"module","description":"Auditable Trezor hardware-wallet TypeScript adapter for Connect initialization, environment checks, xpub export, address display, and P2WSH multisig PSBT signing.","license":"MIT","author":{"name":"Asylia"},"repository":{"type":"git","url":"git+https://github.com/Asylia/bitcoin-toolkit.git","directory":"packages/hw-trezor"},"homepage":"https://github.com/Asylia/bitcoin-toolkit/tree/main/packages/hw-trezor#readme","bugs":{"url":"https://github.com/Asylia/bitcoin-toolkit/issues"},"keywords":["bitcoin","trezor","trezor-connect","hardware-wallet","xpub","bip48","bip380","p2wsh","multisig","psbt","psbt-signing","typescript","self-custody","asylia"],"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsup --config tsup.config.ts","type-check":"tsc --noEmit","lint":"eslint .","test":"vitest run","test:coverage":"vitest run --coverage","clean":"rimraf dist .turbo node_modules/.tmp"},"peerDependencies":{"@asylia/btc-core":"^1.0.1"},"devDependencies":{"@asylia/btc-core":"^1.0.1","@vitest/coverage-v8":"^4.1.6","eslint":"^10.3.0","rimraf":"^6.1.3","tsup":"^8.5.1","typescript":"^6.0.3","vitest":"^4.1.6"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"dependencies":{"@trezor/connect-web":"^9.7.3","bs58check":"^4.0.0","tslib":"^2.8.1"},"_id":"@asylia/hw-trezor@1.0.1","gitHead":"d269e09a317e911fc1438e068c02a209abc5dac4","_nodeVersion":"21.7.3","_npmVersion":"10.7.0","dist":{"integrity":"sha512-XtVGhA+XgH4v8HPTcE1lGepP7uvhbzmNNBCT9ZadGfjb3ZPJyx2o8j1ydCa9PSk/1rdpLkdqP9cX4vpp9zB9CA==","shasum":"e9b32240808e1571038fec9eaa9520c1d47dfd3c","tarball":"https://registry.npmjs.org/@asylia/hw-trezor/-/hw-trezor-1.0.1.tgz","fileCount":8,"unpackedSize":259152,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIApQLJuvCdwzPPuadd3Y9cu+acT2PfLJpQQtvzcpONikAiAIrF5DN7E2onux7ct8kuiXk/+a007dSmrQaGiLW5p5cw=="}]},"_npmUser":{"name":"asylion21","email":"infodavidzita@gmail.com"},"directories":{},"maintainers":[{"name":"asylion21","email":"infodavidzita@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/hw-trezor_1.0.1_1778785887170_0.70566892002041"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-02T12:02:17.031Z","modified":"2026-05-14T19:11:27.434Z","0.1.0":"2026-05-02T12:02:17.732Z","1.0.0":"2026-05-04T10:39:24.909Z","1.0.1":"2026-05-14T19:11:27.335Z"},"bugs":{"url":"https://github.com/Asylia/bitcoin-toolkit/issues"},"author":{"name":"Asylia"},"license":"MIT","homepage":"https://github.com/Asylia/bitcoin-toolkit/tree/main/packages/hw-trezor#readme","keywords":["bitcoin","trezor","trezor-connect","hardware-wallet","xpub","bip48","bip380","p2wsh","multisig","psbt","psbt-signing","typescript","self-custody","asylia"],"repository":{"type":"git","url":"git+https://github.com/Asylia/bitcoin-toolkit.git","directory":"packages/hw-trezor"},"description":"Auditable Trezor hardware-wallet TypeScript adapter for Connect initialization, environment checks, xpub export, address display, and P2WSH multisig PSBT signing.","maintainers":[{"name":"asylion21","email":"infodavidzita@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"../../apps/wallet/resources/logo.svg\" alt=\"Asylia\" width=\"96\" />\n</p>\n\n# @asylia/hw-trezor\n\nTrezor hardware-wallet adapter for the Asylia self-custody platform. It wraps\n`@trezor/connect-web` behind a narrow Asylia-shaped API for initialization,\nenvironment checks, xpub export, address display, live events, and PSBT signing.\n\nThe wallet UI never imports Trezor Connect directly. Every device interaction\nthat can influence a Bitcoin vault passes through this package, making the\nsecurity boundary easy to audit and reuse outside the Vue app.\n\nKeywords: Trezor, Bitcoin hardware wallet, Trezor Connect, PSBT signing, P2WSH\nmultisig, BIP-48, BIP-380 descriptor, xpub export, self-custody, TypeScript.\n\n## Maintainer And Support\n\n`@asylia/hw-trezor` is maintained by [Asylian21](https://github.com/Asylian21).\n\n> **Support Asylia Bitcoin tooling**\n>\n> If this work helps your wallet, audit, integration, or research, you can\n> support ongoing development with a Bitcoin donation:\n> `bc1qrdchup8497xz0972v35q4nr0fx5egghf0z23c3`\n\n## Status\n\n`1.0.0`. Initialization, environment detection, xpub export, address\ndisplay, live events, and `wsh(sortedmulti(...))` PSBT signing are implemented.\n\n## Installation\n\n```bash\nnpm install @asylia/hw-trezor @asylia/btc-core\n```\n\n## Why This Package Exists\n\nHardware-wallet code is a hard security boundary:\n\n- It speaks to a physical device the user trusts.\n- It requests xpub material and master fingerprints.\n- It maps PSBT data into device prompts.\n- It receives signatures that may authorize Bitcoin spends.\n- It must normalize vendor failures into predictable application states.\n\nPulling the Trezor integration out of the wallet SPA keeps the audited surface\nsmall, isolates vendor SDK upgrades, and leaves room for a future Capacitor\nsigner to reuse the same logic.\n\n## Public API\n\nEvery public export is defined by the source barrel and published from the\npackage root.\n\n| Export | Purpose |\n| --- | --- |\n| `initTrezor(manifest)` | Idempotent Trezor Connect bootstrap. |\n| `detectTrezorEnvironment()` | Browser/transport capability probe for UX guidance. |\n| `recommendationFromEnvironment()` | Converts environment state into recommended next steps. |\n| `exportTrezorRoot({ derivationPath, scriptType })` | Prompts the device for the BIP-48 multisig root xpub and master fingerprint. |\n| `displayWshSortedMultiAddress(input)` | Requests an on-device display of a derived P2WSH multisig address. |\n| `signWshSortedMultiPsbt(input)` | Translates a PSBT v2 into Trezor's transaction format, collects signatures, verifies ownership, and merges partial signatures back into the PSBT. |\n| `subscribeToTrezorEvents(handler)` | Streams device, prompt, and transport events for UI steppers and diagnostics. |\n| Public types | Adapter result, manifest, device info, script type, export/sign/display inputs, and normalized errors. |\n\nAll high-level flows return `AdapterResult<T>`: `{ ok: true, data }` or\n`{ ok: false, error }`. UI code should render adapter errors directly instead of\ncatching and pattern-matching raw vendor exceptions.\n\n## Example\n\n```ts\nimport {\n  exportTrezorRoot,\n  initTrezor,\n  signWshSortedMultiPsbt,\n} from '@asylia/hw-trezor';\n\nawait initTrezor({\n  appName: 'Asylia Wallet',\n  appUrl: 'https://wallet.asylia.io',\n  email: 'support@asylia.io',\n});\n\nconst exported = await exportTrezorRoot({\n  derivationPath: \"m/48'/0'/0'/2'\",\n  scriptType: 'p2wsh',\n});\n\nif (exported.ok) {\n  const { xpub, masterFingerprint, device } = exported.data;\n  // Persist xpub + masterFingerprint as signer metadata.\n}\n\nconst signed = await signWshSortedMultiPsbt({\n  psbtBase64,\n  vault: {\n    requiredSignatures: 2,\n    keys: descriptorKeys,\n  },\n  signerFingerprint: 'd34db33f',\n});\n```\n\n## Derivation and Script Policy\n\nAsylia targets native-SegWit BIP-48 multisig only:\n\n```text\nwsh(sortedmulti(...)) at m/48'/0'/0'/2'\n```\n\nFrom that xpub depth, the wallet derives receive and change addresses with\nunhardened `/0/i` and `/1/i` children without asking the device again.\n\nThe nested-SegWit BIP-48 branch (`m/48'/0'/0'/1'`, `sh(wsh(...))`) is not\nsupported. The `TrezorScriptType` union intentionally exposes only `p2wsh`.\n\n## Master Fingerprint\n\nTrezor returns descriptor-shaped public-key metadata. The adapter parses the\nleading 8-character hex fingerprint and returns it as\n`masterFingerprint`, which is the signer identity Asylia stores for matching\nfuture signatures.\n\nTrezor Model One cannot return the descriptor field required for this flow. The\nadapter returns `descriptor_unavailable` so the wallet can show precise upgrade\nguidance instead of a generic failure.\n\n## Web Transport Model\n\nThe adapter uses Trezor Connect's `coreMode: 'auto'` resolution:\n\n- local Trezor service or Suite transport available: iframe mode with event\n  streaming into the SPA,\n- otherwise: popup mode, with Trezor Connect owning browser-side prompts.\n\nPIN, passphrase, permission, and export approval prompts are owned by Trezor\nConnect and the physical Trezor device. `@trezor/connect-web` is USB-only in the\nbrowser; Bluetooth belongs to a future native mobile signer path.\n\n## Signing Model\n\nTrezor Connect does not sign PSBT payloads directly. It signs a Trezor-native\ntransaction shape. `signWshSortedMultiPsbt` bridges that gap:\n\n1. Inspect the PSBT v2 with `@asylia/btc-core`.\n2. Translate inputs into Trezor `SPENDWITNESS` entries with multisig metadata.\n3. Translate external outputs and vault change outputs into device-readable\n   prompts. No-change spends are represented without a wallet change output.\n4. Preserve PSBT version and locktime so signatures are over the transaction the\n   wallet will actually finalize.\n5. Verify returned signatures against the expected cosigner pubkeys.\n6. Re-attribute signatures when a different valid passphrase wallet signs from\n   the same physical device.\n7. Merge verified signatures back into the PSBT with the SIGHASH_ALL byte.\n\nIf no vault cosigner owns a returned signature, the adapter refuses it. Broken\nor misattributed partial signatures should never reach the proposal store.\n\nFor native-SegWit PSBTs, the adapter does not ship previous full transactions\nas Trezor `refTxs`; witness UTXO data from the inspected PSBT is enough for the\ndevice signing flow. That keeps the package dependency boundary narrow:\nPSBT/transaction parsing remains in `@asylia/btc-core`, while this package owns\nonly the Trezor Connect mapping and post-flight signature attribution.\n\n## Error Model\n\nVendor failures are normalized into stable `TrezorErrorCode` values:\n\n```text\ninit_failed | manifest_required | cancelled | device_disconnected |\ndevice_not_found | device_in_use | device_locked | device_timeout |\nfirmware_too_old | descriptor_unavailable | invalid_multisig |\ninvalid_path | message_signing_forbidden_path | transport_unavailable |\nunknown\n```\n\nThe wallet renders the adapter's user-facing message. It should not depend on\nTrezor Connect's raw error strings.\n\n## Not in Scope\n\nThis package does not:\n\n- persist xpubs, fingerprints, or signatures,\n- store seed phrases or private keys,\n- render UI,\n- fetch chain data,\n- build descriptors or PSBTs from scratch,\n- support non-Asylia script families.\n\nDescriptor construction and PSBT helpers live in `@asylia/btc-core`.\n\n## Testing\n\n```bash\nyarn workspace @asylia/hw-trezor type-check\nyarn workspace @asylia/hw-trezor test\n```\n\n## Versioning and Audit Stance\n\nThe package uses semver for stable releases. See [`SECURITY.md`](./SECURITY.md)\nfor the disclosure process and security scope.\n\n## License\n\nMIT - see [`LICENSE`](./LICENSE).\n","readmeFilename":"README.md"}