Self-Custody Guide · 2025

Official Trezor™ login® || Desktop & Web App for Hardware Wallets

Everything you need to know about unlocking a Trezor hardware wallet through Trezor Suite — how the desktop app works, how the browser app works, what happens on the device screen, and how to keep your keys safe while you do it.

Trezor Suite Desktop Trezor Suite Web PIN & Passphrase Model One · T · Safe 3 · Safe 5

What this page covers

Please read first

A hardware wallet has no online account. There is no website where you type a password and reach your coins, and no legitimate software will ever ask you to type your recovery seed to log in. Anyone who asks for your 12, 20 or 24 words — on a page, in an email, in a chat, or on the phone — is trying to empty your wallet.

What "Logging In" Means for a Hardware Wallet

With a normal online service, logging in proves that you know a password. With a hardware wallet, the login is a physical act. Your private keys never leave the small device plugged into your computer; the device itself signs whatever needs signing, and the wallet software on your screen is only a window onto the blockchain. The "login" is really an unlock: you let the device use its keys for a session, and when you unplug it they are sealed away again. Nothing you type into a browser tab can move funds on its own.

Trezor Suite Desktop — the Application

Trezor Suite is the official companion application made by SatoshiLabs, the Czech company behind Trezor. It replaced the older browser-based Trezor Wallet and exists in two forms: a downloadable desktop program and a web version. Most owners should use the desktop build.

Why the desktop app is usually the better choice

Suite also has a mobile app focused on the essentials; the desktop program covers the full feature set — coin control, labelling, buy and exchange integrations, and portfolio charts.

Trezor Suite Web — the Browser App

The web app runs at the company's own domain in a supported browser — convenient on a computer where you cannot install software. The trade-off is that you must be certain the address is right and that the browser can speak to the device.

Browser support matters more than people expect. WebUSB, which lets a page talk directly to a USB device, exists in Chromium-based browsers such as Chrome, Edge and Brave. Firefox and Safari do not offer it, so the web app cannot see a plugged-in Trezor there. On those browsers, and on older Windows machines, you need the Trezor Bridge helper service, a small background program that relays the connection between browser and device.

Desktop vs web at a glance

AspectSuite DesktopSuite Web
InstallationDownload and install onceNone — open a page
Browser neededNoChromium-based for direct access
Extra helperNot requiredTrezor Bridge on Firefox, Safari, older Windows
Firmware updatesFully supportedSupported
Tor modeYesNo
Best forEveryday long-term useQuick access on a borrowed or locked-down computer

The Unlock Process, Step by Step

Whichever version you open, the sequence is almost identical. The device is doing the security work; the app is only asking.

  1. Plug the device in. Use the cable that came in the box. Charge-only USB cables are a surprisingly common cause of "device not found" messages.
  2. Open Suite. Either the installed program or the official web address, and wait for it to show your device as connected.
  3. Unlock the device itself. On a Model One you press the two buttons in the order shown on its tiny screen; on a touchscreen model you tap the pattern you set. This protects the device if it is ever stolen.
  4. Enter your PIN. This is the step people find confusing. To defeat keyloggers, Suite shows a scrambled number pad on your monitor while the device transmits a matching layout. You click positions, not digits, so nothing watching learns the code; the device checks the real values internally. On touchscreen models you can type the PIN on the device glass instead — even more private.
  5. Decide about a passphrase. Every different passphrase opens a separate hidden wallet, so one seed can host several identities. It is not your device PIN and not your recovery phrase.
  6. Confirm on the device screen. Suite shows intent, address and amount; so does the device. If the two ever disagree, stop — that mismatch is the clearest sign of tampering.
  7. Use your wallet, then unplug. Disconnecting proves the point: the keys were always in your hand.

The rule that never changes

Your recovery seed is typed only into the hardware device itself, only during setup or recovery. No login, no update, no support agent and no "wallet validation" page needs it. Treat any request for those words as an attack in progress.

Why There Is No Username and Password

A password lives on someone else's server, which means someone else can lose it, leak it or reset it. Your keys live on a chip in your desk drawer, so the only credential that matters is possession plus the PIN. Three consequences follow naturally:

Model Comparison

FeatureModel OneModel TSafe 3Safe 5
Released2014201820232024
InterfaceMono screen, 2 buttonsColour touchscreenMono screen, 2 buttonsColour touchscreen, haptics
PIN entryButtons on deviceOn device glassButtons on deviceOn device glass
Secure elementNoNoYesYes
Shamir backupNoYesYesYes
Connectormicro-USBUSB-CUSB-CUSB-C

Firmware releases for the oldest hardware eventually slow down, so an early Model One owner sees fewer new features. The unlock flow, though, stays familiar across every generation.

Security Features Behind the Login

PIN scrambling

The shuffled keypad means the position you click tells a watcher nothing — not even a screen recorder can rebuild the PIN from those coordinates.

Passphrase-hidden wallets

A passphrase creates a separate wallet from the same seed, so anyone who forces you to open your device sees only the wallet you choose to reveal.

On-device confirmation

Payments, addresses and firmware signatures are approved on the trusted screen, so malware on the computer can propose but never approve.

Signature checks and Shamir backups

Suite refuses firmware not signed by the manufacturer. Supported models can also split a backup into shares, so no single written copy restores the wallet alone.

Common Problems and Fixes

SymptomUsual causeWhat to try
Device not detectedCharge-only cable, or a bad portUse the supplied cable, try another port, avoid unpowered hubs
Web app sees nothingBrowser without WebUSBSwitch to a Chromium-based browser, or install Trezor Bridge
Permission prompt ignoredBlocked device accessReconnect, then allow the prompt; check site permissions
PIN pad does not appearStale Suite sessionFully quit and reopen the app, then reconnect
Wrong PIN warningWrong wallet unlockedRecheck carefully; the countdown grows and a wipe follows ten failures
Different addresses after unlockingA passphrase wallet behaving as intendedHidden wallets look empty by design — that is the feature
Untrusted firmware messageNon-genuine or corrupted buildDo not proceed; reinstall official firmware through Suite

Safe-Login Best Practices

Frequently Asked Questions

Can I log in to Trezor from any computer?

Yes. The device travels, the keys stay on the chip, and the software reads nothing more than what you approve. On a computer you do not trust, prefer the device's own touchscreen for PIN entry and always check the confirmation screen.

Why does the PIN appear on a shuffled keypad?

Because a fixed keypad would let malware record which positions you clicked and reconstruct the code. The device and the screen agree on a random layout that changes every time.

Is the passphrase the same as the PIN?

No. The PIN unlocks the device itself. The passphrase, typed at the wallet level, opens a hidden wallet derived from the same seed. Losing the passphrase loses that wallet permanently.

What happens if I enter the wrong PIN ten times?

The device wipes itself back to factory state. Your funds are untouched on the blockchain — restoring with the seed brings them back, which is why that seed must be backed up properly.

Do I ever need to enter my seed to log in?

Never. The seed is used once, during setup or recovery, typed on the device. Any page asking for it during a normal unlock is a phishing attempt.

Final Thoughts

Logging in to a hardware wallet is deliberately awkward in one way: it insists a human presses a button on a physical object. That friction is the security. Every convenient alternative — a stored password, an extension holding keys, a page that "verifies" your seed — trades away the thing you bought the device for.

Use the desktop application day to day, keep the web app for borrowed machines, confirm everything on the device screen, and keep the seed offline. Then the login becomes what it should be: a two-minute routine quietly protecting everything behind it.