[DOC] Wallet interface reference
Trezor Suite explained, from first setup to daily use
Trezor Suite is the official companion application for Trezor hardware wallets: a free, open-source interface for Windows, macOS, Linux and the browser that turns a small signing device into a workable portfolio manager. It lists accounts and balances, builds and broadcasts transactions, installs firmware, verifies backups, and routes optional buying, selling, swapping and staking through third-party partners.
Because the wallet's secrets never leave the hardware, Trezor Suite is best understood as a viewer and a transaction builder rather than a wallet in its own right. Anything it prepares only becomes valid once you check it on the device screen and press the physical buttons or touch panel. That split of duties is the whole point, and it shapes almost every design decision in the app.
This page covers what Trezor Suite does, how the desktop, web and mobile builds differ, how to install and initialize it, which privacy and security controls are worth switching on, what it will not do for you, and the questions that come up most often once coins are actually moving.
[SEC-01]
What Trezor Suite is and who it is for
Trezor Suite is developed by SatoshiLabs, the Prague company that shipped the first Trezor device in 2014. The application arrived in 2021 as the successor to the older browser-based wallet interface, consolidating what used to be several separate tools: a coin wallet, a firmware updater, a device setup page and a handful of add-ons. Everything now lives behind one dashboard, and a single connected device unlocks all of it.
The intended user is anyone holding crypto on their own hardware rather than on an exchange. A beginner uses Trezor Suite for the guided setup, the backup wizard, and a plain send and receive screen. A more experienced holder uses the same app for coin control, replace-by-fee, Tor routing, custom backends and multiple hidden wallets. The interface tries to keep the advanced machinery out of the way until you go looking for it in settings.
It helps to name the three jobs Trezor Suite performs. First, it reads the blockchain: it asks backend servers for the history and balances belonging to your public keys. Second, it composes: it assembles unsigned transactions from the inputs and fees you choose. Third, it administers the device: PIN, passphrase, labels, firmware, backup checks and factory reset all run through it. What it does not do is hold, generate or transmit private keys.
There is no account to create and no subscription. Trezor Suite is free software published under an open-source license, and its source code is public, which means the claims about what it sends and where can be checked by people who are not employed by the vendor. For a general background on the hardware itself, the Trezor entry on Wikipedia is a reasonable neutral starting point.
0.00
Free to download and use
3
Desktop, browser, mobile companion
0
Private keys stay on the device
OPEN
Publicly auditable codebase
[SEC-02]
Desktop, browser and mobile versions compared
Trezor Suite ships in three shapes, and choosing the right one matters more than most people expect. The desktop application is the full build: you download an installer for Windows, macOS or Linux, it talks to the device over USB through its own bundled transport layer, and it contains the privacy features that a web page simply cannot offer. If you use one version regularly, use this one.
The browser version of Trezor Suite exists for machines where installing software is awkward, and it communicates with the device through WebUSB in Chromium-based browsers. It is convenient and it is genuinely useful in a pinch, but it inherits every weakness of the web: you are trusting whatever your browser loaded that day, extensions can interfere, and a phishing lookalike page is a real category of attack. Bookmarking the address after your first visit, and treating search-engine results for wallet software with suspicion, is basic hygiene.
Trezor Suite Lite is the mobile companion for iOS and Android. It is deliberately watch-only: it tracks balances and portfolio value using public keys you pair from the desktop app, and it cannot sign or broadcast anything. That restriction is a feature, since checking a balance on a phone is a low-risk activity while signing from one is not.
| Capability | Desktop app | Browser version | Suite Lite (mobile) |
|---|---|---|---|
| How you get it | Signed installer | Loads in browser | App stores |
| Device connection | USB, bundled transport | USB via WebUSB | None (public keys) |
| Sign and broadcast | Yes | Yes | No |
| Firmware updates | Yes, recommended | Supported | No |
| Built-in Tor toggle | Yes | No | No |
| Own node as backend | Yes | Available in settings | No |
| Best suited to | Regular use | Borrowed computers | Balance checks |
[SEC-03]
How the app and the device divide the work
When you unlock a device, Trezor Suite asks it for extended public keys, one per account. From those it can derive every address that account will ever use, which is enough to look up history and compute a balance without ever touching a secret. This is why the app can show you a full portfolio while being, cryptographically speaking, powerless.
Sending works in three moves. Trezor Suite gathers your recipient, amount and fee, selects coins to spend, and hands the unsigned transaction to the device. The device shows the destination and the amount on its own screen, which is the part that defeats malware on the host computer, since a compromised app can lie to you but it cannot change what the hardware displays. Once you approve, the signature comes back and Trezor Suite pushes the finished transaction to the network.
Blockchain data reaches Trezor Suite through backend indexers rather than a full node bundled in the app. By default those are servers operated by the vendor, running open-source indexing software. The trade-off is worth naming plainly: those servers learn which addresses you are interested in and from which IP address, even though they never see keys. Both of the privacy controls described below exist to blunt exactly that.
Labels, account names and other notes are metadata that lives outside the blockchain. Trezor Suite keeps this data encrypted with a key derived from the device, stored locally by default, with an option to sync it to your own cloud storage so it follows you between machines. If you skip that step, expect a fresh installation to show unnamed accounts and no transaction notes.
[SEC-04]
How to get started
First-time setup is a genuine sequence, and the order protects you. Trezor Suite guides new devices through it automatically, refusing to show a receive address until a backup exists.
-
01
Install the application
Download the desktop build from the vendor's own site, never from an ad or a mirror, and verify the signature if you know how. Trezor Suite runs on current versions of Windows, macOS and Linux.
-
02
Connect and install firmware
New devices ship without firmware. Trezor Suite detects the blank device, checks its authenticity, and installs the current official firmware before anything else happens.
-
03
Create a wallet and write the backup
The device generates the recovery seed itself and shows the words on its own screen. Copy them onto the supplied cards by hand. Never type them into Trezor Suite, a phone, a photo or a password manager.
-
04
Set a PIN and name the device
The PIN protects a device that is physically stolen. Trezor Suite then lets you label the device, pick a display currency and switch on the coins you actually hold.
-
05
Test with a small amount
Receive a token amount, send part of it back, and confirm both appear as expected. This single rehearsal in Trezor Suite catches address mistakes and misunderstandings while nothing is at stake.
Migrating an existing seed works the same way in reverse: choose recovery instead of create, and enter the words using the device, not the computer. Trezor Suite will scan for accounts across supported networks and rebuild the portfolio from public keys alone.
Critical alert
No legitimate part of Trezor Suite, and no support agent, will ever ask for your recovery seed. Any prompt to type all your words into a screen, an email or a chat is an attack, without exception. Trezor Suite only asks you to confirm words on the device during a backup check.
[SEC-05]
Everyday features you will actually use
Dashboard and accounts
The dashboard aggregates every enabled account into one value in your chosen fiat currency, with a chart of portfolio history and a feed of recent activity. Below it, Trezor Suite lists accounts individually, and for Bitcoin it distinguishes account types by address format, so a Taproot account, a native SegWit account and a legacy account appear as separate entries derived from the same seed. Adding another account of the same type is a two-click operation once the previous one has been used.
Receiving safely
Receive addresses are always shown on the device as well as in the window, and Trezor Suite asks you to compare them. This matters because address-swapping malware is one of the few attacks that works even with perfect key storage. The app also generates a fresh address per request for Bitcoin, which is a privacy habit rather than a technical necessity.
Sending, fees and coin control
Fee selection offers preset levels with estimates plus a custom rate for people who prefer to argue with the mempool themselves. For Bitcoin, Trezor Suite supports replace-by-fee, so a transaction stuck at a low rate can be bumped rather than abandoned, and it exposes coin control, letting you choose which specific unspent outputs to spend. Ethereum-type networks get their own controls for gas limit and gas price, along with a nonce visible to advanced users.
Labels, exports and viewing options
Accounts, transactions and addresses can all carry your own labels, which makes an old history readable months later. Trezor Suite can export transaction data for accounting, and discreet mode blurs every balance with a single toggle, which is a small feature that earns its keep on trains and in offices. Themes, language and the choice between fiat and crypto denominated display sit in the same settings area.
Message signing and verification round out the toolkit, useful when a service asks you to prove control of an address. As with everything else, the signature is produced by the hardware after an on-device confirmation, and Trezor Suite is only the courier.
[SEC-06]
Privacy controls worth switching on
Privacy in a hardware wallet setup is mostly about network metadata, not about keys. Trezor Suite therefore ships two controls that address the two leaks that matter: who sees your IP address, and who sees which addresses you are watching.
The first is a Tor switch in the desktop build. Turn it on and traffic to the backends is routed through the Tor network, so the servers see an exit node rather than your home connection. Expect slower loading and the occasional failed request, which is the normal cost of onion routing rather than a bug in Trezor Suite.
The second is the custom backend setting. If you run your own Bitcoin node with a compatible indexer, you can point Trezor Suite at it and stop asking anyone else about your balances. This is the strongest privacy configuration available in the app, and it also removes a dependency: your wallet keeps working even when third-party servers are down.
Coin control belongs in this section as much as the previous one. Deliberately avoiding the merge of unrelated coins in one transaction limits what a chain analyst can conclude about your holdings, and Trezor Suite gives you the per-output view needed to do it. Paired with fresh receive addresses and a separate account for anything publicly linked to your name, it goes a long way.
One historical note prevents confusion: Trezor Suite offered a Bitcoin CoinJoin feature for a period beginning in 2023, provided through an external coordinator. That coordinator was shut down by its operator in 2024, and the feature is no longer part of the app. If you find older tutorials describing it, they are out of date.
[SEC-07]
Security model, backups and device administration
The core assumption is that your computer may be compromised. Under that assumption, Trezor Suite can be tricked into showing you nonsense, but it cannot move funds, because every spend requires a confirmation rendered by the device on hardware you trust more than the host. Reading the device screen carefully is not a formality; it is the security model in action.
The PIN defends against physical theft, and the passphrase feature does something different and more interesting. Entering a passphrase produces an entirely separate wallet from the same seed, and Trezor Suite treats each one as a distinct hidden wallet with its own accounts and balances. There is no list of passphrases anywhere, no recovery if you forget one, and no way to prove that another one exists. Powerful, and unforgiving.
Backups are where most real losses originate, so Trezor Suite includes a backup check that walks you through confirming your recorded words against the device. Newer devices also support multi-share backups, splitting the secret into several shares of which a threshold is required, and Trezor Suite offers that path only where the connected firmware supports it. Whichever scheme you choose, the physical storage question remains yours: fire, water, moving house and curious relatives are the real threat model for a paper card.
Firmware management runs entirely through the app. Trezor Suite verifies that the firmware image is officially signed before installing it and warns you when an update is available. It also checks device authenticity when you connect, which is a defense against supply-chain tampering and counterfeit hardware, and it will tell you loudly if something looks wrong. Buying only from official channels remains the best version of that protection.
For a device you no longer want to use, the wipe function in Trezor Suite clears the secret from the hardware. Anyone reselling or gifting a device should do this, and anyone buying second-hand hardware should assume that a seed given to them alongside it is already known to someone else.
Recovery reality check
Your funds depend on the seed, not on the app or the device. If the hardware is lost, drowned or crushed, the backup restores everything onto a replacement, and Trezor Suite will rediscover the accounts. If the backup is lost while the device still works, move the funds to a freshly initialized wallet immediately rather than hoping nothing goes wrong.
SECURITY CHECKLIST / TREZOR SUITE [SEC-A] seed written by hand, never typed into any app [SEC-B] PIN set, passphrase understood before use [SEC-C] firmware installed only via Trezor Suite prompts [SEC-D] receive address compared on device screen, every time [SEC-E] installer taken from the official source, not a search ad
[SEC-08]
Coins, tokens, staking and trade services
Trezor Suite has native support for Bitcoin and a set of major networks including Ethereum, Litecoin, Bitcoin Cash, Cardano, XRP, Dogecoin and Solana, plus tokens on the networks that have them, such as ERC-20 assets on Ethereum. Coin support depends on both the app and the firmware of the connected device, so an older model will show a shorter list. The marketing figure of thousands of supported assets refers to what the hardware can hold across all compatible software, not to what Trezor Suite displays natively.
Assets outside the native list are usually handled by pairing the device with a third-party wallet interface, which continues to work while keys stay on the hardware. In that arrangement Trezor Suite remains your tool for firmware, backups and Bitcoin, and the external interface handles the exotic network. Doing so means trusting that other application's screens, so the same habit applies: read the device, not the window.
Staking is available for a few proof-of-stake assets, with Trezor Suite acting as the front end for delegation while your keys never move. Ethereum staking is provided through an integrated third-party validator service, and Cardano delegation is handled natively. Rewards, lock-up behavior and unstaking delays are properties of the network and the provider rather than of Trezor Suite, so read the terms in the app before committing funds.
Buying, selling and swapping inside Trezor Suite works through an aggregator of external providers. You compare quotes, choose a provider, and complete identity checks with that company directly, since Trezor Suite is not the counterparty and does not custody anything in the process. Rates and fees are theirs, availability depends on your country, and an exchange account remains a perfectly valid alternative if you prefer to keep trading and storage separate.
[SEC-09]
Practical guidance when something misbehaves
The most common complaint is a device that is not detected. In the great majority of cases the cause is physical: a charge-only USB cable, a hub without enough power, or a worn connector. Swap the cable for the one that came in the box, plug directly into the machine, and let Trezor Suite scan again before assuming anything is broken.
The second most common is a conflict over who owns the USB connection. Only one application can talk to the device at a time, so an open browser tab with another wallet, or a leftover standalone bridge process from years ago, will block the desktop app. Close the competing software, then reconnect. On Linux, missing udev rules are the usual culprit, and Trezor Suite documentation covers the one-time fix.
Balances that look wrong are usually a display or discovery issue rather than a loss. Check that you are in the right hidden wallet, since a passphrase typo silently opens a different empty wallet; check that the account type matches the addresses you used; and if you have enabled Tor or a custom backend, try switching it off briefly to see whether Trezor Suite is simply failing to reach its data source. A stalled transaction, by contrast, is a fee problem, and replace-by-fee is the tool for it.
Keep updates deliberate rather than automatic in spirit: install firmware and Trezor Suite updates when you have your backup at hand and time to read the prompts, not thirty seconds before you need to send something. Nothing about an update should require your seed, but having it nearby turns a rare glitch from a crisis into an inconvenience.
[SEC-10]
What Trezor Suite does not do
Trezor Suite is not a custodian, an exchange or an insurer. There is no password reset, no support ticket that can recover a lost seed and no fraud department to reverse a payment you approved. That is the deal you accept in exchange for holding your own keys, and it is worth stating clearly before the first deposit rather than after a mistake.
It is also not a full node, not a general web3 browser, and not a portfolio tracker for assets held elsewhere. Trezor Suite shows what your device controls on supported networks, using data from a backend, and it deliberately keeps the surface area small. Complex on-chain interactions, DeFi positions and unusual tokens live in other applications that you connect the hardware to.
Finally, Trezor Suite cannot protect you from approving the wrong thing. It can show the address, force a confirmation on hardware and warn about suspicious situations, but the decision to send is human. Most losses in self-custody come from bad backups, phishing sites and hasty confirmations rather than from broken cryptography, and no interface, including this one, closes that gap for you.
[SEC-11]
Frequently asked questions
Does Trezor Suite cost anything?
No. Trezor Suite is free, and there is no account or subscription. You pay for the hardware once, and any fees you encounter later are network fees or charges from third-party trade providers inside the app.
Do I have to use it with my device?
Not for everything, but practically yes. Other wallet applications can drive the hardware for sending and receiving, while firmware updates, backup checks, passphrase management and device settings are handled by Trezor Suite, which makes it the tool you will come back to.
Can it see or store my private keys?
No. Trezor Suite works from extended public keys, which reveal balances and history but cannot authorize a spend. Keys are generated on the device, stay there, and every signature is produced inside it.
Is Trezor Suite open source?
Yes, the code is published openly, as is the device firmware. That does not guarantee an absence of bugs, but it does mean independent researchers can inspect what Trezor Suite sends, to whom and when.
What if the company disappears?
Your recovery seed follows open standards, so it can be restored in compatible third-party wallets without Trezor Suite or the original hardware. Independence from any single vendor is exactly why the standardized backup exists.
Does using it require identity verification?
Not for wallet functions. Receiving, sending, staking setup and device administration in Trezor Suite involve no registration. Identity checks appear only if you choose to buy, sell or swap through an external provider, and you complete them with that provider.
Can I check balances without plugging in the device?
The desktop and browser versions expect a connected device to unlock a wallet. For a look at balances without carrying hardware, Trezor Suite Lite on a phone tracks your accounts in watch-only mode, and because it cannot sign anything, it stays a safe place to glance at numbers.