WorkSilicon

esp32-seed

ESP32 firmware framework: signed updates, Wi-Fi, storage, time sync and web admin, built in.

Released2026

ECDSA P-256
signed over-the-air updates, verified while they stream in; each device generates its own secrets on first boot
AP + STA
Wi-Fi with captive-portal setup, and a recovery access point after three quick power cycles
LittleFS + NTP
a filesystem with daily audit logs, and network time sync with a fallback
Web admin
built in: dashboard, settings and firmware updates, on ESP32, S3, C3 and C6 chips. Add your application on top.
The esp32-seed stack, bottom to top: ESP32 hardware; ESP-IDF, FreeRTOS and the Arduino core; seed services (signed OTA, Wi-Fi AP and STA, filesystem, time, web admin); your application.

esp32-seed is our way of giving back to the technical community. Every connected device needs the same core functions: a way to receive updates, join Wi-Fi, store files, keep time, be managed and recover when something goes wrong. esp32-seed packages them as a secure baseline, built to the practices expected of enterprise products at Fortune 500 companies, so anyone building on an ESP32 can focus on their own business logic rather than on the integrity and safety of the device underneath.

A new device works before the first line of product code: Wi-Fi setup through a captive portal, signed over-the-air updates, a filesystem with daily audit logs, network time sync with a fallback and a web admin. Firmware images are signed offline with ECDSA P-256 and verified on the device as they stream in; an unsigned or tampered image is rejected and the running firmware is left untouched. Update authentication is a challenge-response, so the password never crosses the network, and nothing secret is compiled in: each device generates its own credentials on first boot. Three quick power cycles open a recovery access point for ten minutes.

The design starts from a threat model and records what it deliberately leaves out, such as secure boot and flash encryption, and why. Alongside the code is a 1,134-line playbook of embedded practice, drawn from real incidents in sprinklerd and Oshkidar, the two devices the baseline was extracted from. The code is public on GitHub.