Getting started with device apps
This section covers how to build, test, and submit Rust and C apps, Ethereum plugins, and cloned-coin apps that run on Ledger signers.
Rust is mandatory for all new device app projects. C remains supported as a reference for teams that maintain existing C apps.
A device app is the on-signer software that signs transactions for a protocol. How you reach publication depends on whether you work with Ledger or develop on your own. Fill in this form to introduce the project. After we meet, we will point you to one of the two paths below.
Working with Ledger
You can sign a contract with Ledger for development of your device app and full support of your blockchain in Ledger Wallet. That path includes development of the device app with Clear Signing for transactions; integration into Ledger Wallet for the features defined in the statement of work and the relevant wallet services; ongoing maintenance and updates of the integration; mandatory security audits for each device app update, managed within Ledger’s process; and direct collaboration with Ledger’s engineering team.
Developing on your own
If an agreement with Ledger is not feasible, you can still develop a device app on your own. Every device app must pass a security audit before it can appear on the Ledger Wallet My Ledger app list. You will build a device app that works with third-party wallets. Users will not be able to manage their assets in Ledger Wallet unless an agreement is signed later.
Before publication, the app must go through a functional and security audit. An approved partner performs the audit, at your expense. Both partners follow Ledger specifications and deliver a full report that includes potential vulnerabilities. When the app is ready, contact one of these partners: Coinspect or Quarkslab (qb_ledger@quarkslab.com).
Make sure the device app meets the requirements and is fully tested before you start a security audit.
When you contract with an auditor, align on when the audit can start, the cost (entirely at your expense), and maintenance. Include a clause for updates, or plan to sign a new contract for major updates. Otherwise Ledger will not update your app, and it may be delisted from My Ledger if it becomes incompatible. Ledger is not a party to the contract between you and the auditor.
Tools and languages
The VS Code extension guide walks through environment setup, building, and tests. For project scaffolding, use the app boilerplate (Rust is mandatory for new projects; C is kept as a reference for existing apps), the Ethereum plugin walkthrough, or the cloned coins process.
To load Ledger’s embedded coding rules in your repository for GitHub Copilot, Cursor, and compatible agents, see the ledger-app-ai-instructions repository.
Ledger OS is written in C. Applications use Rust for new projects and C only for existing projects. Plugins use C. Tools, including tests, are mostly Python. CI GitHub Workflows use YAML. App manifests use TOML in ledger_app.toml. The app database uses JSON.
Main takeaways
Rust is required for new device apps. Publication on My Ledger always requires a partner security audit. Working with Ledger is what unlocks first-class Ledger Wallet support. Autonomous development still produces a signer app that third-party wallets can use.