Caliptra
Caliptra IP and firmware for integrated Root of Trust block
Install / Use
/learn @chipsalliance/CaliptraREADME

Caliptra
Caliptra consists of IP and firmware for an integrated Root of Trust block.
Caliptra targets datacenter-class SoCs like CPUs, GPUs, DPUs, TPUs. It is the specification, silicon logic, ROM and firmware for implementing a Root of Trust for Measurement (RTM) block inside an SoC. A Caliptra integration provides the SoC with Identity, Measured Boot and Attestation capabilities.
Organizations
Caliptra is a project originally incepted at the Open Compute Project (OCP). The major revisions of the Caliptra specifications are published at OCP. The evolving source code and documentation for Caliptra live in this repository within the CHIPS Alliance Project, a Series of LF Projects, LLC.
Governance
The Caliptra WorkGroup Technical Charter sets out the charter governing the Caliptra project.
Trademark
- Caliptra Trademark Policy
- Caliptra Trademark Process definition
- Caliptra Trademark Checklist and Evaluation Methodology
Specifications
Caliptra 1.x:
- Main Caliptra specification 1.x
- Caliptra Core Hardware Specification
- Caliptra Core Hardware Integration Specification
- ROM 1.x
- FMC
- Runtime
Caliptra 2.x:
- Main Caliptra specification 2.0 - Version 1.0
- Caliptra Core Hardware Specification 2.0.1
- Caliptra Core Hardware Integration Specification 2.0.1
- Caliptra Subsystem Hardware Specification - Version 1.0rc1
- Caliptra Subsystem Integration Specification - Version 1.0rc1
- ROM 2.x - WIP
- FMC 2.x - WIP
- Runtime 2.x - WIP
- MCU Firmware and SDK specification - WIP
Versioning
Caliptra is released in independently versioned components: RTL, ROM, FMC and Runtime FW. They are all represented by 3 values: major.minor.patch (such as 1.0.2). The first 2 values, major.minor, correspond to a set of features caliptra supports. The patch value is incremented as new releases are made with bug fixes. Lastly, mutable firmware (FMC/FW) have security version numbers (SVNs) that are incremented as required by when addressing security-critical issues. These are specified with the label (svn/svn) for (FMC/FW) versions respectively.
Not all components necessarily need to be of the same major.minor version to be compatible. Details are below:
Caliptra 1.0
Compatible Configurations: | RTL | ROM | Runtime FMC/FW | | --- | --- | --- | | 1.0.x | 1.0.x | 1.0.x (0/0) |
Caliptra 1.1
Additional Features
- ECC HW performance enhancements*
- LMS HW acceleration*
- New Runtime commands
- Expanded PL0 contexts to 16
* Requires 1.1 RTL
Compatible Configurations:
| RTL | ROM | Runtime FMC/FW | | --- | --- | --- | | 1.1.x | 1.1.x | 1.1.x (0/0) | | 1.0.x | 1.0.x | 1.1.x (0/0) |
Caliptra 1.2
Additional Features
- Manifest-based Authorization
- Deferred retrieval of IDEV CSR**
- Self-signed FMC Alias CSR
- DPE export of CDI
- DPE max cert size increased to 6kB
** Requires 1.2 ROM
Compatible Configurations:
| RTL | ROM | Runtime FMC/FW | | --- | --- | --- | | 1.1.x | 1.2.x | 1.2.x (0/0) | | 1.1.x | 1.1.x | 1.2.x (0/0) | | 1.0.x | 1.0.x | 1.2.x (0/0) |
Caliptra 2.0
Additional Features
- Support ML-DSA Caliptra FW Signature
- Support OCP Recovery
- Support Caliptra Sub-System
- IDevID CSR HMAC Signing
- Crypto Offload Mailbox Services
*** Only RTL release versions 2.0.2+ should be used due to ROM compatibility requirements.
Compatible Configurations:
| RTL | ROM | Runtime FMC/FW | | --- | --- | --- | | 2.0.2+ | 2.0.x | 2.0.x (0/0) |
Caliptra 2.1
Additional Features
- Support ML-KEM in Adams Bridge
- Support for ML-DSA External-Mu mode in Adams Bridge
- Support OCP L.O.C.K.
- Support for AES DMA mode
- Caliptra Core mailbox size reduced to 16 KiB in subsystem mode
Compatible Configurations:
| RTL | ROM | Runtime FMC/FW | | --- | --- | --- | | 2.1.x | 2.1.x | 2.1.x (0/0) |
Test Dashboards
- Caliptra Software CI dashboard -- includes ROM
- Caliptra CPU DV coverage dashboard
Repositories
The Caliptra code base and documentation are split across several repositories:
| Repository | Areas of interest | Description | | ---------- | ---- | ----------- | | Primary repository | Issues, PRs, Security advisories | This repository, with admin boilerplate and docs | | Adams Bridge RTL | Issues, PRs, Security advisories | The primary repository with Adams Bridge Post-Quantum Cryptography hardware accelerator | | Caliptra RTL | Issues, PRs, Security advisories, internal registers, external registers | The primary repository with immutable RTL | | Caliptra Software 1.x | Issues, PRs, Security advisories | Caliptra software (ROM, FMC, runtime firmware), and libraries/tools needed to build and test | | Caliptra Software 2.x | Issues, PRs, Security advisories | Caliptra software (ROM, FMC, runtime firmware), and libraries/tools needed to build and test | | Caliptra DPE | Issues, PRs, Security advisories | An implementation of a TCG DICE Protection Environment profile | | Caliptra U-Reg | Issues, PRs, [Security advisories](https://github.com/chipsalliance/calipt
Related Skills
node-connect
350.1kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
frontend-design
109.9kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
openai-whisper-api
350.1kTranscribe audio via OpenAI Audio Transcriptions API (Whisper).
qqbot-media
350.1kQQBot 富媒体收发能力。使用 <qqmedia> 标签,系统根据文件扩展名自动识别类型(图片/语音/视频/文件)。
Security Score
Audited on Apr 6, 2026
