Skip to content

pymobiledevice3 restore

Restore/erase IPSWs, fetch blobs, and manage devices in Recovery/DFU.

shell

create an IPython shell for interacting with iBoot

pymobiledevice3 restore shell [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.

enter

enter Recovery mode

pymobiledevice3 restore enter [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.

exit

exit Recovery mode

pymobiledevice3 restore exit [OPTIONS]

restart

restarts device

pymobiledevice3 restore restart [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.

tss

query SHSH blobs

pymobiledevice3 restore tss [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.
-i, --ipsw <str> Path or URL to an IPSW. If omitted, choose a signed build interactively.
--out <path>
--behavior <Update\|Erase> Restore behavior to use when selecting the BuildIdentity. [default: Update]

preflight

Show the preflight data lockdown reports before a restore: PreflightInfo (each peripheral updater's identity fields and current nonce), FirmwarePreflightInfo (baseband) and ApParameters (AP and SEP nonces). Requires normal mode.

pymobiledevice3 restore preflight [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.

preflight-requests

Ask the device to build the TSS request of each peripheral updater for the given IPSW, the way restored does during a restore (restoreserviced getdevicesidepreflightinfo; needs a tunnel and uploads each updater's firmware to the device). Prints the requests, their ticket and manifest tags, and the updaters that failed.

pymobiledevice3 restore preflight-requests [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.
-i, --ipsw <str> Path or URL to an IPSW. If omitted, choose a signed build interactively.
--native macOS only: reach the iOS 17+ tunnel by piggybacking Apple's own remoted tunnel via the remotepairingd service. NO root, no entitlement, no Xcode, and remoted is left running (so it coexists with Xcode/devicectl). Rides Apple's kernel-routable tunnel, so throughput matches the kernel tunnel. Mutually exclusive with --rsd/--tunnel/--userspace. [env var: PYMOBILEDEVICE3_NATIVE]
--updater <str> Updater to query (repeatable); default: all of T200, Rose, SE, Vinyl, Savage, Centauri, Baseband except Baseband.

Accepts the connection options: --rsd, --tunnel, --userspace.

ramdisk

Boot only the update ramdisk without performing a restore (IPSW path or URL accepted).

pymobiledevice3 restore ramdisk [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.
-i, --ipsw <str> Path or URL to an IPSW. If omitted, choose a signed build interactively.

update

Update or restore the device using an IPSW (local path or URL).

pymobiledevice3 restore update [OPTIONS]

Options:

Option Description
--ecid <str> Target device ECID; defaults to the first connected USB device or waits for Recovery/DFU.
-i, --ipsw <str> Path or URL to an IPSW. If omitted, choose a signed build interactively.
--tss <path> Path to SHSH blob plist to use for signing requests.
--erase / --no-erase Erase and restore (factory reset) instead of updating in place. [default: no-erase]
--ignore-fdr / --no-ignore-fdr Connect to the FDR service only (debug mode; no traffic proxying). [default: no-ignore-fdr]
--tss-batch Opt-in: request the prefetchable peripheral tickets (SE/SE2, Rose, Savage, T200, Centauri, eUICC, Baseband) together with the AP ticket, in the same TSS request, and serve them during the restore whenever the device asks with the identical request (iOS 18+). Adds no request; chips whose nonce changed are signed live as usual.