Flipper Zero Sub-GHz TPMS Tire Pressure Sensor Reading and Decoding
Every car built since the mid-2000s (and all US-market cars since 2008, under the TREAD Act) has tire pressure monitoring sensors broadcasting over sub-GHz RF, and the Flipper Zero's built-in CC1101 radio sits right in the frequency range those sensors use. This is a different animal from the garage-door and gate-remote sub-GHz work already covered elsewhere on this site: TPMS sensors use their own manufacturer-specific encodings, transmit identifying data alongside pressure and temperature, and raise a genuine privacy question that's worth understanding alongside the technical how-to.
How TPMS sensors actually transmit
Each TPMS sensor is a small battery-powered unit mounted inside the wheel, usually on the valve stem, that periodically transmits its unique sensor ID along with current pressure and temperature readings. Most sensors transmit on a slow heartbeat interval while the car is parked and switch to a much faster transmission rate once the sensor detects motion (via a built-in accelerometer), which is why you'll see far more activity scanning a moving car than a parked one.
RegionCommon frequencyNotes United States / most of North America315 MHzStandard for most US and many Asian-market vehicles Europe and most other regions433.92 MHzShared ISM band also used by many garage/gate remotes, so expect some RF neighborsWithin those frequencies, manufacturers (Schrader, Continental/VDO, Huf, Beru, and others, often supplying multiple car brands) use their own bit encoding and packet structure, so "receiving on 315MHz" and "decoding what the packet actually says" are two separate problems.
Finding and capturing a signal
- Start with the Flipper's Sub-GHz frequency analyzer to confirm where activity is actually happening near your vehicle — see the frequency analyzer and RSSI guide elsewhere on this site for the general technique of hunting down an unknown signal before committing to a capture.
- Once you've confirmed activity on 315 or 433.92 MHz, switch to Read/raw capture and either walk near each wheel to isolate that specific sensor's transmission, or physically deflate/reinflate a tire slightly to force an out-of-cycle transmission (many sensors send an extra report on a sudden pressure change, which is a reliable way to trigger a capture on demand).
- The Flipper's stock firmware does not include a built-in TPMS protocol decoder the way it does for many garage and gate remote protocols; check the app catalog's Sub-GHz category and community firmware (Momentum, Unleashed, and similar forks periodically bundle community-contributed protocol parsers) for a TPMS-specific decoding app, since protocol support here changes faster than this guide can track.
- If you have access to an RTL-SDR and the rtl_433 decoder project, running the same capture through it side by side is a good way to cross-check what you're seeing on the Flipper, since rtl_433 has broader out-of-the-box TPMS protocol support across more manufacturers.
Practical, legitimate uses
- Confirming sensor relearn after a tire rotation or sensor replacement — capturing each wheel's unique ID lets you verify the vehicle's TPMS module actually associated the right sensor with the right wheel position.
- Diagnosing an intermittent TPMS warning — comparing signal strength and transmission consistency across all four (or five) sensors on your own vehicle can help narrow down a flaky sensor before you pay a shop to diagnose it.
- RF reverse-engineering practice — TPMS is a genuinely useful real-world example of manufacturer-specific sub-GHz encoding, distinct enough from the fixed-code and rolling-code remotes covered elsewhere to be worth studying on its own.
The privacy angle
TPMS sensor IDs are static and unique per sensor, broadcast in the clear with no encryption or rotation. Published privacy research has demonstrated that a receiver positioned to repeatedly capture a specific vehicle's TPMS broadcasts can use that unique, unchanging ID to fingerprint and track that specific vehicle over time and location, independent of license plate visibility — the automotive equivalent of the tracking-device concerns already discussed in the Flipper Zero legal guide and the rogue Bluetooth tracker detection guide on this site. Scanning your own vehicle's sensors for diagnostic or educational reasons is exactly the kind of use this hardware is for. Positioning a receiver to log and re-identify other people's vehicles over time crosses into surveillance, and depending on jurisdiction and intent, into the same legal territory as other unauthorized tracking activity covered in this site's Flipper Zero and the Law guide.
Closing thoughts
TPMS decoding is a good next step once you're comfortable with the Flipper's general Sub-GHz workflow and want a protocol that isn't just another rolling-code remote — it touches real automotive engineering (TREAD Act-mandated sensors, accelerometer-triggered fast reporting) and a live privacy debate, all from hardware that's probably already parked in your driveway.