Every situation, step by step.
These paths are also available as a readable guide. Enable JavaScript to play them in the flow explorer.
An entry is approved+
Start with an authenticated directory. Follow one selected login from request to release.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
An entry always requires PIN+
The per-entry PIN flag overrides an Off hourly allowance.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Enter a fresh reveal PINAfter approval, enter the device PIN on the Trezor. A boot PIN or a previous reveal does not skip this check.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
Master re-authentication on the Trezor+
Choose the device keyboard when the entry requires the master password again.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Re-enter the master passwordChoose On the Trezor in the extension. Type the current vault master password on its touchscreen. A wrong password or cancellation releases nothing. If Always require PIN is also selected, a fresh device PIN is required as well.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
Master re-authentication in Chrome+
Choose the computer input for the same protected-entry check.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Re-enter the master password in the extensionChoose On this computer and type the master password in the trusted extension page. The extension derives a contribution for this request and does not store the password. A compromised computer can capture and reuse it; typing on the Trezor avoids that exposure.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
The hourly PIN allowance is used+
A device-wide Off–99 setting counts successful Chrome releases, not requests or directory access.
- Use the allowanceWith X selected, up to X successful new Chrome reveals are allowed without another PIN. Each still needs physical approval. Failed or cancelled reveals do not use the allowance. Off disables this quota.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Enter a fresh reveal PINAfter approval, enter the device PIN on the Trezor. A boot PIN or a previous reveal does not skip this check.
- Start a new allowanceA successful fresh reveal PIN resets the allowance. This successful read becomes its first reveal. Individual earlier reveals also expire after one hour of device time. Re-authenticating Chrome or switching computers cannot reset the device count.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
An entry is denied+
The computer can request an entry. The person holding the Trezor can refuse.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Deny the requestNo selected password is released. Directory access is separate from permission to read a private record.
The reveal PIN is cancelled or wrong+
When an entry requires PIN or the hourly allowance is used, approval alone cannot release it.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Enter a fresh reveal PINAfter approval, enter the device PIN on the Trezor. A boot PIN or a previous reveal does not skip this check.
- Stop before releaseA cancelled or failed fresh PIN stops this read. The approved record is not returned to the computer.
The approval times out+
An unattended request does not become an approval.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- The request expiresThe device approval has a time limit. If it expires, the read fails and a new request needs a new approval.
The entry or vault changes+
A stale or mismatched request cannot silently switch which record is released.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Reject a changed identity or versionAn identity or version mismatch is rejected. If the vault changes during approval, the final recheck also aborts the read. Refresh the directory before requesting the intended entry again.
The sensitive view closes or expires+
Receiving one record does not permanently authorize future reads.
- Choose one entryThe authenticated directory shows names, domains, usernames and emails. Its passwords and private fields are still protected.
- Send a request, not a passwordChrome communicates directly over USB. It requests one entry by its identity and version; no bulk password read is requested.
- Review the stored identityThe Trezor displays the selected entry’s stored identity. Check the website and account on the device, then physically approve or deny.
- Recheck and open that recordThe firmware checks that the vault has not changed and decrypts the captured, approved record. The authorization is limited to that one read.
- Receive one approved recordThe selected password and its private fields reach the extension. A compromised computer can capture them. Other records remain protected and need their own approval and configured protections.
- Remove the sensitive viewClose or refresh the view, lock it, or let its chosen viewing timeout expire. The extension removes that view’s sensitive values. This cannot erase a copy already captured by a compromised computer.
- Request it againOpening that entry again requires another physical approval and any configured protections. The Never option skips the viewing timer; closing or refreshing the view still ends it.
Unlock from the computer+
Authenticate the directory in Chrome while local device browsing stays locked.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Enter the master passwordThe extension derives the password contribution locally. A compromised computer can capture a master password typed into it. The device secret is not sent to Chrome.
- Approve directory authenticationThe Trezor asks AUTHENTICATE? before checking the password contribution. Approval opens directory access, not an individual password.
- Check the password and device secretOnly after device approval does the firmware open the master envelope and authenticate the encrypted directory. The vault key stays on the device.
- Browse the public directoryThe extension can list entries and request individual records. This computer unlock does not enable local password browsing on the Trezor; enter the master password on the device for that mode.
Unlock on the device, then use on PC+
Keep the master password off the computer by using the separate on-device unlock and handoff.
- Unlock locally on the TrezorEnter the master password on the device touchscreen. This is a separate authorization from typing it in the extension.
- Local browsing is enabledThe vault is now open for on-device browsing. Each new local password reveal still requires its entry approval and a fresh PIN.
- Ask to use it on this computerA paired extension can request directory access to the vault already opened locally. It does not receive the on-device master password.
- Hold to approve, then enter a fresh PINReview USE ON PC?, hold to approve and enter the device PIN. This grants computer directory access; individual records still need their own approval and any configured reveal protections.
- Two separately authorized modesLocal browsing remains authorized by the on-device master-password entry. The computer can browse public metadata and request one record at a time.
Directory authentication is denied+
A directory unlock request can be refused on the device.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Enter the master passwordThe extension derives the password contribution locally. A compromised computer can capture a master password typed into it. The device secret is not sent to Chrome.
- Approve directory authenticationThe Trezor asks AUTHENTICATE? before checking the password contribution. Approval opens directory access, not an individual password.
- Refuse directory accessThe firmware does not grant a computer directory session. This request releases no entry passwords.
Directory authentication times out+
A device prompt or failed transport exchange does not grant a session.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Enter the master passwordThe extension derives the password contribution locally. A compromised computer can capture a master password typed into it. The device secret is not sent to Chrome.
- Approve directory authenticationThe Trezor asks AUTHENTICATE? before checking the password contribution. Approval opens directory access, not an individual password.
- End the failed authenticationIf the device approval expires or the transport exchange fails, the extension does not treat the request as an authenticated session. Retry authentication after resolving the cause.
Restart Chrome or reload the extension+
Chrome WebUSB does not persist a remembered master key for a later browser session.
- Browse the public directoryThe extension can list entries and request individual records. This computer unlock does not enable local password browsing on the Trezor; enter the master password on the device for that mode.
- End the browser sessionThe extension clears its active access and sensitive views when its session ends. An encrypted directory mirror is only a disposable cache; it never authorizes a private-record read.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Authenticate againUse a fresh computer master-password unlock, or the separate Use on PC handoff if the vault was explicitly opened on the device. Each reveal still has its own device gates.
The master password is wrong+
Physical approval does not make an incorrect master password valid.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Enter the master passwordThe extension derives the password contribution locally. A compromised computer can capture a master password typed into it. The device secret is not sent to Chrome.
- Approve directory authenticationThe Trezor asks AUTHENTICATE? before checking the password contribution. Approval opens directory access, not an individual password.
- Credentials failThe master envelope does not open and no computer session is granted. Failed attempts are counted by the device’s password-attempt policy; delays or configured limits may apply.
A challenge is stale or replayed+
An old authentication exchange cannot create a fresh directory session.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Submit an obsolete exchangeThe request refers to a challenge that is no longer valid for the current authentication operation.
- Reject the stale requestThe device rejects it rather than granting fresh computer access. Restart the intended authentication flow.
Another application owns USB+
Chrome permission and an open device connection are different things.
- Allow Chrome USB accessSelect the Trezor in Chrome’s USB dialog. This permission allows a connection attempt; it does not authorize a password read.
- The interface cannot be claimedAnother Trezor application or connection may be using the interface. Close the competing connection and retry. A connection failure grants no new record approval.
The Trezor is at its PIN screen+
Unlock the device screen before trying to authenticate its vault.
- Open the extensionThe device is present, but its PIN screen is still locked. USB presence is not proof of vault access.
- Enter the PIN on the deviceThe PIN opens the device screen. It does not replace the vault master password, enable local vault browsing, or approve a record.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
A paired firmware fingerprint changes+
The extension requires the master password before recording acceptance of the changed firmware.
- Detect the changed fingerprintThe extension compares the connected device and firmware with the pairing history. A changed firmware image needs review.
- Verify what you installedCompare the image fingerprint and approve only an expected update. Local pairing history is a consistency check; it is not independent proof that firmware is safe.
- Verify the master password locallyEnter the master password in the extension to verify acceptance. This local check does not require a password change. A compromised computer can capture input or tamper with local checks.
- Return to My vaultOnce acceptance succeeds, the extension returns immediately to the main vault page. Authenticate as needed; no entry password was released by accepting firmware.
First setup · Safe 5+
A blank Safe 5 needs the model-specific preparation and permanent bootloader-unlock path.
- Inspect a dedicated Safe 5Use Chrome guided setup, a USB data cable and a microSD card. Preserve existing data before a firmware change.
- Prepare a blank Safe 5For a blank device, the guide installs pinned official preparation firmware, checks the image and factory identity where available, and guides its first boot without creating a wallet.
- Unlock the bootloaderExplicit bootloader unlocking is permanent. It wipes storage, removes factory authenticity keys and cannot be reversed.
- Install verified ByzanPass firmwareInspect again, install the pinned candidate when available, restart normally, acknowledge its warning, and verify the installed image. Failed checks stop setup.
- Create the vaultFollow the PIN, master-password, microSD and 12-word backup prompts. Record recovery words privately; never type a device PIN or recovery words into a browser.
- Pair and test a dummy entryPair this Chrome profile, authenticate and create a dummy login. Test its approval and configured protections. Back up the complete encrypted card directory.
First setup · Model T+
The Model T uses a direct custom-firmware path without the Safe 5 secure-chip preparation.
- Inspect a dedicated Model TUse Chrome guided setup, a USB data cable and a microSD card. Preserve existing data before a firmware change.
- Enter bootloader modeGuided setup requires bootloader 2.1.16 or newer. The Model T does not use the Safe 5 permanent bootloader-unlock step.
- Install verified ByzanPass firmwareInstall the pinned candidate when available, confirm on the device, restart normally, acknowledge the custom-firmware warning and verify the installed image.
- Create the vaultFollow the PIN, master-password, microSD and 12-word backup prompts. Record recovery words privately; never type a device PIN or recovery words into a browser.
- Pair and test a dummy entryPair this Chrome profile, authenticate and create a dummy login. Test its approval and configured protections. Back up the complete encrypted card directory.
Existing vault · new computer+
Keep the working device and current card. No restore or firmware reinstall is needed.
- Use the existing-vault pathInstall the extension on the new computer and keep the original device with its working card. Do not format or restore a working vault.
- Connect and pair this profileAllow Chrome USB access, unlock the device PIN if needed, and review device and firmware checks. Each browser profile has its own pairing history.
- Connect a paired deviceAllow USB access in Chrome and complete the pairing and firmware checks. If the Trezor is PIN-locked, unlock its screen on the device first.
- Enter the master passwordThe extension derives the password contribution locally. A compromised computer can capture a master password typed into it. The device secret is not sent to Chrome.
- Approve directory authenticationThe Trezor asks AUTHENTICATE? before checking the password contribution. Approval opens directory access, not an individual password.
- Browse the public directoryThe extension can list entries and request individual records. This computer unlock does not enable local password browsing on the Trezor; enter the master password on the device for that mode.
Replace a device · encrypted backup + words+
Recover the password vault using its complete encrypted card backup and matching recovery words.
- Prepare the replacementFollow the Safe 5 or Model T firmware path first. Keep the original backup untouched and choose Restore a backup.
- Copy the complete encrypted backupUsing a card reader, copy the entire /vault-v4 directory to a separate microSD card. The setup flow does not transfer card files over USB.
- Enter 12 words on the TrezorEnter the matching recovery words only on the device. The firmware authenticates the backup and asks for a new master password.
- Pair and check recovered entriesAn older backup restores an older snapshot. Every recovered reveal still needs device approval and any configured protections. Local reveals always require a fresh PIN. Device-only passkeys and security-key credentials are not restored.
Recovery words without a card backup+
Recovery words do not contain the password records.
- You have the recovery wordsThe words can recover the vault key, but do not store a copy of its entries.
- Find the complete encrypted backupRecovery cannot restore the missing password records without their matching encrypted files. Find the card backup before proceeding.
Import an existing password export+
Preview an export in the extension, then approve saving it to the encrypted vault.
- Open a supported exportUse Import passwords in an authenticated extension. The computer reads the imported values; encrypted KeePass files require their own database password.
- Preview the mapped entriesCheck names, domains and fields before saving. The default site match is exact host and subdomains. Keep secrets out of fields marked public.
- Approve the importFollow the device confirmations for the import. Approval authorizes writing the selected import; it does not provide bulk read access to the existing vault.
- Test and back upOpen one imported dummy entry to test its approval and fresh PIN. Make a new complete encrypted card backup after changes.