Find your login.
Authenticate to see your directory: names, websites, and public login details. Select the entry you need.
A password manager with a physical boundary
Turn your Trezor into a password vault. Browse your logins in Chrome. Release a password only when you approve that specific entry on the device.
Development alpha For testing with dummy passwords. See release status.
READ LOGIN
Atlas workspaceReview this entry on your device.
Only public entry details are visible.
01 / HOW IT WORKS
Finding an entry and revealing its password are separate actions. The important decision happens in your hand.
Authenticate to see your directory: names, websites, and public login details. Select the entry you need.
The Trezor shows the stored identity of that entry. Enter a fresh device PIN and physically approve the request.
The extension receives that approved record. Opening another entry requires another approval on the Trezor.
A compromised computer can capture a password you release to it. The physical approval boundary is designed to prevent it from silently reading the rest of your vault. Understand the security model ↗
02 / IN YOUR HANDS
Your encrypted password database lives on the microSD card in your Trezor. The extension is your interface to it.
03 / EVERYDAY DETAILS
The conveniences of a password manager, with approval enforced by the firmware on your device.
Find matching accounts in the extension and approve an entry before filling it on a website.
Keep secure notes, recovery codes, payment cards, and other private fields in individually encrypted records.
The Chrome package communicates directly over USB. No native host or Trezor Bridge is needed.
Automatically hide sensitive information after 1–1,440 minutes, or keep it visible until its view is closed or refreshed.
Preview imports from supported exports, including Bitwarden, 1Password, KeePass, LastPass, and browser CSV files.
Website icons and public login details help you find the right entry. Favicons are handled by the extension.
04 / CHOOSE YOUR DEVICE
ByzanPass uses custom firmware and an encrypted microSD vault. Guided Chrome setup covers both models.
Touchscreen approval, haptic feedback, and secure-element PIN protection.
Safe 5 setupTouchscreen approval and encrypted microSD storage, without a secure element.
Model T setupUse a dedicated device. The ByzanPass firmware disables cryptocurrency wallet commands. Safe 3 and Safe 7 setup are not supported.
05 / GOOD QUESTIONS
No. Computer access and local device access are separate. To browse passwords directly on the Trezor, enter the master password on the device. A fresh PIN is still required for every new entry reveal.
It can read public metadata after authentication and capture anything you approve for release to it. It can also mislead you or interrupt a request. Always check the entry on the device. The design does not provide a bulk plaintext-read command for the vault.
Password-vault recovery requires a complete encrypted card backup and its 12 recovery words. Enter those words only on the replacement device. Passkeys and security-key credentials are device-only and are not restored from the password-vault backup. Read the recovery guide.
The Chrome WebUSB package connects directly to the device. Firefox is a separate integration and is not part of this direct USB setup guide.
Use a dedicated device. Changing firmware can wipe existing storage, and ByzanPass firmware disables wallet commands. Safe 5 bootloader unlocking is permanent and removes factory authenticity keys. Review the model-specific setup before proceeding.
It is a development alpha. Use dummy credentials while full physical acceptance, independent security review, and authenticated production distribution remain release requirements. See development status.
YOUR NEXT STEP
New vault, new computer, or restoring a backup?
Start with the path that fits you.