ByzanPass. Get started

SETUP & RECOVERY / START HERE

Your vault.
Your next step.

Choose what you’re doing. The Chrome extension guides the device steps; this page helps you prepare.

Installing the extension
Your device
NEW VAULT

Start with a dedicated device.

You’ll need a supported Trezor, a USB data cable, a microSD card, Chrome, and somewhere private to write recovery words.

Before changing firmware

Preserve any existing wallet or vault. Firmware changes can erase device storage. ByzanPass is custom firmware with wallet commands disabled. Test with dummy passwords during the alpha.

  1. Install the Chrome development extension.

    Open its full vault page and select Setup & help → New vault. See the extension installation details below.

  2. Connect and inspect your Trezor.

    Use a USB data cable and approve Chrome’s USB selection dialog. Keep only the intended device connected. Close other Trezor applications if the connection is busy.

  3. Follow your model’s firmware path.

    For a blank Safe 5, guided setup installs the pinned official preparation firmware first. Restart normally and finish its first boot without creating a wallet. The guide checks the installed image and factory identity where available.

    Next, enter bootloader mode and explicitly unlock it. This is permanent, wipes storage, removes factory authenticity keys, and cannot be reversed. After fresh inspection, the guide can install the pinned ByzanPass image when that candidate is available.

    A Model T installs the pinned ByzanPass image directly in bootloader mode when that candidate is available. There is no Safe 5 secure-chip preparation or permanent bootloader-unlock step. Guided setup requires bootloader 2.1.16 or newer.

    The extension shows the image fingerprint and asks for device confirmation. After installation, restart normally, acknowledge the custom-firmware warning, and reconnect in Chrome for the installed-image check.

  4. Create the vault and recovery backup.

    Follow the device prompts for its PIN, master password, microSD vault, and 12 recovery words. Write the words privately. Never enter a device PIN or recovery words into this website or a browser page.

  5. Pair, authenticate, and test one entry.

    Pair the device with this Chrome profile. Add a dummy login and test its approval and PIN flow. Keep a complete encrypted backup before storing anything important.

EXISTING VAULT / NEW COMPUTER

Connect. Pair. Authenticate.

If your original device and its current card work, you do not need to restore, format, or reinstall firmware.

  1. Keep your device and its current card together.

    Install the Chrome extension on the new computer. Open its full vault page and choose the existing-vault setup path.

  2. Allow USB access in Chrome.

    Connect your Trezor and select it in Chrome’s USB dialog. If the Trezor is at a PIN screen, enter the PIN on the device.

  3. Pair this browser profile.

    Review the device and firmware consistency checks. A new Chrome profile has its own pairing and firmware-approval history. Confirm a firmware change only if you installed and verified it.

  4. Authenticate to the directory.

    Enter the vault master password in the extension and approve on the device. If you already opened the vault locally, the device’s Use on PC path provides a separate PIN-and-approval handoff.

  5. Open one entry.

    Review its identity on the device, enter a fresh PIN, and approve. Extension authentication does not grant local password browsing on the Trezor.

RESTORE A BACKUP

First, identify what you have.

Recovery words, encrypted backups, and readable exports have different roles. Choose the matching path before changing a device.

Original device + current card

No restore needed. Connect and pair on this computer.

Encrypted backup + 12 words

Prepare a replacement Safe 5 or Model T, then recover the password vault on the device.

A readable password export

Create a new vault, then use Import passwords in the extension. Preview and approve the import.

Recovery words only

The words contain no records. You also need the complete encrypted card backup.

  1. Prepare the replacement device.

    Follow the for your model. In the extension’s setup guide, choose Restore a backup.

  2. Copy the full encrypted backup to a card.

    Use a card reader to copy the complete /vault-v4 directory onto a separate microSD card. Setup does not transfer card files over USB. Preserve the original backup.

  3. Recover on the Trezor.

    Choose recovery and enter all 12 words on the device touchscreen. It authenticates the backup and asks for a new master password. The browser never needs the words.

  4. Check your recovered records.

    An older backup restores an older snapshot. Opening each recovered entry still requires its own PIN and approval. Passkeys and security-key credentials are not included in this recovery.

Protect the pair, separately.

Anyone with both the complete encrypted backup and its recovery words has enough material to recover the password vault. Keep them in separate, protected places.

This guide describes the current development flow. Candidate availability and checks are enforced by the extension. Never bypass a failed check to follow a web page.

CHROME EXTENSION

Direct USB.
No companion app.

The WebUSB package works directly with the device. You do not need a native host or Trezor Bridge for this Chrome path.

DEVELOPMENT PREVIEW

Public download is not available here yet.

The project currently uses development packages. A public Chrome Web Store listing and authenticated release download have not been configured for this site.

Review distribution status →

With a project-provided development package

  1. Unzip the Chrome WebUSB package into a folder you will keep.
  2. Open chrome://extensions and enable Developer mode.
  3. Choose Load unpacked and select the folder containing manifest.json.
  4. Open ByzanPass, then its full vault page. First installation opens guided setup.

Install only a package whose source and hashes you have verified. This website does not request USB access or install firmware.

BEFORE YOUR FIRST REAL PASSWORD

Know the boundary.

Understand what the device protects and what an approved release exposes.

Read the security model