Browser extension: fill approved records from a paired browser
The VaultPilot Browser Vault Extension pairs a named browser device with your VaultPilot server. An Owner approves and revokes each device in the VaultPilot console.
- Customer install
- Chrome Web Store
- Pairing
- Short-lived approval code
- Secret use
- After user action

A device gets access after console approval
In the extension, the user enters the VaultPilot server address, a username, a device name, and the extension PIN. The extension then shows a short-lived pairing code. An Owner approves that device on the Browser extension screen, which needs a writable license. Only then does VaultPilot give the device access to every vault unlocked in the approving profile, encrypted for that device alone.
The extension waits for you
Secrets are decrypted only in the active extension session, after you start an action. Extension storage keeps encrypted snapshots and wrapped keys. The extension PIN and the browser profile protect its private key material. Before filling, you still check the site and the account yourself.
Install from the Chrome Web Store
The supported customer path is the Chrome Web Store. Managed fleets can deploy the published extension ID through Chrome or Edge policy. The release ZIP is not a normal install path; keep it for lab tests or an emergency fallback.
Limits to know
- The extension does not fill forms on its own; every fill starts with a user action.
- A paired device is an endpoint. When it is lost, unused, or no longer trusted, you have to revoke it yourself.
- Requesting a Web Store update check does not make Chromium install an update right away.
- The device name is text the user typed. It does not verify which device sent the request.
Check step by step
Read more in the guides: Browser extension guide, Browser extension screen, Extension pairing remains pending