Use a password manager on a ticket's computer
Each ticket’s computer is a Chromium the board starts for that ticket, which you can watch and drive from the ticket view. You can load browser extensions into it, a password manager being the usual one, so a sign in on the computer can use your vault instead of you typing a password.
1. Add the extension in Settings
Section titled “1. Add the extension in Settings”Open Settings > Connections > Built in browser and set the session to Per ticket
computer. In Agent Browser Extensions, paste the extension’s Chrome Web
Store link (or just its id, the last part of that link) and press Add. The board
downloads it from the Web Store the way Chrome itself does, unpacks it into
~/.rev0/extensions/<id> and adds that folder to the list below the link. Press Save.
Any Web Store extension works this way, not only a password manager.
Installing from the Web Store inside the live view does not work, because Chrome’s “Add extension?” prompt is browser UI and never shows in the screencast. That is why the board does the download.
The list also takes an unpacked extension folder of your own: a folder with a
manifest.json at its top, one absolute path per line. Save checks each one.
This is set once for the board: every ticket’s computer loads these each time it starts. Delete a line to stop loading one. A computer that is already running keeps what it started with until you restart it (next step).
2. Sign in on the ticket that needs it
Section titled “2. Sign in on the ticket that needs it”Open the ticket’s computer (the monitor icon in the ticket view) and click the Extensions button next to the keyboard icon. Its menu lists each extension with its version and whether it loaded, and:
- Open shows the extension’s page in a new tab, where you sign in or unlock it. The agent’s tab stays as it was.
- Done with NordPass (or whichever is in front) closes that tab again.
- Restart to apply appears when Settings changed since this computer started. It restarts only this ticket’s computer; its logins stay.
- Manage in Settings goes back to the list.
How often you sign in depends on Share the computer’s sign-ins (see share one computer across tickets). With Per board (the default) or Every board, the tickets in that scope drive one shared browser, so you sign in to the password manager once and it stays signed in (and unlocked, if it was) for every ticket there. With Per ticket, each ticket’s computer starts with no extension data, so you sign in again on every ticket.
What keeps the agent away from the vault
Section titled “What keeps the agent away from the vault”These stop the everyday accident. None of them is a wall while the debugging port is open to this machine, which is why the vault you unlock is what really bounds the exposure.
- The agent’s browser results never show a password field’s value: a textbox whose label reads like a secret (password, PIN, one time code and so on) is redacted before the agent reads it, including in the snapshot files the browser saves. A field with no label is not caught.
- The agent’s browser cannot open a
chrome-extension://page, and any extension tab you left open is closed when the agent next connects. - The agent is told the password manager is yours, and to ask you when a sign in needs it.
Good to know
Section titled “Good to know”- Updating. Extensions on a ticket’s computer never update themselves. Paste the same
link again and press Add: the board replaces the folder in place, so the extension
keeps its id and every ticket stays signed in. A running computer picks it up on
Restart to apply, or the next time it starts. For a folder of your own, extract the
new version over the same folder: for an extension without a
keyin its manifest, the id comes from the folder path, so a new folder is a new extension, signed out on every ticket. - Desktop app unlock does not work. 1Password’s and Bitwarden’s desktop app integrations cannot reach a browser in its own profile. Sign in with the account itself (for 1Password: email, Secret Key and password).
- Some prompts stay invisible. Anything an extension asks through Chrome’s own UI, such as Bitwarden’s “make me your default password manager” Allow prompt, never shows in the live view. Choose Skip on those screens.
- Google Chrome stays the browser. Extensions load over the computer’s debugging connection, so the board keeps using installed Google Chrome, which sign in pages accept. The computer also presents a normal Chrome user agent rather than a headless one, and does not report itself as automated, so Cloudflare’s “Verify you are human” check passes on a click instead of coming back each time.