Item logo image for Carissa Authenticator

Carissa Authenticator

ExtensionPrivacy & Security
Item media 5 (screenshot) for Carissa Authenticator
Item media 1 (screenshot) for Carissa Authenticator
Item media 2 (screenshot) for Carissa Authenticator
Item media 3 (screenshot) for Carissa Authenticator
Item media 4 (screenshot) for Carissa Authenticator
Item media 5 (screenshot) for Carissa Authenticator
Item media 1 (screenshot) for Carissa Authenticator
Item media 1 (screenshot) for Carissa Authenticator
Item media 2 (screenshot) for Carissa Authenticator
Item media 3 (screenshot) for Carissa Authenticator
Item media 4 (screenshot) for Carissa Authenticator
Item media 5 (screenshot) for Carissa Authenticator

Overview

Request your verification codes from your phone and approve them with your fingerprint. Secrets never leave the phone.

Carissa Authenticator for Chrome brings your two-step verification codes from your phone to your computer, without ever copying your secrets to the browser. How it works 1. Link this browser once: open the extension, show the QR code and scan it with the Carissa Authenticator app (Settings › Linked browsers › Link browser). Both screens then show the same 6-digit confirmation code; the extension asks "Does your phone show this code?" — confirm it matches before the link is used for anything. 2. On a site that asks for a verification code, click the Carissa icon (or press Ctrl+Shift+L) and choose "Request code". 3. Your phone shows the site's domain in large type. Approve with your fingerprint or PIN. 4. The code is filled in on the page. If there is no code field, it is copied to the clipboard and shown in the extension. If you switched tabs in the meantime, it is only shown, so you can check where you paste it. Privacy and security - Your 2FA secrets never leave your phone. The extension never stores 2FA secrets or verification codes: on this device it only keeps the browser link's key (non-extractable) and a link token. When a code can't be filled in, it is copied to the clipboard as a fallback, and the clipboard is cleared when the code expires if the extension is still open. - Every request and answer is end-to-end encrypted between the extension and your phone (X25519, HKDF-SHA256, AES-256-GCM). Our server only relays encrypted messages and cannot see the site, the code or the account. - Pairing is verified with a secret that only travels inside the QR code, so not even our server can swap the keys. The matching confirmation code shown on both screens catches it if a link was ever claimed by the wrong phone: if the codes do not match, choosing "It doesn't match" cancels the link and nothing is requested. - Minimal permissions: the extension reads the address of the active tab when you open it (to show the site's domain) and its title when you ask for a code, and only talks to the Carissa server. - You can unlink the browser from the extension or from the app at any time. Requires the Carissa Authenticator app for Android (version 1.5.0 or later) with a Carissa account, and Chrome 133 or later. ``` **Descripción detallada — Español:** ``` Carissa Authenticator para Chrome lleva tus códigos de verificación en dos pasos del móvil al ordenador, sin copiar nunca tus secretos al navegador. Cómo funciona 1. Vincula este navegador una vez: abre la extensión, muestra el código QR y escanéalo con la app Carissa Authenticator (Ajustes › Navegadores vinculados › Vincular navegador). Las dos pantallas muestran entonces el mismo código de confirmación de 6 dígitos; la extensión pregunta "¿Tu móvil muestra este código?": confírmalo antes de que el vínculo se use para nada. 2. En un sitio que te pide el código de verificación, pulsa el icono de Carissa (o Ctrl+Shift+L) y elige "Pedir código". 3. Tu móvil muestra en grande el dominio del sitio. Apruébalo con tu huella o tu PIN. 4. El código se rellena en la página. Si no hay campo para el código, se copia al portapapeles y se muestra en la extensión. Si cambiaste de pestaña mientras tanto, solo se muestra, para que compruebes dónde lo pegas. Privacidad y seguridad - Tus secretos 2FA nunca salen del móvil. La extensión nunca guarda secretos 2FA ni códigos de verificación: en este dispositivo solo guarda la clave del vínculo del navegador (no extraíble) y un token del vínculo. Si un código no se puede rellenar, se copia al portapapeles como alternativa, y el portapapeles se vacía cuando el código caduca si la extensión sigue abierta. - Cada petición y cada respuesta van cifradas de extremo a extremo entre la extensión y tu móvil (X25519, HKDF-SHA256, AES-256-GCM). Nuestro servidor solo reenvía mensajes cifrados: no puede ver el sitio, el código ni la cuenta. - La vinculación se comprueba con un secreto que solo viaja dentro del código QR, así que ni nuestro servidor puede cambiar las claves. El código de confirmación que coincide en las dos pantallas detecta si alguna vez el vínculo lo reclamó el móvil equivocado: si los códigos no coinciden, "No coincide" cancela el vínculo y no se pide nada. - Permisos mínimos: la extensión lee la dirección de la pestaña activa al abrirla (para mostrar el dominio del sitio) y su título cuando pides un código, y solo habla con el servidor de Carissa. - Puedes desvincular el navegador desde la extensión o desde la app cuando quieras. Necesita la app Carissa Authenticator para Android (versión 1.5.0 o posterior) con una cuenta Carissa, y Chrome 133 o posterior. - EN: Request your verification codes from your phone and approve them with your fingerprint. Secrets never leave the phone. - ES: Pide tus códigos de verificación al móvil y apruébalos con tu huella. Los secretos nunca salen del teléfono.

Details

  • Version
    1.0.2
  • Updated
    October 3, 2026
  • Size
    40.05KiB
  • Languages
    2 languages
  • Developer
    Email
    abel@carissa.io
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Carissa Authenticator has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Carissa Authenticator handles the following:

Authentication information

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps