Item logo image for Family Pass

Family Pass

ExtensionHousehold20 users
Item media 4 (screenshot) for Family Pass
Item video thumbnail
Item media 2 (screenshot) for Family Pass
Item media 3 (screenshot) for Family Pass
Item media 4 (screenshot) for Family Pass
Item video thumbnail
Item video thumbnail
Item media 2 (screenshot) for Family Pass
Item media 3 (screenshot) for Family Pass
Item media 4 (screenshot) for Family Pass

Overview

暗号化ファイルをGoogleドライブ等の共有フォルダ経由で同期する、Family向けパスワードマネージャー

# Family Pass Googleアカウントが異なるFamily間で、パスワードを安全に共有・同期できるChrome拡張機能です。 ## 仕組み - パスワードは暗号化され、マスターパスワードから鍵を導出します。 - 暗号化された保管庫ファイル(`family-vault.fpass`)を **Googleドライブ等の共有フォルダ** に置き、各自のChromeから読み書きすることで同期します。 - ファイルの中身は常に暗号化済みなので、Googleや第三者に平文パスワードが渡ることはありません。 - 変更はエントリ単位で「新しい方が勝つ」方式でマージされ、削除もFamily間で伝播します。 ## 前提 - Google ドライブ(パソコン版)/ Dropbox / OneDrive など、**共有フォルダがパソコン上のフォルダとして同期されている**こと。 - Family全員が **同じマスターパスワード** を使うこと(忘れると復元不可)。 - **異なるマスターパスワードで作成された共有ファイルは利用できません**。利用するには拡張機能を再インストールし、そのファイルに合ったマスターパスワードを設定し直してください。 ## インストール 1. このフォルダ(`family-pass`)を任意の場所に置く 2. Chromeで `chrome://extensions` を開く 3. 右上の「デベロッパーモード」をON 4. 「パッケージ化されていない拡張機能を読み込む」→ `family-pass` フォルダを選択 ## セットアップ ### 最初の1人 1. ツールバーのアイコンをクリック → マスターパスワードを決めて入力(8文字以上) 2.設定→「新しい共有ファイルを作成」→ **共有フォルダの中**に `family-vault.fpass` として保存 3. ポップアップに戻り「同期」を押す ### 他のFamily 1. 共有フォルダがパソコンに同期されていることを確認 2. 拡張機能をインストール →設定→「既存の共有ファイルを選択」→ 共有フォルダ内の `family-vault.fpass` を選択 3. ポップアップで **同じマスターパスワード** を入力してロック解除 ## 日常の使い方 - **登録**: 「+ 新規登録」でサイト名・ID・パスワード等を保存(ログインページで開くとサイト名とURLが自動入力されます)。URLは http:// または https:// のものだけ登録できます - **自動入力**: 登録済みサイトのログインページで アイコンを開くと、一致する登録が先頭に「設定入力」ボタン付きで表示されます。押すとID/パスワードがフォームに自動入力されます(URL欄にそのサイトのURLを登録しておくことが条件) - **利用**: 一覧から開いてコピーも可能 - **同期**: 登録・変更後や、Familyの変更を取り込みたい時に「同期」を押す - **ロック**: デフォルトではブラウザを終了すると自動的にロックされます ## ロック設定 $2699$FE0F(設定)→「ロック設定」で、ロック解除の維持期間を選べます。 - **ブラウザを終了するとロックする(Default)** - **ロック解除を維持**: 1時間 / 3時間 / 6時間 / 1日 / 3日 / 1週間 / 2週間 / 1カ月 / 半年(6カ月) / 無期限 から選択 - 期間を選ぶと**維持期間終了日時**が表示されます(分以下は切り捨てて00分) - 1カ月以上(無期限を含む)に設定する場合は、マスターパスワードの確認が必要です - 維持期間を設定した後にブラウザを終了すると、以降の**ロック設定の変更にもマスターパスワードが必要**になります - 「維持」期間中は暗号化キーがパソコン内に保存されるため、共用パソコンでは非推奨です。手動ロックでいつでも解除できます ## 使用者の権限 $2699$FE0F(設定)→「使用者の権限」で、そのパソコンの使用者に編集を許可するかを設定できます。 - **編集権限 無(デフォルト)**: 詳細表示では**IDとURLのみ**表示。パスワードの表示・コピー、登録・編集・削除は不可。「設定入力」での自動入力は可能(パスワードは画面に表示されません) - **編集権限 有**: 全機能が使えます - 「有」で保存するには毎回マスターパスワードの確認が必要です(セットアップ後、最初に設定してください) - マスターパスワード未設定の状態では権限を変更できません(設定を促す通知が表示されます) - 「無」を「ロック解除を維持」と組み合わせると、パスワードを見せずにログインだけさせられます > 「編集権限 無」は操作ミス防止・抑止のための機能であり、技術に詳しい使用者に対する防御ではありません。** > ブラウザの開発者ツールを使える人であれば、保存された設定や(「ロック解除を維持」中は)復号キーにアクセスできる可能性があります。 > 確実に内容を秘匿したい相手とは、そもそもマスターパスワードを共有しないでください。 ## 既存パスワードマネージャーからの移行 設定→「既存パスワードマネージャーからの移行」で、Chrome / Edge 等からエクスポートしたCSV・TXTを一括インポートできます(1行目に列名ヘッダーがある形式)。 - インポートにはマスターパスワードの確認が必要です - パスワード確認後、プレビューで件数と列の対応を確認してからインポート実行 - 既存と重複する登録(同じURLとID)は自動でスキップ(解除可) - **インポート後、平文パスワードを含む元のCSVファイルは必ず削除してください** ## CSVへのエクスポート 設定→「CSVへのエクスポート」で、全登録をChrome/Edge互換のCSV(name, url, username, password, note)として書き出せます。マスターパスワードの入力が必要です。他ソフトへの移行やバックアップ用です。**書き出されたCSVは平文のため、使用後は必ず削除してください。** ## プライバシーとセキュリティ - この拡張機能は、パスワードを含む**一切のデータを外部に送信しません**。エラー情報の収集も行いません(エラーのコンソール出力もデフォルトOFF。設定画面のデバッグ用設定でのみ有効化可能) - マスターパスワードはどこにも保存されません。**忘れるとデータは復元できません** - 共有ファイルは暗号化されていますが、マスターパスワード自体をメール等で送らないでください - 削除済みデータの痕跡(タイトルのみ)は同期の誤認防止のため90日間保持されます - 自動入力は「設定入力」を押した時だけ、そのタブに対してのみ動作します(常時ページを監視しません)。フィッシング対策として、URLが一致しないサイトには入力ボタンが表示されず、さらに入力実行の直前にもタブの現在URLを再確認します - 登録できるURLは http:// / https:// のみに制限しています(javascript: 等は登録不可) ## ファイル構成 ``` family-pass/ ├── manifest.json # 拡張機能定義 (Manifest V3) ├── popup.html/css # メインUI ├── options.html # 設定画面(共有ファイルの選択) ├── js/ │ ├── crypto.js # PBKDF2 + AES-GCM 暗号化 │ ├── vault.js # 保管庫データとマージロジック │ ├── filestore.js # File System Access API でのファイル読み書き │ ├── importer.js # CSV/TXTインポートのパーサー │ ├── popup.js # メインUIロジック │ └── options.js # 設定画面ロジック └── icons/ ``` Family Pass Family Pass is a Chrome extension that allows passwords to be securely shared and synchronized among family members using different Google accounts. How It Works Passwords are encrypted, and encryption keys are derived from a master password. An encrypted vault file (family-vault.fpass) is stored in a shared folder on Google Drive or a similar cloud storage service, and each family member reads and writes to the file from their own Chrome browser. Since the vault file is always encrypted, plaintext passwords are never exposed to Google or any third party. Changes are merged on a per-entry basis using a "latest change wins" approach, and deletions are also propagated to all family members. Requirements A shared folder synchronized to a local computer via Google Drive for Desktop, Dropbox, OneDrive, or a similar service. All family members must use the same master password (if forgotten, recovery is impossible). Shared vault files created with a different master password cannot be used. To access such a file, reinstall the extension and configure it with the correct master password. Installation Place the family-pass folder anywhere on your computer. Open chrome://extensions in Chrome. Enable Developer Mode in the upper-right corner. Click Load unpacked and select the family-pass folder. Setup First Family Member Click the extension icon in the toolbar and create a master password (minimum 8 characters). Open Settings → Create New Shared File, then save it as family-vault.fpass inside the shared folder. Return to the popup window and click Sync. Other Family Members Confirm that the shared folder is synchronized to the computer. Install the extension, then open Settings → Select Existing Shared File and choose family-vault.fpass from the shared folder. Enter the same master password in the popup window to unlock the vault. Daily Usage Add Entries: Click + Add New Entry to save a website name, username, password, and other information. When opened from a login page, the website name and URL can be filled automatically. Only http:// and https:// URLs can be registered. Auto-Fill: When visiting a registered site's login page, open the extension icon. Matching entries will appear at the top with a Fill Credentials button. Clicking it automatically fills the username and password fields. (The website URL must be registered in the entry.) Use Credentials: Open entries from the list and copy credentials as needed. Sync: Click Sync after adding or modifying entries, or when you want to retrieve changes made by other family members. Locking: By default, the vault automatically locks when the browser is closed. Lock Settings Open ⚙ Settings → Lock Settings to choose how long the vault remains unlocked. Options Lock when browser closes (Default) Keep Unlocked: 1 hour / 3 hours / 6 hours / 1 day / 3 days / 1 week / 2 weeks / 1 month / 6 months / Never Additional notes: The unlock expiration date and time are displayed after selecting a duration (minutes are rounded down to 00). Selecting 1 month or longer (including Never) requires confirmation of the master password. Once a duration is set and the browser is closed, changing lock settings will also require the master password. During the unlock period, the encryption key is stored locally on the computer. Therefore, this feature is not recommended on shared computers. You can manually lock the vault at any time. User Permissions Open ⚙ Settings → User Permissions to control whether the current computer user can edit vault contents. No Edit Permission (Default) Only Username and URL are visible in detailed views. Passwords cannot be viewed or copied. Entries cannot be added, edited, or deleted. Auto-fill remains available via Fill Credentials (the password is never displayed on screen). Edit Permission Enabled Full functionality is available. Additional notes: Enabling edit permission always requires master password confirmation. User permissions cannot be changed until a master password has been configured. Combining No Edit Permission with Keep Unlocked allows users to log in without revealing passwords. Important: "No Edit Permission" is intended to prevent accidental changes and provide basic access control. It is not designed to defend against technically skilled users. Anyone with access to browser developer tools may be able to inspect stored settings and, while the vault is kept unlocked, potentially access decryption keys. If you need to keep vault contents completely secret from someone, do not share the master password with them. Importing from Existing Password Managers Open Settings → Import from Existing Password Manager to bulk-import CSV or TXT files exported from Chrome, Edge, and other password managers (files must contain a header row). Master password confirmation is required. After authentication, a preview displays the number of entries and column mappings before import. Duplicate entries (same URL and username) are automatically skipped by default (this behavior can be disabled). After importing, permanently delete the original CSV file because it contains plaintext passwords. Exporting to CSV Open Settings → Export to CSV to export all entries as a Chrome/Edge-compatible CSV file: name, url, username, password, note Master password authentication is required. This feature is intended for migration to other software or backups. Because the exported CSV contains plaintext passwords, it should be deleted immediately after use. Privacy and Security This extension does not transmit any data externally, including passwords. No error reporting or analytics are collected. (Console logging is disabled by default and can only be enabled through debugging settings.) The master password is never stored anywhere. If it is forgotten, the data cannot be recovered. Although the shared vault file is encrypted, never send the master password via email or other insecure channels. Deleted-entry traces (titles only) are retained for 90 days to prevent synchronization conflicts. Auto-fill works only when the Fill Credentials button is clicked and only for the current tab. The extension does not continuously monitor web pages. As an anti-phishing measure, auto-fill buttons are displayed only when the website URL matches a registered entry, and the URL is verified again immediately before filling credentials. Only http:// and https:// URLs can be registered. URLs such as javascript: are blocked. File Structure family-pass/ ├── manifest.json # Extension definition (Manifest V3) ├── popup.html/css # Main UI ├── options.html # Settings screen (shared file selection) ├── js/ │ ├── crypto.js # PBKDF2 + AES-GCM encryption │ ├── vault.js # Vault data and merge logic │ ├── filestore.js # File I/O using the File System Access API │ ├── importer.js # CSV/TXT import parser │ ├── popup.js # Main UI logic │ └── options.js # Settings screen logic └── icons/

Details

  • Version
    2.0.0
  • Updated
    July 6, 2026
  • Offered by
    shunpuutei
  • Size
    30.27KiB
  • Languages
    日本語
  • Developer
    ラジオ屋
    Email
    hagino@radioya.jp
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps