Secrets

Passwords, authenticator codes, and passkeys live in bia’s own vault on the stick. Listing names never shows the secret until work truly needs it.

The vault stores ordinary passwords, rotating one-time codes, and WebAuthn passkeys. Import from a 1Password-style CSV (or legacy JSON); export a clean CSV when you want a human-readable backup — then delete plaintext copies when told.

When a site asks for a login code, bia can fetch the current code for that entry. When a site wants a passkey, Chrome and the vault cooperate so the signature never has to be typed into chat.

This is how bia walked Google and Meta logins in the week-long story: pull a passkey or TOTP from the vault, ask a human for the captcha, keep going without scattering secrets across screenshots.

In everyday life

  • Lists entry names without revealing values.
  • Returns a password or the current one-time code only when needed.
  • Imports and exports common password-manager formats.
  • Creates and asserts passkeys for supported websites.

Unlike a normal chatbot

Chatbots beg you to paste secrets into the thread. bia keeps them on the device and fetches one value at a time for a real login.