Zesam

Support

A question, a problem

Write to support@zesamapp.fr. A person answers, not a form.

Never send a secret, a code, or a screenshot showing one. Not to us, not to anyone. No support question requires knowing them.

My codes are being refused

Almost always a clock that has drifted. Open Settings › Reference time: Zesam measures the gap between the device clock and real time, and can correct codes for it. Beyond a few seconds, a service refuses everything.

My service's QR code won't scan

Some services, Microsoft in particular, offer two different QR codes. The one meant for their own app encodes an activation towards their servers, which no third-party app can read. Look for the option to use a different authenticator app: it gives a standard code, which Zesam reads without trouble.

If you have no second device to photograph the screen, take a screenshot instead: Zesam reads the QR code inside an image, a photo or a PDF.

How travel mode works

In two steps. In each account's own sheet, a switch marks the ones that should disappear. In settings, the global switch makes them disappear for real: from folders, from search, even from the sidebar counters.

Face ID is required in both directions, and it is the “off” direction that protects: somebody you hand an already-unlocked device to cannot reveal the hidden accounts with a single gesture.

What travel mode does not do: it encrypts nothing further and erases nothing. It protects against someone looking at the screen, not against a forensic examination of the device.

An account shows on one device and not the other

Two separate settings must be on: iCloud Drive for names and folders, and iCloud Keychain for secrets. If only the second is missing, the account appears without its code: Zesam shows it greyed out, waiting, rather than producing a wrong code.

I lost a device

Settings › Devices, then Revoke. The device loses access to the shared store. But be clear-eyed: revoking does not take back what has already been copied. Anyone holding a secret keeps producing valid codes until the service issues a new one. Zesam then offers you a rotation plan, service by service.

The browser extension can't find Zesam

On Chrome and Firefox, access is off by default: open Zesam on the Mac, Settings › Chrome and Firefox, turn on access, and paste the key it shows into the extension. On Firefox, accept the permission request that follows.

On Safari none of this applies: the extension ships with the app and is enabled in Safari's own settings.

Getting my accounts onto a new device

Sign in to the same iCloud account: everything returns. Without iCloud, use the encrypted export made from the old device. Keep its passphrase somewhere other than Zesam; nobody, ourselves included, can reopen that file without it.

Reporting a security issue

Write to security@zesamapp.fr. Reports are handled first, and the person who reports is credited if they wish.