securephone.co

Install GrapheneOS & set up your device

Flash GrapheneOS onto a Pixel, then enroll it — all from this page, over USB. Works from a computer or another phone.

This needs Chrome, Edge, or Brave — Firefox and Safari can't talk to USB devices. Open this page in a supported browser.
On a phone host (e.g. a Galaxy S25): turn off “Desktop site” in your browser menu, or the installer can't re-request the device after each reboot. Use Wi-Fi — the GrapheneOS download is ~2 GB. A good USB-C↔USB-C data cable is essential.
Phase 1 · Install GrapheneOS

Before you start

1Unlock the bootloader

Pick the Pixel in the USB chooser, then confirm the unlock on the phone with the volume + power keys.

2Download GrapheneOS

~2 GB, fetched and cryptographically verified directly from GrapheneOS's servers. It's cached, so you won't re-download if you retry.

3Flash GrapheneOS

Keep the cable connected. The phone reboots a few times during flashing — if prompted, tap Reconnect device and re-allow USB.

4Re-lock the bootloader

Restores Verified Boot for full security. Confirm on the phone. Don't skip this.

Revert to stock Android (advanced)

Only if you're going BACK to stock: erase the GrapheneOS verified-boot key, then re-lock. Not part of a normal install.

Phase 2 · Set up & enroll

Finish setup on the phone

  1. Unplug, power on, and complete GrapheneOS setup. Skip adding any accounts — device management requires a fresh, account-free device.
  2. Turn USB debugging on: Settings → About phone → tap Build number 7× → back → System → Developer options → USB debugging on.
  3. Reconnect over USB and tap Allow on the phone's debugging prompt.

5Connect

6Enroll

Activation code:

Installs the Device Manager device-management app as Device Owner and registers the phone to your account. The cable is needed only for setup; afterwards it's managed over the network. No activation code? You can stop after Phase 1 — you'll have plain GrapheneOS, just without enrollment.

This installs unmodified GrapheneOS, downloaded directly from grapheneos.org and verified against their signing key. GrapheneOS is an independent project, not affiliated with SecurePhone; we self-host their open-source (MIT) web installer for convenience. The device-management enrollment in Phase 2 is a separate, optional step. Full docs: grapheneos.org/install/web.