How to Install GrapheneOS — Complete End-to-End Guide (2026)

Install GrapheneOS on a supported Pixel with preparation, web and CLI guidance, bootloader verification, troubleshooting and a security-settings reference.

Share
How to Install GrapheneOS — Complete End-to-End Guide (2026)

Installing GrapheneOS involves unlocking a supported device's bootloader, flashing the operating system and locking the bootloader again. The official web installer is the recommended route for most people. It runs in a compatible browser and does not require you to install command-line flashing tools.

This guide covers preparation, the installation sequence, verification and problems that should make you stop. Keep the official installer open while you work: its current instructions and device-specific requirements take precedence over any walkthrough, including this one.

Before you begin:

  • Back up the phone and check that you can restore your accounts. Unlocking, flashing and relocking involve data wipes.
  • Confirm that your exact model is supported and permits bootloader unlocking. A SIM-unlocked phone is not necessarily bootloader-unlockable.
  • Use a reliable USB cable and a direct computer port.
  • Finish flashing successfully before locking the bootloader. Locking is part of completing the installation, not a repair for an unexplained flashing error.

Check device support before buying or wiping

Check the exact model against GrapheneOS's supported-device list. Do not assume that every newly released Pixel is supported or that an older model still receives full security updates.

For a purchase, consult the project's separate recommended-device list. It currently recommends supported eighth-generation and later Pixels for their security features and longer support guarantees. The seven-year minimum support period runs from launch, not from the date you buy the phone.

Carrier variants can restrict bootloader unlocking, particularly in the US. A seller's “unlocked” label may refer only to SIM restrictions. Confirm OEM unlocking eligibility before buying; do not rely on a promised software workaround.

Before committing to a switch, check your essential apps using the GrapheneOS compatibility guide. Resolve a banking, work-app or payment dependency before erasing your current setup.

Prepare the phone and installation computer

Backups and account access

Copy important files off the phone and verify that the copies open. Check your password-manager access, authenticator migration or recovery codes, and any application-specific backup requirements. Keep recovery material somewhere you can access without this phone.

Update the stock operating system before installation. GrapheneOS recommends this so the early connection and flashing stages use current firmware; its installer also flashes firmware as part of installation.

Browser, storage and USB connection

The web-installer prerequisites specify at least 2 GB of available memory and 32 GB of free storage on the installation computer. Use an up-to-date, supported operating system and browser.

Supported browser options include Chrome, Edge and Chromium, plus Brave with Shields disabled. GrapheneOS also supports installation from compatible Android devices using suitable browsers. Firefox and Safari are not listed as supported web-installer browsers.

Avoid private browsing, browser Snap/Flatpak packages and virtual-machine USB passthrough. These can introduce storage or USB-access problems. Use the supported-platform list on the installer rather than assuming that any Chromium package works.

Use the device's supplied USB-C cable where possible, or another reliable data cable. Connect directly to a laptop port or a desktop rear port rather than a hub, dock or front-panel hub. GrapheneOS identifies faulty cables and hubs as a common installation failure source.

Linux permissions and Windows drivers

On traditional Linux distributions, USB access requires the appropriate udev rules. The documented packages are android-udev on Arch and android-sdk-platform-tools-common on Debian/Ubuntu. This is USB permission setup, not a requirement to use the CLI installer.

Current Windows 10/11 installations include a usable generic fastboot driver for non-obsolete supported Pixels. If the device is not detected, consult the installer's Windows driver guidance rather than installing an arbitrary driver bundle.

Install GrapheneOS with the web installer

1. Enable OEM unlocking

On the phone, open Settings → About phone → Build number and tap repeatedly until developer options are enabled. Then open Settings → System → Developer options → OEM unlocking and enable it.

Some device variants need internet access to check carrier restrictions. A greyed-out toggle is not, by itself, proof that the phone is permanently carrier-locked. Follow the OEM unlocking instructions, including the documented stock-firmware update and factory-reset requirement for affected Pixel 6a devices.

Enabling this toggle permits a later bootloader unlock. It does not unlock the bootloader immediately.

2. Enter Fastboot Mode and connect

Power off the phone, then hold Volume Down while powering it on. Keep it at the bootloader interface displaying Fastboot Mode. Do not select Start yet; that boots the operating system instead.

Connect it to the installation computer and open grapheneos.org/install/web. Follow its connection prompts and grant the browser access to the intended device. A Pixel Tablet must be disconnected from its stand for installation.

The web route does not require adb, fastboot devices or a terminal check before proceeding.

3. Unlock the bootloader

Use Unlock bootloader in the installer. Read the confirmation on the phone, use a volume button to select the unlock option and press Power to confirm.

Unlocking wipes the phone's data. Do not proceed unless your backups and account-recovery preparations are complete.

4. Download and flash the release

Use Download release, then Flash release, following the live installer's sequence. Let flashing finish without disconnecting the cable, putting the computer to sleep or interacting with the phone unnecessarily.

The installer handles firmware flashing and device reboots during the process. Wait for flashing to complete before proceeding to locking. If it reports an error, retain the exact message and resolve it first. A fixed number of minutes is not a reliable test of whether flashing succeeded.

5. Lock the bootloader

After successful flashing, use Lock bootloader and confirm the action on the phone. Locking enables full verified boot and wipes data again, so complete it before restoring applications and personal files.

Once the installer has completed the sequence, select Start in the bootloader interface to boot GrapheneOS. During initial setup, leave the recommended option to disable OEM unlocking enabled. You can manage that setting later through developer options if needed.

Verify the installation

Check the verified-boot identity

A yellow notice that the device is loading a different operating system is expected with GrapheneOS. It is not the same as an unlocked-bootloader warning or a corruption error.

On sixth-generation and later Pixels, compare the full verified-boot key hash shown during boot with the entry for your exact model in the official key-hash list. Use a separate trusted device to view the reference where possible. Do not compare against a hash copied from an unverified guide or forum post.

This manual comparison checks the installed OS identity; verified boot operates whether or not you perform the comparison.

Use Auditor for attestation

Auditor is bundled with GrapheneOS. Local verification requires a second device running Android 13 or later, with a camera and Auditor installed; the phone being checked does not display its own trusted verification result.

Follow the local verification tutorial: the second device acts as Auditor, the GrapheneOS phone acts as Auditee, and the devices exchange QR-code challenges and responses. Review the result on the verifying device.

Alternatively, the scheduled remote verification service supports periodic checks and email alerts. Set up the account from a separate device and follow the enrollment instructions.

Attestation is not a promise that compromise is impossible. GrapheneOS documents a pairing model and limitations of the initial verification; subsequent paired checks build on that initial trust.

Troubleshoot without guessing at destructive steps

The browser cannot connect

Confirm that the phone is still in Fastboot Mode, that the browser is supported and that no other program is using the device. Try another reliable cable and direct USB port. On Linux, check the udev rules and reconnect after installing them.

If an error says the USB device is already claimed, GrapheneOS documents an fwupd conflict on Linux. Follow that section only when it matches the problem; do not change system services as a generic first step.

Flashing reports an error or is interrupted

Save the error text and note the installation stage, model, host OS and browser. Consult the official instructions or GrapheneOS community support before changing the bootloader state or improvising a recovery sequence.

Do not lock an incompletely flashed device as a troubleshooting shortcut. Do not assume A/B slots make every interrupted factory flash harmless. A/B update fallback does not establish that an interrupted installation is safe to ignore.

A warning appears during boot

Read the text, not just the colour or triangle icon. The Android verified-boot documentation distinguishes:

  • Yellow: a locked device using a custom root of trust, expected for GrapheneOS; verify the OS key hash.
  • Orange: an unlocked bootloader.
  • Red corruption warning: a verification/corruption problem.
  • Red “no valid operating system” warning: no valid OS was found.

The red triangle in the Fastboot Mode interface is also not, by itself, a corruption diagnosis.

A red corruption screen does not mean “the bootloader needs locking.” Record the exact warning and get state-specific guidance. Unlocking or reflashing may erase data; do not apply either as a blanket repair to a phone containing files you need.

If you prefer the command-line installer

Use the official CLI guide as the complete procedure. It includes host-specific setup, supported fastboot versions, USB permissions, download verification and the correct flashing script invocation.

The CLI route requires verifying the factory-image signature, not just downloading a ZIP over HTTPS. Follow its instructions for obtaining allowed_signers, the image and its matching signature. Windows and Unix-like shells have different verification syntax; do not paste a Unix redirection example into PowerShell unchanged.

CLI preparation and sequence

Use the same terminal throughout the procedure so its PATH configuration remains available to the flashing script. On Windows, use a normal, non-administrator PowerShell session. The official tool setup currently requires fastboot 35.0.1 or newer and explains which packages are suitable; an installed distro package is not automatically recent enough.

Check the tool version before proceeding:

fastboot --version

After the host-specific tool and USB-permission setup, follow the official sequence:

  1. Enable OEM unlocking and enter Fastboot Mode as described above. Connect the intended phone.
  2. Unlock the bootloader using the CLI guide and confirm the data wipe on the device.
  3. Obtain the official allowed_signers file, the factory-image ZIP for your exact device and release, and that ZIP's .sig file.
  4. Verify the signature using the command for your host OS. Stop if verification fails; do not treat successful extraction as verification.
  5. Extract the verified archive and change into its release directory.
  6. Run the provided flashing script without editing it. Wait for successful completion before proceeding.
  7. Lock the bootloader following the official guide, confirm the second data wipe, then boot and verify the installation.

For Linux/macOS, the documented script invocation from the extracted release directory is:

bash flash-all.sh

For Windows PowerShell:

./flash-all.bat

These are the script-launch steps, not a complete copy-paste installer. Complete the prerequisite, unlock and signature-verification steps first. The scripts flash the device and erase its data.

If CLI flashing fails, preserve its terminal output. On Linux, a memory-backed temporary directory can run out of space even when the main disk has room; the official CLI troubleshooting section explains how to use a different temporary directory. Do not restart a failed flash blindly or relock to suppress an error.

The web installer and CLI installer are alternative workflows. Avoid mixing their steps or omitting setup because a short command list looks sufficient.

Return to stock Android

Returning to stock involves another installation and data wipes. Back up first, then follow GrapheneOS's stock-OS replacement instructions.

There is an extra step beyond flashing Google's image: remove the non-stock Android Verified Boot key while the bootloader is unlocked, before flashing and locking stock Android. The official page provides the Remove non-stock key action and links to Google's flashing tool. Do not remove that key as routine GrapheneOS maintenance.

Follow the full stock-restoration sequence and relock only after the correct stock image has been successfully flashed. Do not assume that returning to stock automatically restores every app's accounts or local data.

Initial configuration: the decisions to make next

Google Play and app sources

Sandboxed Google Play is optional and runs without the privileged system integration it has on stock Android. Install it through GrapheneOS's Apps application in the profile where you need it. Decide this before restoring dependent apps, then follow the official setup and notification guidance.

A separate profile is a compartmentalization choice, not a requirement for sandboxing. Consider which applications need to work together and how often you want to switch profiles. Do not assume that a second profile adds isolation without usability trade-offs.

Choose app sources deliberately and keep their update mechanisms working. The official usage guide covers supported installation options. When installing an APK directly, grant installation permission only to the app handling it and revoke that permission when finished. A longer app-store comparison belongs with day-one setup, not the flashing procedure.

Permissions and scope controls

Review permissions after restoring apps. GrapheneOS adds per-app Network and Sensors controls; grant access according to the app's purpose and test the functions you need after changing it. Storage Scopes and Contact Scopes let you limit what an app can access instead of granting broad permissions. Contact Scopes also blocks contact writes, which matters for apps intended to edit your address book.

Profiles

Use profiles when you need separate app data and settings, rather than creating a complicated layout before you know your requirements. Start by identifying which apps must share a working environment, then consult the profile features before deciding what to separate.

The first-day guide provides the broader setup sequence. The reference below keeps advanced options available here rather than discarding them from the installation guide.

Security and maintenance reference

Auto reboot and USB protection

Auto reboot reboots a device that remains locked for the configured period, returning data to rest. Review the interval against how you use the phone, including how you will receive notifications and unlock it after restarting. It is not a substitute for an appropriate unlock credential.

USB-C port control defaults to charging-only when locked. It blocks new connections on locking; existing connections affect when the data lines are disabled. That is more precise than claiming that locking instantly terminates every existing USB connection. Consult the mode descriptions before changing the setting for accessories or troubleshooting.

Per-app exploit protection

The exploit-protection documentation explains controls for dynamic code loading from memory or storage, WebView JIT and native debugging. These settings can affect compatibility. Change them deliberately and test the application rather than copying a blanket “enable everything” checklist.

GrapheneOS also changes how app processes are spawned to improve isolation. Keep process-spawning behavior separate from permission controls: it is an OS hardening mechanism, not another permission that users should toggle indiscriminately. Refer to the feature documentation for current implementation and compatibility details.

Unlock options and destructive duress credentials

Two-factor fingerprint unlock adds a PIN after fingerprint authentication as a secondary unlock mechanism. It can accompany a strong primary passphrase. PIN scrambling applies to PIN entry; it does not transform a passphrase keyboard into a scrambled PIN keypad.

Duress credentials are destructive: entering one at a supported credential prompt irreversibly wipes the device, including installed eSIMs. The current documentation requires both a duress PIN and password when enabling the feature and describes where each applies. Do not test this on a phone containing data you need, and do not configure it as a routine installation checkbox.

Profile sessions, notifications and VPNs

End session puts a secondary profile's data back at rest by ending its session; it is different from merely switching away. The owner profile needs a reboot for the corresponding at-rest transition. Understand that distinction before relying on profile switching to protect inactive data.

Notification forwarding can help with using multiple profiles, but review what is forwarded and test the workflow with the apps you depend on. Profiles also have their own VPN configuration; do not assume a VPN configured in one covers all the others. Cross-profile app installation can reuse an installed package without making the profiles share that app's private data. Check the current profile documentation for controls and limitations.

Updates and battery settings

Keep system and application updates enabled, and complete restarts when required to activate system updates. Review update-channel descriptions in the official usage guide before selecting a channel other than Stable; early-access options are not a prerequisite for a secure installation.

If your current device and release expose a battery charge-limit option, review it under Battery settings according to how you charge the phone. Treat it as optional battery maintenance, not an installation or app-compatibility requirement.

After installation

Once installation and verification are complete, continue with First 24 Hours with GrapheneOS for the post-install configuration sequence. Keep app-compatibility decisions separate from installation troubleshooting: What Breaks on GrapheneOS covers that part of the switch.

## Convertkit Newsletter