Phone first. Install the Blasts Deals app on your phone (Google Play; iPhone: App Store), register in it with your work e-mail, and turn on Settings → Sign-In Approvals. Every sign-in below is approved on that phone - nothing works without it.
Sign in to the Blasts developer console with that SAME e-mail. A test partner can ring only that phone.
Create a sandbox partner there - the console walks you through it and shows a 4-step tracker like this one.
Register this extension's id with that partner (console step 3): ...
Enter the partner id here - Settings (button below), then come back to this popup (puzzle-piece Extensions icon next to the address bar → Blasts Kit Sample; pin it there once) and sign in with the same e-mail.
Sign in with the Blasts Deals app
Use the e-mail that is on YOUR phone's Blasts Deals app - the same account that created the test partner in the console. Any other e-mail cannot be approved.
Your phone approves this PC; this extension never sees a password.
What to expect: after you click, your 6-digit code appears right here - usually within a few seconds, up to about 10 the first time while the server wakes up. The first click on a new account only asks your phone for permission (Settings → Sign-In Approvals); the second click brings the code, which you type into the request on your phone (the code is never sent to the phone).
Check your phone
Open Blasts Deals on your phone, go to Approvals, open the request from this product and type this code into it (it appears here and nowhere else):
------
Waiting for your phone...
This PC is signed in
Account
...(your pairwise user id - never the e-mail)
PCs on this account
...
Free units
...
Server check
...
Your plan on this PC
Checking the free counter...
You do not need a license code for the free tier. Sign in above first; the paid-plan code field appears afterwards.