Your passwords,
encrypted in your browser before they are saved.
PassKey encrypts your passwords, notes and 2FA secrets in your browser with a key made from your master password, and only the encrypted versions are stored on the server. Titles, URLs, usernames, emails, folders and tags are stored as plain text so search and sorting work.
One master password. Takes about a minute to set up.
Passwords are the weakest link, and you can't memorise your way out
The average person has dozens of accounts. Remembering a strong, unique password for each one isn't realistic, so shortcuts creep in.
One password, everywhere
Most people reuse a handful of passwords. When one site leaks, attackers try that same password on your email, bank and social accounts.
Phishing looks real
Fake login pages are convincing. With a vault you never retype a password from memory, and every site gets its own, so a stolen one only works in one place.
Breaches are routine
Companies get breached constantly. Unique, random passwords turn a leak at one service into a non-event instead of a chain reaction.
Everything you need to lock things down
Security first, convenience second, and without trading one for the other.
Client-side encryption
Passwords, notes, 2FA secrets and password history are encrypted in your browser with a key derived from your master password. The server stores only the encrypted versions of those fields.
Browser extension Coming soon
A browser extension for autofill is planned but is not available yet. Until it ships, open your vault in the browser and copy logins from there.
Breach check
Check your saved passwords against known data breaches whenever you like, so you can change any that have leaked. Only a short hash prefix leaves your browser.
TOTP / 2FA codes
Keep your two-factor codes next to the login they protect and stop juggling a separate authenticator app.
Password generator
Create long, random passwords in one click, with adjustable length and character types.
Auto-lock
The vault locks itself after a period of inactivity that you choose.
Activity log
A history of what happened in your vault on this device: entries added or edited, unlocks, exports and breach scans. It is kept in this browser only.
Email-code account reset
Forgot your account password? A one-time code sent to your email lets you set a new one. It does not unlock an existing vault: for that you need your old master password or your recovery key.
From sign-up to secured, in four steps
Create your account
Enter your email and choose one master password. That is the only password you need to remember.
Your key is made on your device
Your browser turns your master password into an encryption key. The key is kept only in your browser tab and is never sent to the server.
Your secrets are encrypted
Passwords, notes and 2FA secrets are encrypted in your browser before they are sent. The server stores only the encrypted versions of those fields.
Use it anywhere
Log in from any browser with your email and master password. Your vault comes along, and its encrypted fields can only be opened with your master password or recovery key.
What is protected, and what is not
Your passwords, notes and 2FA secrets are locked in your browser with a key we do not store. Someone who copies our database gets those fields only as ciphertext.
Know the limits. Your master password is also your account password, so it is sent to our server over HTTPS when you register or log in (WordPress keeps only a hash of it). A server that has been tampered with could capture it. Titles, URLs, usernames, emails, folders and tags are stored as plain text.
Stays on your device
- Your encryption key (this browser tab)
- Your decrypted passwords and notes
- Your activity log
What our server stores
- Your email and a hash of your account password
- Titles, URLs, usernames, emails, folders and tags (plain text)
- A random salt and a verification value
- Passwords, notes and 2FA secrets (encrypted)
Standard algorithms, not home-grown tricks
PassKey uses well-reviewed primitives built into your browser instead of inventing its own.
AES-256-GCM
Authenticated encryption for your vault data.
PBKDF2-SHA256
600,000 iterations to slow down password guessing.
Secure random
Salts, IVs and generated passwords come from the browser's cryptographic random generator.
Browser WebCrypto
Encryption runs locally, using your browser's built-in crypto API.
Questions, answered honestly
Everything you might want to know before you start.
What happens if I forget my master password?
We cannot decrypt your vault for you. If you generated a recovery key during setup, you can use it to unlock your vault; otherwise a lost master password means the encrypted fields are lost. Resetting your account password by email does not bring the old vault back.
Can PassKey staff read my passwords?
Not from the database alone: passwords, notes and 2FA secrets are encrypted in your browser and stored only as ciphertext. But staff can read titles, URLs, usernames, emails, folders and tags, and your master password passes through the server when you log in, so you are trusting whoever runs and secures this site.
Is the vault available yet?
Yes. Account creation, the encrypted vault, the password generator, breach checks and TOTP codes are live today. The browser extension is not available yet.
Why is my master password also my account password?
PassKey logs you in with a WordPress account, and that login uses your master password. Your browser also uses it to derive the key that encrypts your vault. The server stores only a hash of it, but it does see the password while you log in.
Do I need to install anything?
No. PassKey works in your browser, so there is nothing to download or install to get started. A browser extension for autofill is coming soon, but it is not available yet.
Ready to take your passwords back?
Create your account in a minute. One master password, and your passwords are encrypted before they are saved.
Open your vault