Autofill without phishing
Fills only on an exact domain match and only when you click. Look-alike addresses and hidden trap fields get nothing.
Version 0.9.8 · Chrome and Edge
Your vault is encrypted on your computer. An account syncs it across your devices and with your colleagues, yet the server only ever sees ciphertext.
Features
An email account with two-step verification; encryption happens only on your device. No ads, no telemetry.
Fills only on an exact domain match and only when you click. Look-alike addresses and hidden trap fields get nothing.
Logins, cards and bank accounts, identities for forms, passports, Wi-Fi, servers, API keys, licenses, notes and your own templates.
List and item side by side. The full-screen window adds vaults, tags, favorites, archive, a 30-day trash and bulk actions.
An overall score and issues: weak, reused and old passwords, missing 2FA, expired cards, addresses without HTTPS.
A generator of random passwords and passphrases from the EFF word list, with strength in bits.
One-time codes right in the item, and filling them on the sign-in page.
“Personal”, “Work” and any others under one master password, each with its own key.
A fingerprint, device PIN or security key instead of the master password between its entries.
Import from 1Password, Bitwarden, LastPass, Chrome, Edge and Firefox. Export to Bitwarden JSON or CSV.
One vault on all your devices. Changes from different computers merge item by item.
An organization with employees, offices and shared vaults. Each employee is confirmed by comparing five words, so nobody can swap their key unnoticed.
An employees × vaults matrix, vault key rotation when someone leaves, access recovery and an organization audit log.
Popup
List and item side by side. Search by title, site, username and tags finds an item from the first letters; passwords and notes never enter the search.
Security check
An overall score from 0 to 100 and six kinds of issues. Click a kind to list only those items, click an item to open it.
Generator
Random characters or a passphrase from the EFF word list — easy to type on any keyboard.
Security
Encryption happens on your device. The key lives only in memory, and only while the vault is open.
The key is derived from your master password with Argon2id using 128 MiB of memory. The master password and keys are never stored.
Add a keyfile and the vault will not open without it, even with the right password.
The server stores only ciphertext and a hash of the sign-in key. The extension talks to it alone — the browser blocks everything else. No analytics, no remote code.
Previous versions of the vault on disk, an encrypted backup and a Recovery Kit PDF — to get back in if you forget the master password.
Sync goes through your Y-Secret-Pass account: the server receives the same encrypted file — without the master password or keys. Sign-in is by email with two-step verification, and you can delete the account in settings.