OoKey Password Manager
Overview
Zero-knowledge password manager — autofill, password generation, and secure vault access.
OoKey is a zero-knowledge password manager. It securely stores your passwords on your own device and autofills saved credentials into login forms across the web. ━━ Key Features ━━ 🔒 Zero-knowledge architecture Your master password, encryption keys, and vault contents are never stored on OoKey servers. The server holds only AES-256-GCM ciphertext that cannot be decrypted by OoKey or any third party. 🔑 Strong cryptography Key derivation uses Argon2id with 64 MiB memory cost and 3 iterations. Symmetric encryption uses AES-256-GCM. Authentication uses SRP-6a, a zero-knowledge password proof. The optional recovery key is a 24-word BIP-39 mnemonic. ⚡Autofill OoKey detects login forms automatically and fills your saved credentials in a single click. When you sign in on a new site, an inline prompt offers to save the credentials to your vault. 🛡️Password generator The built-in generator supports customizable length, character classes, passphrases, and usernames. It shows real-time strength feedback and a short history of recently generated values. 📊 Security report A local report flags weak passwords, reused passwords, sites that use plain HTTP, and items missing two-factor authentication. The report runs entirely on your device, with no external API calls. 🌐 Cross-browser Works on Chrome, Edge, Firefox, and Safari. Your vault syncs across browsers and devices through your OoKey account. 📤 Data portability Export your vault to JSON, CSV, or ZIP at any time. Your data remains under your control and is portable to other password managers. 🆘 Emergency access Designate trusted contacts who can request access to your vault in an emergency. Two-layer encryption (RSA-OAEP-2048 + AES-256-GCM) ensures only an authorized contact can decrypt during the takeover window. 📨 OoKey Send Share passwords or short notes through expiring, encrypted links. Recipients do not need an OoKey account. You can set link expiration and view-count limits. ━━ Privacy and Security ━━ ✅ OoKey does not contact any third-party service. There is no breach database lookup, no analytics, no crash reporter, and no advertising telemetry. The only network destination is the OoKey API. ✅ Servers are hosted in AWS Tokyo (ap-northeast-1). All data remains in Japan. TLS 1.2 or higher is enforced, with HSTS and SameSite=None Secure cookies. Refresh tokens rotate on every use, with reuse detection that revokes the session on suspected theft. ✅ Full technical documentation is available at https://ookey.jp/#docs. ━━ Permissions Justification ━━ ✅storage : Cache encrypted vault data locally for offline use. ✅activeTab : Read and fill form fields on the currently focused tab when the user invokes autofill. ✅scripting : Inject the autofill content script on demand. ✅contextMenus : Provide the right-click autofill menu. ✅alarms : Run the idle auto-lock timer in the background. ✅notifications : Show "Saved to vault" and breach-warning prompts. ━━ About the Developer ━━ OoKey is developed and operated by GOMOAL Inc., Tokyo, Japan. Website: https://ookey.jp Privacy Policy : https://ookey.jp/#privacy Terms: https://ookey.jp/#terms Support : nfo@gomoal.co.jp Source code: https://github.com/gomogy/ookey-browser With a zero-knowledge architecture, no one — including the developer — can read your vault.
0 out of 5No ratings
Details
- Version0.3.0
- UpdatedJuly 22, 2026
- Offered bypemhoo
- Size604KiB
- Languages2 languages
- Developer
Email
pemhoo@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
OoKey Password Manager has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
OoKey Password Manager handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site