Overview
Zero-knowledge password manager. Secrets are decrypted only in your browser — TATER's servers never see them.
TATER Vault is the browser companion to the TATER platform. It holds the credentials, secrets, and recovery codes your team needs for the systems you manage, with one architectural rule that drives every design decision: TATER's servers never see your decrypted vault. ZERO-KNOWLEDGE, VERIFIABLY - End-to-end encryption. You sign in with Microsoft Entra ID (SSO — there is no master password). Your vault key is unwrapped by a device-bound, non-extractable WebCrypto key that lives only in this browser. Items are AES-256-GCM encrypted in the browser before they reach TATER; ciphertext is all the server ever stores or sees. - New devices authorize, keys re-wrap client-side. Adding this extension as a device is an SSO-gated release from your organization's Azure Key Vault, re-wrapped locally to this browser's key. After that, unlock is a fast local operation. - Open crypto. The same vault-crypto.js library is used byte-for-byte by the extension and the web vault, and the design is documented end to end in the public VAULT-CRYPTO-DESIGN doc. Audit it yourself. FILL AND SAVE, WITHOUT THE CREEPINESS - Inline fill icon. A small TATER glyph appears inside username/password fields when your unlocked vault has a match for that site. Click it, pick the account, and the exact field you targeted is filled — nothing fills silently, and one site can never see logins saved for another. - Works on real-world login pages. Field discovery pierces open shadow DOM and same-origin iframes, and fills reach cross-origin iframe forms too — so component-based sign-in pages (Microsoft, Apple-style flows) just work. - Save and update prompts. After you sign in with credentials the vault doesn't know, the extension offers to save them — or to update the stored item when the password changed. Your click decides, every time; there's a per-site "never offer here", and prior passwords are kept inside the encrypted item when you update. - Popup autofill too. The popup ranks matches for the active tab first, and can fill extra site-specific inputs via custom-field tags (tenant IDs, database names). - Background unlock, on your terms. Choose how long the vault stays usable after the popup closes — 15 minutes to 24 hours, or until the browser closes — with an automatic re-lock timer. Or turn autofill off entirely. A FULL VAULT IN THE TOOLBAR - Nine item types: logins, secure notes, payment cards, bank accounts, identities, SSH keys, API credentials, software licenses, custom. - Live 2FA codes. Store a TOTP secret and the popup shows the rotating code with a countdown — copy without ever seeing the raw secret. - Password generator (8 to 64 chars) built into a dedicated tab. - Group vaults. Items shared with your team decrypt locally with per-user RSA key wrapping — the server brokers only encrypted blobs. - Organization switcher for users who belong to more than one TATER org. - Copy with auto-clear (about 30 seconds) and fill-only passwords that can be filled into pages but never displayed or copied. - Site icons and badge. Item icons come from your browser's own favicon cache (no third-party icon service), and the toolbar badge shows how many logins match the site you're on. - TATER Send shortcut for time-limited, optionally one-time sharing of a secret or file via the TATER Send web page. WHAT WE STORE (AND DON'T) - On TATER servers: ciphertext of your vault items; item metadata (type, title, and the site hostname used for matching and icons); wrapped key material the server cannot use; and audit-log entries recording when items are accessed (by whom, when, from which device) — never what was inside. - In this browser only: the non-extractable device key, and memory-backed session state (sign-in tokens and the device-wrapped key bundle) that clears when the browser closes. - Never: a master password (there isn't one — Entra ID SSO is the identity), decrypted vault contents on our side, page content, browsing history, or analytics of any kind. WHO THIS IS FOR TATER Vault is built for organizations with a TATER tenant. Without one, the extension can sign you in via Microsoft Entra ID but cannot unlock a vault (server-side enrollment is required).
5 out of 51 rating
Details
- Version1.2.3
- UpdatedJuly 27, 2026
- Size168KiB
- LanguagesEnglish
- DeveloperTATER SecurityWebsite
459 Lafayette Rd Hampton, NH 03842-2241 USEmail
support@tatersecurity.comPhone
+1 317-289-8921 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S147776239
Privacy
TATER Vault has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
TATER Vault handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site