KeyLockr

E2E Encrypted Password Manager - Your passwords, your control

Free E2E Encrypted Cross-Platform Zero Knowledge

Download

macOS: Build 260805.0448 · 9.0 MB · Requires macOS 13.0+
Android: Build 260805.0530 · 28.6 MB · Requires Android 7.0+
Chrome: v4.1.2 · Install via Chrome Web Store

Why KeyLockr?

Security without compromise, simplicity without complexity

End-to-End Encryption

Your data is encrypted on your device before it ever leaves. Only you can decrypt it.

Zero Knowledge

We cannot see your passwords. Even if our servers are breached, your data remains secure.

Phone-Centric

Your phone is the master key. Approve access requests from any device with a single tap.

2FA Built-in

Store and generate TOTP codes alongside your passwords. One app for everything.

SSO Integration

Login to third-party apps with KeyLockr. One tap, zero passwords to remember.

Secure Sync

Seamlessly sync across all your devices. Your encrypted vault, everywhere you go.

How It Works

Simple, secure, and seamless

1
Setup on Phone

Install KeyLockr on your phone and start using immediately

2
Connect Devices Optional

Scan QR code to connect your Mac, PC, or browser extension

3
Approve Access Optional

When other devices need a password, approve the request on your phone

One picture: who holds the keys, and who does not

Keys are created by the very devices that use them, and content is locked before it is sent. We keep the locked things, and hold nothing that opens them.

Zero knowledge Two layers of locking A new random value on every save Approved on your phone
Who holds the keys Devices you approved can read your content; what sits on the server is locked. A third-party app receives only results or data addressed to it, within the scope you approved.
Keys start on your phone
Your account key is created on your phone and never handed to us. Every new device is approved from there, too.
Your computer needs a key from the phone
The Mac app and the extension get their own copy of the key, but they cannot approve another device or service — and you can cut them off at any time.
Things are locked before they are sent
Content is locked on your device first, and the key travels in a packet only the receiving device can open. One altered byte and the whole thing is refused.
What we store is locked
The server and its backups hold the same locked bytes, plus routing, account, and version metadata. There is no master password, and no key that opens the vault.

Security Architecture

Vault content and sensitive metadata remain encrypted on the server; only authorized devices holding the corresponding keys can read them.

Two-Layer Encryption
  • Light Encryption: For titles, website URLs, and 2FA labels. Encrypted with your Account Key so our servers can't read them. Desktop and browser devices securely receive this key after phone authorization, enabling quick browsing without per-item approval.
  • Strong Encryption: For actual passwords and sensitive note content. Each file has its own independent filekey. Requires phone approval for each access (or set device to auto-approve mode).
Zero Knowledge

Secret keys are generated locally and remain in plaintext only on the devices that hold them. The server stores encrypted vault fields, sealed envelopes, public keys, and operational metadata, but no key that decrypts vault content. Key transfers between devices are encrypted for the named recipient.

Data Storage

Data is stored both locally on your phone and in the cloud. Works offline anytime. Cloud sync ensures you can restore data whenever needed.

Auto Backup

Phone supports automatic backup with 7-day retention. All backup data is encrypted with your account key. Backup files can be downloaded and imported to other accounts (with correct key).