Open source · Offline · No account

Remember one passphrase.
Get the same strong password everywhere.

EasyPwd calculates a unique password for each website from your email, your passphrase, and the site's name. Install it on another computer, type the same two things, and every password is already there. Nothing is synced, because there's nothing to sync.

EasyPwd showing a list of logins and the generated password for github.com

How it works

  1. Enter your email and a passphrase. EasyPwd shows four words, your key fingerprint. Write them down.
  2. Type a website and press Enter. github.com, https://www.github.com/login and GitHub.com all give the same password.
  3. On a new device, do the same. If the four words match, every password matches. If they don't, you made a typo.

Inside the extension

Five screens, one idea: nothing to sync, nothing to lose.

  1. 01

    Set up in a minute

    Your email and one passphrase. No account, no sign-up, no server.

    The setup screen asking for an email and a master passphrase
  2. 02

    Every login in one list

    Generated and saved logins side by side. Search, copy, done.

    The list of logins with a generated password for github.com
  3. 03

    A password for any new site

    Type a website and its password is already there. Set length and characters per site.

    Creating a login for stripe.com with its generated password and rules
  4. 04

    Typos caught right away

    Four words only your email and passphrase can produce. Same words on every device.

    The four-word key fingerprint dialog
  5. 05

    Breached? One click.

    Get a new password, and keep the old one until you have changed it. Dark mode included.

    A rotated password showing the new and previous versions, in dark mode

What a plain password generator gets wrong

Calculated passwords are an old idea. Here is what usually goes wrong, and the fix.

A site gets breached

Bump its version for a fresh password.

Picky password rules

Set length and symbols per site.

Passwords you can't change

Keep them in an encrypted local vault.

A typo in your passphrase

Four words flag it instantly.

Try it

This runs the extension's own code in this page. Nothing leaves your browser, but use made-up values here, not your real passphrase.

1Your secrets the same on every device

Key fingerprint

Different words on another device? You made a typo.

Try it: change one letter of the passphrase and watch all four words change.

2Any website

Password for github.com v1

abcABC123#$&

Characters

Security, without the marketing

  • No network access. The extension's security policy blocks all connections.
  • Two permissions: storage and clipboardWrite.
  • Zero dependencies. Only the browser's built-in Web Crypto.
  • The algorithm is published as a spec with test vectors, and tested against an independent implementation.

The tradeoff

Anyone who learns your passphrase and email can calculate every generated password, without needing your vault. A single leaked site password also lets an attacker test passphrase guesses offline. Use a long passphrase of several unrelated words, and don't reuse it.

EasyPwd has not been independently audited.