This password manager keeps every sensitive field encrypted with AES-256-GCM and derives the master key locally using PBKDF2-HMAC-SHA256 with 400,000 iterations. The vault, browser extensions, AutoFill, health audit, breach check, TOTP codes, passkey metadata, and encrypted backups run offline without an account. Multi-device sync remains optional and uses a relay that only passes encrypted messages. No analytics, no advertising, no third-party tracking SDKs, and no server-side vault storage. Available on macOS, iOS, Windows, and Android with the same feature set on every platform.
Users who need credential storage without cloud dependency can rely on MyPwdTool for daily password, passkey, and TOTP management. The application flags weak or reused passwords on-device, checks breaches through k-anonymity, and produces encrypted local backups. Browser extensions and system AutoFill cover Chrome, Edge, Firefox, Safari, iOS, macOS, and Android. A yearly subscription enables sync across devices through a relay that cannot read vault contents. Joining an existing group costs nothing.
MyPwdTool suits individuals and professionals who want separate personal and work vaults, biometric unlock between master-password prompts, and a complete local activity log. CSV import and export simplify migration, while encrypted backups protect against device loss. The program avoids account creation, server-side storage, and tracking SDKs. Made in France by developer TDucray137, with the relay source code planned for independent review.
| Encrypted container holds logins, usernames, passwords, notes | AES-256-GCM field isolation, keys only in volatile memory |
| Stores passkey metadata without exposing private key material | Complete inventory of registered authentication methods per service |
| Built-in TOTP generation alongside stored passwords | Rotating six-digit codes produced on-device without network |
| Credit card numbers, expiry, names, security codes encrypted | Independent field encryption, searchable alongside password entries |
| Several vaults each with own master password and keys | Cryptographically independent, unlocking one grants no access to others |
| Extensions for Chrome, Edge, Firefox plus native Safari | System AutoFill provider integrates with OS credential framework |
| Audit flags weak, reused, old credentials in stored vault | Length and composition analysis, hashed comparison, on-device only |
| Breach check uses k-anonymity with SHA-1 prefix query | Service never receives password or complete hash value |
| Encrypted backup files protected by master password | Restore replaces or merges with current vault as chosen |
| Imports credentials from CSV exported by other managers | Export produces plaintext file with sensitivity warning attached |
| Records unlocks, failed attempts, creations, modifications, deletions | Local encrypted audit trail without plaintext entry contents |
| Tracks last successful sync time per vault | Reminder appears when interval exceeded without network needed |
| Direct device-to-device sync through encrypted relay server | Relay cannot read vault, password, or account data even if compromised |
| PBKDF2-HMAC-SHA256 with 400,000 iterations derives encryption key | Master password never stored, no recovery mechanism exists |
| No analytics, advertising, tracking SDKs, or account system | Does not phone home or collect telemetry from the application |