Unlock your vault
Your items are encrypted on this device. We never receive the key, so nothing here is readable without your passphrase.
Continue with GoogleQuick actions
Recently updated
0 items · Decrypted only in this tab, and re-locked after 10 minutes of inactivity.
Vault health
Calculated in your browser, after decryptionUnlock your vault to run the audit.
Breach check runs automatically a moment after you unlock.
Items that need attention
Your API key
Read the docs →Send it as Authorization: Bearer <key>.
Keep it server-side; rotating replaces it immediately.
Attribution link
The API is free in exchange for one public link back to our docs. Add this anywhere on your site, then verify it here:
<a href="https://passwordgenerator.now/2fa-api"> Two-factor authentication powered by PasswordGenerator.now </a>
We re-check daily. The first time a verified link
disappears you get a 7-day grace window and an explanation - Never a silent shutdown.
A repeat disappearance pauses the key straight away; restoring the link re-activates
it. A
rel="sponsored" or rel="nofollow" link passes too.
Account
| - | |
| Name | - |
| Sign-in method | - |
| Encryption | AES-256-GCM, PBKDF2-SHA256 (600,000 iterations) |
Two-factor authentication (2FA)
Scan this QR with Google Authenticator, Authy, 1Password or any TOTP app - Or paste the secret manually. Then confirm with a code:
Auto-lock
The vault re-locks and wipes its in-memory key after this much inactivity in the tab.
Change master passphrase
Every item is decrypted in this browser and re-encrypted with a key derived from the new passphrase - The server only ever sees ciphertext, before and after. The change is atomic: it either fully succeeds or nothing changes.
Backup & export
Encrypted backup (recommended) protects the file with a password of its own using the same AES-256-GCM scheme as the vault. Plain JSON is readable by anyone who opens the file - Handle with care.
Import passwords
Bring passwords in from a previous export (
.json or encrypted .pgnvault) or a CSV exported by Chrome,
Edge, Firefox, Bitwarden or LastPass. Everything is encrypted on this device before
it is uploaded - The file itself never leaves your browser.
Danger zone
Deleting your account removes every stored item and your API key immediately. This cannot be undone.