Blackbox is a zero-knowledge password, secret & autofill manager. Your master password and keys never leave your device — our servers only ever hold encrypted ciphertext. One account, every device: sign in anywhere and your vault follows you.
AES-256-GCM · ARGON2ID · ZERO-KNOWLEDGENine item types — logins, API keys, SSH & encryption keys, servers, databases, cards, identities, Wi-Fi, secure notes — with live TOTP codes, a strength-audited generator, and search across everything.
Add a login on your desktop and it's on your phone's browser before you've switched chairs. Everything syncs through the encrypted Blackbox cloud — and every app works offline.
The full manager, running entirely in your browser — decryption included.
Blackbox where you actually type passwords — in the browser.
A native window, always a keystroke away — same vault, same sync.
One click fills username + password on the site you're on.
Logins, API keys, SSH keys, servers, databases, cards, identities, Wi-Fi, notes.
Store the TOTP seed, read live 6-digit codes with a countdown.
Passwords & passphrases with entropy and crack-time estimates.
Import from LastPass, Bitwarden, 1Password, Chrome, KeePass, Dashlane.
Forgot the master password? Email + SMS codes + your security answers restore access. The server alone can never decrypt.
Changes land on every signed-in device in seconds — ciphertext only.
Copied secrets auto-clear ~25 seconds later — never wiping what you copied next.
"Trust us" isn't a security model. Here is the actual key hierarchy — the server is mathematically incapable of reading your vault.
master password ──Argon2id(salt)──▶ master key # never stored, never sent │ ┌───HKDF───────┴────────HKDF───┐ ▼ ▼ encryption key auth key # server sees only a hash │ ▼ random vault key ──AES-256-GCM──▶ wrapped vault key # useless without your password │ ▼ every item ──AES-256-GCM──▶ ciphertext # the only thing our servers store
chrome://extensions (or edge://extensions).