KeyLockr is a zero-knowledge password manager where your phone holds the only key to your data. All passwords, secure notes, and 2FA codes are encrypted on your device before syncing to the cloud — our servers never see your plaintext data. Access from desktop or browser requires real-time mobile authorization, ensuring only you can decrypt your secrets. Your data is always backed up, always encrypted, and always under your control.
more Fixed a crash caused by malformed messages.
Unified request size limits at 4MiB
5.4.8 10 Sept
- Sign-in now applies the same standard email validation to every account.
- Static Plugin cells now honor service-provided semantic colors in light and dark mode.
- Temporary server failures now show a friendly retry message without signing you out or clearing local security data.
5.4.6 28 Aug
Plugin icons now refresh immediately when a service updates the shared icon set, without waiting for the screen to reload.
5.4.4 21 Aug
Improved plugin icons.
5.4.2 21 Aug
- Sending debug logs now asks for confirmation first, showing what the logs contain, what they never contain, and where they are sent, with a link to the Privacy Policy
- Automatic unlock now covers App Data connections, not just Access Points, so an approved app can refresh its data without a separate approval each time
- Plugin actions can now show service-provided icons and semantic colors, making it easier to tell apart actions such as ordering and canceling
- Plugins that provide their own artwork now show it as their tab icon instead of the generic placeholder
5.4.1 19 Aug
- Search results now highlight matches in password, note, and 2FA list titles, with clear dark-mode contrast.
- Note search clearly distinguishes the current match from other matches.
- Password search finds usernames immediately, including one-character and fuzzy matches.
- Plugin actions have improved VoiceOver support: visible titles remain accessible names, while icon-only actions use service-provided labels.
5.3.0 15 Aug
- Debug log results now appear beside the Send button, with clear error messages on failure.
- Pinch-to-zoom on Plugin pages now reflows content, keeping text sharp.
- Account reset, user deletion, and alias confirmation screens now scroll when the keyboard is open.
- Plugin data rows now honor service-provided column widths, with unspecified text left-aligned.
5.2.5 14 Aug
- Debug log send results now appear beside the Send button, with visible error text when sending fails.
- Pinch-zoom on Plugin pages now re-lays out the content, so text stays sharp at every zoom level.
5.2.1 14 Aug
Plugin page UI tuning
5.1.7 13 Aug
Plugin actions can now appear beside the page title, with long titles shortened cleanly so the action stays accessible.
5.1.5 12 Aug
- Authorization no longer shows a stalled return countdown when the result is handed directly back to the requesting app.
- Spreadsheet formulas, formatting, and display calculations are more efficient, keeping large sheets responsive.
- Approved App Data is returned directly to the requesting app without requiring a second unlock request.
5.1.3 11 Aug
- Device lists now prioritize device names, show app setting names and added times, and keep IDs in details
- New pairings and app authorizations now refresh devices immediately, preventing stale “Device not found” errors
- Debug logs can now be sent securely to support with a six-digit reference code and a 60-second cooldown
- “Access Point” is now written out in full throughout the app and highlighted clearly during authorization
- Authorization now lists each requested permission, and the full page scrolls when needed
- SSO/Access Point authorization confirmation text now wraps to show the full message without truncation
- App authorizations opened from another app now return to the source app after five seconds, while still allowing decryption requests to be reviewed before returning
- Account Key Backup now uses an improved recovery screen; existing security answers open verification first, with a re-setup link when needed.
5.0.2 11 Aug
- KeyLockr and SSO links now open the Safe directly.
- Links received before sign-in automatically continue after sign-in.
4.6.0 19 Jul
• Stronger encryption: every password and note update now uses a fresh random nonce
• Existing items and revision history upgrade automatically in the background — no change to modification dates or list order
• Data upgrade progress now shows at the top with total and remaining item counts
• Fixed an issue that could prevent some revision histories from completing the background data upgrade
4.5.0 18 Jul
Stronger encryption with a fresh random nonce.
4.4.0 15 Jul
Improved plugin page description render style.
4.2.3 14 Jul
Improved reminder and plugin desc.
4.2.2 14 Jul
* Improved plugin loading speed. Refactored plugin workflow.
* Added changelog to setting.
4.2.0 13 Jul
Fixed the tag migration stability in v4 light encryption.
Ability to reveal and copy the original 2FA secret from the edit screen.
4.1.0 29 Jun
- Account Key encryption: your titles, website URLs, and 2FA labels are now end-to-end encrypted — zero-knowledge, the server can no longer read them.
- Share Extension: send content into KeyLockr straight from other apps' share sheets, encrypted inside the extension before it's saved.
- Smarter search: now matches note body text and password notes, with consistent fuzzy matching across every list.
- Stays signed in: brief network drops no longer log you out.
- Zero-knowledge pairing and encrypted device names.
- Stability & recovery: fixed startup crashes (non-Latin spreadsheet formulas, corrupted metadata) and automatically recovers titles that briefly showed as locked after enabling encryption.
4.0.0 25 Jun
- Fixed a "Data encoding error" that could prevent notes/passwords from saving when tags or URL were empty.
- Fixed the delete-account confirmation field rejecting letters, which blocked the server's alphanumeric codes.
3.8.8 16 Jun
Tags: organize passwords and notes with colored tags
3.8.6 11 Jun
New: Log in with your SafeID
You can now sign in using your SafeID — not just your email or phone. Just type your SafeID in the login field, then confirm with the email or mobile linked to it (we show a masked hint of which one to use). Existing email/phone login works exactly as before.
3.7.6 9 Jun
- Notes: native text selection in read-only note body — long-press to select a word, see the selection highlighted, and drag the start/end handles
- Masked password fields in notes: wrap sensitive text as [hide]secret[/hide] to show it as dots — eye icon to reveal, tap to copy (green check + the whole field briefly highlights), whole-field highlight on hover, and hidden values are still found by search
- Recovery reliability fixes: verifying recovery no longer wipes your saved security questions; corrupted recovery data is now detected and you're prompted to set it up again; Settings now shows whether your security questions are set
- Share: opening Share now shows who the file is already shared with, including pending (not-yet-accepted) invitations
- Plugin pages: data older than 10 minutes auto-refreshes from the server (with a loading indicator at the top) so you no longer see stale data
3.7.0 7 Jun
Device sorted by mtime
3.6.2 26 May
Fixed a crash caused by malformed messages.
Unified request size limits at 4MiB
more Version 5.4.8 10 Sept
Data Linked to You The following data may be collected and linked to your identity:
Contact Info User Content