A new device needs your say
Approve its fingerprint from a trusted device before it can open your vault. Each device has its own unlock passphrase.
A different kind of password manager
Unique passwords and email aliases for the everyday web, backed by your ATProto identity.
Built for the web you already use.
Browser builds for ChromiumFirefoxSafari on macOS
One identity, many possibilities
Keep using ordinary websites. kaleID creates the credentials; you stay in control of where they go.
Connect your ATProto account, create a local vault and save your recovery phrase.
Your existing ATProto handleGenerate a password and email alias for each site account. Mail reaches your verified inbox through your chosen provider.
Distinct credentials for each accountApprove the exact website address before autofill. You review the credentials and submit the form yourself.
Explicit approval, every new originYour device holds the key. Encrypted site and account policies sync to your ATProto personal data server.
Your PDS can still see your identity, record counts and update timing.
Approve its fingerprint from a trusted device before it can open your vault. Each device has its own unlock passphrase.
Give websites a generated address instead of your usual email. Incoming messages stay in your kaleID inbox; they are never forwarded.
Save your 24-word recovery phrase and export an encrypted backup. The separate recovery utility can restore that backup offline.
Good questions to ask before trusting a new password manager.
No. Websites receive a normal email alias and generated password. kaleID does not send them proof of your ATProto identity.
kaleID is in early development. Setup currently involves building the extension and configuring an inbox provider with an owned domain, MX and SMTP TLS. Review the deployment requirements in the setup guide before relying on it.
Your inbox provider receives and stores messages encrypted at rest, but the running service and host operator can decrypt them. An alias keeps your usual address away from the website; messages are not forwarded to another mailbox.
A trusted device can approve a replacement. Keep your recovery phrase and an exported encrypted backup somewhere safe: the offline utility recovers credentials from your backup without contacting a server.
Your PDS sees identity and activity metadata, even though policy contents are encrypted. Once you fill a credential, that website can read it. Backups offer best-effort protection against missing or rolled-back PDS records.
Start with the foundations
kaleID is an early project for hands-on users. Start with the build guide and a provider you trust.
Download setup guideFrom the project checkout, with Node.js 24+ and npm 12+:
npm install
cp apps/extension/.env.example apps/extension/.env
Configure the OAuth metadata URL and handle resolver in that environment file, then build for Chromium:
npm run build:extension
Load apps/extension/.output/chrome-mv3 as an unpacked extension in your browser’s extension settings.
Firefox and Safari have separate build and packaging commands in the guide. Browser-specific OAuth redirects must match your deployment.
Use an operator-issued invitation, or configure your own inbox service with HTTPS, an alias domain and inbound SMTP/TLS. Messages sent to your kaleID aliases are stored in the inbox and are not forwarded to another mailbox. Open the extension inbox after connecting ATProto and unlocking your vault.
Connect your ATProto identity in the extension and set a local passphrase. Write down and verify your 24-word recovery phrase, then export an encrypted backup.