A different kind of password manager

Your identity.
On your terms.

Unique passwords and email aliases for the everyday web, backed by your ATProto identity.

A six-fold kaleidoscope of mint-green mirrored facets

Built for the web you already use.

Browser builds for ChromiumFirefoxSafari on macOS

One identity, many possibilities

A familiar login.
A different foundation.

Keep using ordinary websites. kaleID creates the credentials; you stay in control of where they go.

  1. Bring your identity

    Connect your ATProto account, create a local vault and save your recovery phrase.

    Your existing ATProto handle
  2. Make each login its own

    Generate a password and email alias for each site account. Mail reaches your verified inbox through your chosen provider.

    Distinct credentials for each account
  3. Choose where to fill

    Approve the exact website address before autofill. You review the credentials and submit the form yourself.

    Explicit approval, every new origin

Your vault key
stays local.

Your device holds the key. Encrypted site and account policies sync to your ATProto personal data server.

On your device Vault root key Protected by your local passphrase
On your PDS Encrypted policies Site and account contents stay encrypted

Your PDS can still see your identity, record counts and update timing.

A new device needs your say

Approve its fingerprint from a trusted device before it can open your vault. Each device has its own unlock passphrase.

An alias for each account

Give websites a generated address instead of your usual email. Incoming messages stay in your kaleID inbox; they are never forwarded.

A way back, kept by you

Save your 24-word recovery phrase and export an encrypted backup. The separate recovery utility can restore that backup offline.

A little more
clarity.

Good questions to ask before trusting a new password manager.

Does a website need to support ATProto?

No. Websites receive a normal email alias and generated password. kaleID does not send them proof of your ATProto identity.

Is kaleID ready to use?

kaleID is in early development. Setup currently involves building the extension and configuring an inbox provider with an owned domain, MX and SMTP TLS. Review the deployment requirements in the setup guide before relying on it.

Who can see my email?

Your inbox provider receives and stores messages encrypted at rest, but the running service and host operator can decrypt them. An alias keeps your usual address away from the website; messages are not forwarded to another mailbox.

What happens if I lose a device?

A trusted device can approve a replacement. Keep your recovery phrase and an exported encrypted backup somewhere safe: the offline utility recovers credentials from your backup without contacting a server.

What are the privacy limits?

Your PDS sees identity and activity metadata, even though policy contents are encrypted. Once you fill a credential, that website can read it. Backups offer best-effort protection against missing or rolled-back PDS records.

Start with the foundations

Make it yours.

kaleID is an early project for hands-on users. Start with the build guide and a provider you trust.

Download setup guide
Build and install the extension

From the project checkout, with Node.js 24+ and npm 12+:

npm install
cp apps/extension/.env.example apps/extension/.env

Configure the OAuth metadata URL and handle resolver in that environment file, then build for Chromium:

npm run build:extension

Load apps/extension/.output/chrome-mv3 as an unpacked extension in your browser’s extension settings.

Firefox and Safari have separate build and packaging commands in the guide. Browser-specific OAuth redirects must match your deployment.

Set up an inbox

Use an operator-issued invitation, or configure your own inbox service with HTTPS, an alias domain and inbound SMTP/TLS. Messages sent to your kaleID aliases are stored in the inbox and are not forwarded to another mailbox. Open the extension inbox after connecting ATProto and unlocking your vault.

Create your vault

Connect your ATProto identity in the extension and set a local passphrase. Write down and verify your 24-word recovery phrase, then export an encrypted backup.