Documentation
Keyorra
A password manager for macOS: an encrypted vault on your Mac and a browser extension for Chrome, Firefox and Safari. This guide covers setup, everyday use, moving from 1Password and how your data is protected.
Install
Keyorra runs on macOS. Download the latest release from GitHub Releases, drag Keyorra.app into Applications and open it.
Create your vault
On first launch Keyorra asks for a master password. It encrypts everything else and is never stored anywhere.
- Choose a long passphrase you can type reliably, for example four or five random words.
- There is no reset. If the master password is lost, the vault cannot be opened by anyone.
- Write it down and keep it somewhere safe, offline.
Lock and unlock
Type the master password to unlock. Keyorra locks itself:
- after a few idle minutes (set in Settings, 5 minutes by default);
- when the Mac sleeps or the screen locks;
- when you choose Lock in the sidebar.
After five wrong passwords Keyorra makes you wait before the next try: one second, then two, four and so on, up to five minutes.
Items and fields
Choose New above the list and pick a kind. Each kind starts with the fields it needs:
| Kind | Starts with |
|---|---|
| Login | Username, password, websites |
| Secure note | Free text |
| Password | A single password |
| Credit card | Cardholder name, number, expiry date, verification number |
| Identity | First name, last name, email, phone |
| API credential | Username, credential, hostname |
Add your own fields in the editor: text, hidden, URL, email, phone or a one-time code. Tags help group things across vaults.
Vaults, favorites, search
- Vaults keep things apart, for example Personal and Work. Create one with New vault in the sidebar.
- Favorites collect starred items from every vault.
- Search above the list filters as you type.
Copying
Hover a field to see its buttons: the eye reveals a hidden value, the copy button puts it on the clipboard. Keyorra clears the clipboard by itself after 90 seconds (adjustable in Settings), so a copied password doesn't linger.
One-time codes
Add a one-time code field to a login and paste the setup key from the site (the text under its QR code) or an otpauth:// link. Keyorra shows the current six-digit code with a ring that counts down to the next one. Copy it from the item, or let the browser extension fill it after the password.
Password generator
The generator makes random passwords or memorable passphrases. Choose the length and character sets; the value updates as you change them. It is available in the item editor and, through the extension, on sign-up forms.
Recently deleted
Deleting an item asks for confirmation right in its header, then moves it to Recently Deleted. Items stay there for 30 days and can be restored with one click. When you change a login's password, the old one is kept in that item's history.
Settings and themes
- Appearance: System, Light, Dark or Index. System follows macOS.
- Lock after a period of inactivity, and lock when the Mac sleeps.
- Clear clipboard after a set time.
- Change master password. Only the account key is re-encrypted, so it takes a moment however large the vault is.
- Browsers: connect the extension (see below).
Import from 1Password
- In 1Password, choose File → Export and save a
.1puxfile (or CSV). - In Keyorra, choose Import… in the sidebar and pick the file.
- Check the preview: how many logins, notes, cards and identities were found, and which vaults they go to.
- Choose Import. One-time code secrets come across with their logins.
Install the extension
The extension works in Chrome and other Chromium browsers (Brave, Edge, Opera, Yandex Browser), Firefox and Safari. It never stores your secrets; it asks the Keyorra app on the same Mac for each fill.
chrome://extensions → Developer mode → Load unpacked, or in Firefox about:debugging → Load Temporary Add-on.Connect and pair
- In Keyorra open Settings… → Browsers → Connect browsers. This registers the app with every browser it finds. Run it again if you move the app.
- Click the Keyorra icon in the browser toolbar and choose Connect.
- Keyorra shows a six-digit code. Check it matches the one in the browser and confirm.
Fill, save, generate
- Fill: focus a login field, click the Keyorra icon in it and pick a login. Username, password and one-time code are filled. You can also set a shortcut for “Fill the best login” in
chrome://extensions/shortcuts. - Save: after you sign in with a new password, Keyorra offers to save the login or update the existing one.
- Generate: on sign-up and change-password forms the icon offers a strong password. Keyorra saves it as a draft login at once, so it is never lost if the page fails.
- Cards and addresses: offered only on secure (https) pages, this Mac or your local network. Payment fields inside separate frames are filled one at a time.
Safari
Safari loads extensions only from inside a Mac app, so the extension ships as Keyorra for Safari.
- Open Keyorra for Safari and choose Open Safari Extensions Settings.
- Turn on Keyorra and allow it on websites.
- Pair as above. The app shows the request as “Safari”.
The Safari extension is sandboxed: its only permission is to talk to the Keyorra app, and it starts the app if it isn't running.
Security model
- Key derivation: Argon2id over your master password with a random salt, 64 MiB of memory and three passes, gives the key-encryption key. The parameters are stored with the vault so they can be raised later.
- Key hierarchy: that key unwraps a random account key, which unwraps one random key per vault, which encrypts that vault's items.
- Items: XChaCha20-Poly1305 with a fresh random nonce on every save. Each item is bound to its vault and id, so swapping encrypted items between vaults or items fails.
- No password hash: a wrong password simply fails to unwrap the account key.
- Memory: keys are wiped when the vault locks; decrypted items are dropped.
- No home-made crypto: standard Rust crates (
argon2,chacha20poly1305,zeroize) and the operating system's random generator. - Browser: the extension holds no secrets. It talks to the app over a local channel after pairing, and fills cards and addresses only on secure pages.
Where your data lives
Everything is in the app's folder in ~/Library/Application Support, encrypted. Keyorra has no server and sends nothing anywhere. Back the folder up like any other file; without the master password the backup is unreadable.