Skip to content
← Back to Projects
Icono de Password Centinel
Private code Chrome / Chromium Firefox

Password Centinel

A fully local password manager: encryption, TOTP and breach checking

Before

contraseña123

↓

After

xK9#mQ2$vL7pR4wZ — TOTP: 482 913

Password Centinel

How it works

Password Centinel is a password manager that lives entirely in your browser: no account, no cloud, no first-party backend. AES-256-GCM encrypted vault, built-in TOTP/2FA, breach checking via Have I Been Pwned using k-anonymity, strength analysis, a passphrase generator, and CSV import from other password managers.

  1. 1

    Create your vault

    Set a master password; your vault is encrypted locally with AES-256-GCM from the very first second.

  2. 2

    Save and generate

    Add existing credentials or generate secure passwords and passphrases on the fly.

  3. 3

    Check and protect

    Analyze strength and check for breaches (HIBP) without your password ever leaving the browser.

Password Centinel

What it includes

  • AES-256-GCM encrypted vault

    Key derived from your master password via PBKDF2 (100,000 iterations, SHA-256). The master password never leaves browser memory.

  • Built-in TOTP / 2FA

    Generate one-time codes directly from the vault, with no external app required.

  • Breach checking (HIBP)

    Uses the Have I Been Pwned k-anonymity model: only 5 characters of a SHA-1 hash are sent, never your password.

  • Strength analysis

    Detects weak patterns and reused passwords across your vault.

  • Passphrase generator

    Generates secure passphrases and random passwords, fully configurable.

  • CSV import

    Import credentials from other password managers without leaving the browser.

Privacy and security

Privacy and security

Password Centinel is 100% local. It never sends your passwords, vault or personal data anywhere. It only reports a single anonymous install/update event (version and browser) to a first-party endpoint to gauge usage.

  • The full vault is stored encrypted in browser-local storage (chrome.storage.local); there is no cloud sync or user account.

  • The only network call is the k-anonymity lookup to api.pwnedpasswords.com: SHA-1 is computed locally and only the first 5 characters of the hash are sent.

  • It uses no third-party tracking tools (no Google Analytics, no Sentry, no cookies). The only event reported is install/update, and it never includes usage data, visited domains or anything from the vault.

  • CSV import and key handling are processed entirely in the browser; files you upload are never sent to a server.

Permissions and why they are requested

storage Stores the encrypted vault, settings and history locally in the browser.
tabs Identifies the active tab to send/receive autofill and form-detection messages.
contextMenus Adds "Generate and fill" / "Analyze password" entries to the right-click menu on editable fields.
activeTab Lets the popup interact with the visible page when the user invokes it.
host_permissions: <all_urls> The content script needs to detect password fields and login forms on any site to offer autofill.
host_permissions: api.pwnedpasswords.com The extension's only network request: k-anonymity lookup to check for breaches.

FAQ

Frequently asked questions

Is it paid? +

No. Password Centinel is completely free.

Does it work on Firefox? +

It is built for Chrome and Chromium-based browsers (Edge, Brave, Opera).

What data does it collect? +

None from your vault: it is stored encrypted locally, and the only network call is the k-anonymity lookup to Have I Been Pwned, which never reveals your full password. The extension also reports a single anonymous install/update event (version and browser) to gauge usage.

What happens if I lose my master password? +

Since there is no account or server, there is no recovery path: the master password is the only way to decrypt the local vault.