Password Centinel
A fully local password manager: encryption, TOTP and breach checking
Before
contraseña123
↓
After
xK9#mQ2$vL7pR4wZ — TOTP: 482 913
Password Centinel
How it works
Password Centinel is a password manager that lives entirely in your browser: no account, no cloud, no first-party backend. AES-256-GCM encrypted vault, built-in TOTP/2FA, breach checking via Have I Been Pwned using k-anonymity, strength analysis, a passphrase generator, and CSV import from other password managers.
- 1
Create your vault
Set a master password; your vault is encrypted locally with AES-256-GCM from the very first second.
- 2
Save and generate
Add existing credentials or generate secure passwords and passphrases on the fly.
- 3
Check and protect
Analyze strength and check for breaches (HIBP) without your password ever leaving the browser.
Password Centinel
What it includes
-
AES-256-GCM encrypted vault
Key derived from your master password via PBKDF2 (100,000 iterations, SHA-256). The master password never leaves browser memory.
-
Built-in TOTP / 2FA
Generate one-time codes directly from the vault, with no external app required.
-
Breach checking (HIBP)
Uses the Have I Been Pwned k-anonymity model: only 5 characters of a SHA-1 hash are sent, never your password.
-
Strength analysis
Detects weak patterns and reused passwords across your vault.
-
Passphrase generator
Generates secure passphrases and random passwords, fully configurable.
-
CSV import
Import credentials from other password managers without leaving the browser.
Privacy and security
Privacy and security
Password Centinel is 100% local. It never sends your passwords, vault or personal data anywhere. It only reports a single anonymous install/update event (version and browser) to a first-party endpoint to gauge usage.
-
The full vault is stored encrypted in browser-local storage (chrome.storage.local); there is no cloud sync or user account.
-
The only network call is the k-anonymity lookup to api.pwnedpasswords.com: SHA-1 is computed locally and only the first 5 characters of the hash are sent.
-
It uses no third-party tracking tools (no Google Analytics, no Sentry, no cookies). The only event reported is install/update, and it never includes usage data, visited domains or anything from the vault.
-
CSV import and key handling are processed entirely in the browser; files you upload are never sent to a server.
Permissions and why they are requested
| storage | Stores the encrypted vault, settings and history locally in the browser. |
| tabs | Identifies the active tab to send/receive autofill and form-detection messages. |
| contextMenus | Adds "Generate and fill" / "Analyze password" entries to the right-click menu on editable fields. |
| activeTab | Lets the popup interact with the visible page when the user invokes it. |
| host_permissions: <all_urls> | The content script needs to detect password fields and login forms on any site to offer autofill. |
| host_permissions: api.pwnedpasswords.com | The extension's only network request: k-anonymity lookup to check for breaches. |
FAQ
Frequently asked questions
Is it paid? + −
No. Password Centinel is completely free.
Does it work on Firefox? + −
It is built for Chrome and Chromium-based browsers (Edge, Brave, Opera).
What data does it collect? + −
None from your vault: it is stored encrypted locally, and the only network call is the k-anonymity lookup to Have I Been Pwned, which never reveals your full password. The extension also reports a single anonymous install/update event (version and browser) to gauge usage.
What happens if I lose my master password? + −
Since there is no account or server, there is no recovery path: the master password is the only way to decrypt the local vault.