Features
Keys, wallet, and a watch on the lot
KeysWalletWatch keeps the passwords you use every day, the details you need now and then, and an eye on how safe they all are. Every feature on this page is in the app today.
What can KeysWalletWatch store?
Logins with their two-factor (TOTP) codes, backup MFA codes, and notes for anything else: card and ID details, Wi-Fi keys, alarm codes, instructions. Every entry can carry custom fields and notes, belong to an account and an owner, and be starred as a favorite. With Developer Mode on it also stores API keys, secrets, environment-variable sets, SSH keys, database credentials and certificates.
Keys
Every login, with its two-factor code beside it
Search the whole vault from one box and copy what you need in a click.
Logins
Username, password, web address, notes and any custom fields you add. Mark a custom field sensitive and it's hidden like a password.
Two-factor codes
Paste a site's authenticator secret and the entry shows the live 6-digit code with a countdown ring, ready to copy.
Backup MFA codes
A dedicated entry type for the one-time recovery codes sites give you when you turn on two-factor.
Password generator
8 to 128 characters from upper case, lower case, digits and symbols, with an option to leave out look-alikes such as 0 and O. A strength meter rates every password as you type.
Clipboard that cleans up
Copied passwords are cleared from the clipboard after 30 seconds by default (10 seconds to 2 minutes), and only if you haven't copied something else since.
Password history
When a password changes, the old one is saved inside the entry (the last 10), including the losing side of a sync conflict. A screen for browsing them isn't in the app yet.
Wallet
Cards, IDs and the things you keep having to look up
Not everything is a login. Notes hold card details, ID numbers, Wi-Fi keys, alarm codes and instructions, all inside the same encrypted file.
Notes
A Note entry is for anything that isn't a login: card numbers, passport details, insurance policies, the gate code.
Accounts
One account per company or service, holding all of its credentials, so the bank's website login, app PIN and card notes sit together.
Owners
File each entry under a person or a company. The Owners list answers "whose is this?" for a family, a small office or a client list.
Favorites
Star what you use every day and it's one click away.
Several vaults
Keep separate vaults on one PC, for example a personal one and a business one, each with its own master password.
Starts simple
A short setup wizard creates a vault with recommended security settings. Extras such as Owners and Developer Mode switch on only when you want them.
Watch
A security dashboard that tells you what to fix first
One health score for your logins, with the entries behind every warning a click away.
Weak passwords
Every login is rated with zxcvbn, the strength estimator used by many password managers. Anything that scores weak is listed.
Reused passwords
Logins that share a password are grouped, so you can see exactly which ones to change.
Old passwords
Passwords you haven't changed in a while (90 days by default, and you choose) are flagged.
Breach check
Checks your passwords against Have I Been Pwned's list of leaked passwords without sending them: only the first 5 characters of a SHA-1 hash leave the PC. The app reminds you to re-check every 3 months by default.
Expiring secrets
Give an API key or certificate an expiry date and the dashboard warns you 30 days ahead.
Health score
Starts at 100 and drops for each weak, reused, old or expired item, so progress is visible as you fix things.
Moving in
Bring your passwords with you
Switching takes minutes, not an afternoon of copy and paste.
- Straight from your browser: KeysWalletWatch finds the passwords saved in Chrome, Edge, Brave and Opera on the same PC (every profile) and lets you pick which to bring in.
- From another password manager: CSV exports from Chrome, Bitwarden, LastPass and 1Password are recognised automatically. Bitwarden's two-factor secrets come across too.
- From a spreadsheet: any other CSV works through a column-mapping screen, including a Person or Owner column so every login lands under the right owner.
- Then clean up: after a browser import, step-by-step directions show how to delete the copies the browser kept.
Getting out is just as easy
Your data is never locked in. Export to CSV at any time (the app warns you that a CSV isn't encrypted), or keep the encrypted .kww vault file itself as your backup.
Firefox import isn't available yet; export a CSV from Firefox instead.
Developer Mode
A proper home for API keys and .env files
Turn on Developer Mode in Settings and the vault grows the tools developers need. Leave it off and none of it gets in the way.
Developer entry types
API Key, Secret, Environment Variables, SSH Key, Database and Certificate, each with the right fields.
Projects and environments
Group secrets into projects (nested if you like) and tag each with its environment, such as production or staging.
.env in and out
Paste a .env file to create entries; export one per entry or per project and environment.
Expiry dates
Set when a key or certificate expires and the security dashboard warns you in time.
Shared projects
Share one project, not your whole vault, with editors or viewers. End-to-end encrypted, with a fingerprint check before anyone joins. How sharing works.
Project trash
Entries deleted from a shared project sit in a trash every member can see and restore from for 30 days.
Everyday safety
Protection that's on before you think about it
Auto-lock
Locks after 5 minutes idle by default (1 to 30 minutes, or never).
Screen-capture protection
On by default, so screenshots and screen recordings show a blank window.
Remote-session lock
The vault locks and the clipboard clears if a remote-desktop session, remote-access tool or debugger is detected.
Recovery key sheet
Print your recovery key on a sheet with storage tips, so a forgotten password isn't the end.
Backups
Save a copy of the encrypted vault anywhere you like. The app reminds you when a backup is due.
Slow to guess
Wrong master passwords add a growing delay, up to a minute between tries.
Works offline
Nothing needs the internet except sync, breach checks and licensing.
No telemetry
The app sends no analytics or usage data. Ever.
Not in the app (yet)
What you won't find
So you can decide with the full picture:
- No Mac, Linux, iPhone or Android version. Windows 10 and 11 only; a phone app is planned with no date.
- No browser extension and no autofill. You copy and paste.
- No passkey storage, no file attachments, and no QR-code scanning for two-factor secrets.
- No automatic updates. You install a new version over the old one, and your vaults are kept.
- No light theme in the app; it's dark only.
Guides for every feature are in the KeysWalletWatch how-to guides (opens in a new tab).
Try every feature free for 30 days
Try every feature free for 30 days. If you keep it, it's $24.99 once for up to 5 PCs.