Support

How can we help?

Most questions have a short answer below. For anything else, there are three ways to reach us, depending on what it is.

Problems with a tool

Problems with Keyrook Authenticator can go on GitHub, where anyone can follow them.

Open an issue

Security reports

A security problem in anything Keyrook makes is best reported privately, not in a public issue.

How to report one

Common questions

Short answers

Is Keyrook Authenticator free?

Yes. It is free, with no ads, and syncing it with a Keyrook account is free too, with no limit on how many codes you keep.

Do I need a Keyrook account?

No. Every feature but sync works without one, and then nothing leaves your computer. An account only keeps your codes in step across your browsers.

Can Keyrook read my codes?

No. With sync on, your accounts are encrypted on your device before they are uploaded, under a key our server never receives. We can see your email address and when your devices connect, not what is in your vault. What the server can still see

Which browsers does it work in?

Chrome and Microsoft Edge, on a computer: get it from the Chrome Web Store or Edge Add-ons.

I forgot my account password. What now?

Use the recovery key you were given when you made the account: it lets you set a new password and keeps everything in your vault. Without the password and the recovery key, nobody can open the vault — us included. That is the price of a server that cannot read it.

How do I delete my account?

In the extension: Settings → Account & sync → Delete account. It asks for your password, then removes your email address, your encrypted entries, your devices and your recovery data at once. Encrypted backups of the database expire within 60 days.

Is it open source?

The extension is, under GPL-3.0, on GitHub. The sync server's code is not public, which is why the extension is written to treat the server as a stranger.