← Back to Store
🛡️

mvmPasswords

Your passwords, encrypted before they leave your browser.

v1.4.3 🔐 Security & Privacy 💎 Premium available securitypasswordsautofill
No ratings yet
Download

About

mvmPasswords is a password vault for your mvmOS account. Every Apps Hub profile receives a separate vault, so multiple people using the same machine never see one another’s logins. The app works in the desktop, from its optional public page, and in a compact Chrome or Firefox extension. Passwords, usernames, notes and website addresses are encrypted in the browser with a key derived from your master password. The server stores only the encrypted vault records and the non-secret encryption salt; it never receives the master password or the readable passwords. Unlocking is local to the browser you did it in and never reaches the server. You decide how long an unlocked vault stays open: from five minutes up to a day or a week, or only until the browser session closes. Anything longer than the session survives closing the page, which is what makes the app usable from a phone home screen, where every launch would otherwise start from the master password again. The countdown restarts each time you open the vault, so a vault you use daily never asks twice, while one you forget about locks itself after the span you chose. The shortest option is the default, and the whole choice is a trade — a longer window keeps the unlocked key in that browser, on that device, until it expires. Folders keep a growing vault navigable. Create, rename and delete them from the app menu, pick a folder while adding or editing a login, and switch between them with the tabs under the search box. The tabs reorder themselves so the folder you used last is first, fold onto a single row on a narrow screen with the remainder behind a ⋯ button, and the folder you were in is still selected when you come back. On a sign-in page the chosen folder decides which of the matching logins you see: two accounts for the same site, one in Home and one in Work, show you only the one from the folder you are in, with a button that says how many are hidden and brings them back for that moment. A folder name is encrypted exactly like a password, so the server cannot read it either, and deleting a folder never deletes a login — the logins inside it simply become unfiled. The generated browser extension can match the active website, open with a keyboard shortcut, and show a small key button inside supported sign-in fields. The key appears on its own as soon as a page with a login form is open, so you can see at a glance that the vault has something for it; a checkbox in the extension settings keeps it out of the way until you click in the field instead. The extension settings also show the current keyboard shortcut and open the browser's own page for changing it. Select a vault item in the popup and it fills the username and password only into the current tab. The extension also acts as a passkey provider: when a website offers to create or use a passkey, it is stored inside the matching vault entry and stays encrypted like everything else. Moving in from another manager is a single step. The import screen reads an export from Bitwarden, KeePass, 1Password, LastPass, Dashlane, NordPass, Chrome, Firefox or Safari, in either JSON or CSV. The file is read and encrypted inside your browser, so its readable passwords never reach the server, and entries that already exist in the vault are detected and left unticked. When the administrator enables it and the installation is licensed, the vault also talks to mvm2factor: link a two-factor account to a login and the card gains a button that copies the current code, while filling that login puts the code on the clipboard at the same time. The shared secret never leaves mvm2factor — mvmPasswords only ever asks it for finished digits, and only when you press the button. A licensed install also gets a password check from the app menu: it looks at every login already unlocked in that vault and flags two things — a password reused on more than one login, and a password weak enough to guess, whether that's too short, too simple, or one of the passwords people pick most often. Nothing about the check leaves the browser; it looks only at passwords already decrypted there.

What it does

  • A separate encrypted vault for every Apps Hub profile.
  • AES-GCM encryption performed in the browser before a vault record is sent to the server.
  • A master password that is never transmitted or stored by mvmOS.
  • Logins with website, username, password and private notes.
  • Passkey storage: create and use website passkeys straight from the vault, in the browser extension.
  • Import from Bitwarden, KeePass, 1Password, LastPass, Chrome, Firefox and other managers, in JSON or CSV.
  • Duplicate detection on import, so re-running it does not fill the vault with copies.
  • Search and website matching after the vault is unlocked.
  • A chosen unlock window — five minutes to a week, or until the browser session closes — that restarts every time you open the vault, so frequent use never asks for the master password again.
  • Folders with encrypted names: create, rename and delete them, assign a login to one, and filter with the tabs under the search box, which remember your choice and put the folder you used last in front. A chosen folder hides the matches kept in other folders behind a button that counts them.
  • A public page enabled by an administrator through Apps Hub.
  • Generated Chrome and Firefox extensions configured automatically for the current mvmOS server.
  • Username and password autofill into the active browser tab after you choose an entry.
  • A key button that appears by itself in login fields, or only when the field is clicked, plus a keyboard shortcut shown in the extension settings — all switchable there.
  • Optional two-factor codes from mvm2factor on a linked login, copied on demand and on autofill — enabled by an administrator, with a subscription.
  • A password check, with a subscription, that flags passwords reused across logins and passwords weak enough to guess — computed in the browser from the vault already unlocked there.

Integrations

Uses mvm2factor App API

A login can be linked to a mvm2factor account, and mvmPasswords then copies its current six-digit code on request — including when it fills the login, so the second step is already on the clipboard. The code is computed by mvm2factor and fetched only when the button is pressed.

Requires: A subscription, mvm2factor installed, the integration switched on by an administrator in Apps → mvmPasswords → Settings, and the mvm2factor App API enabled in Apps Hub → Settings → App APIs, which is off by default.

💎 With Premium

Two-factor codes in the vault

Once an administrator switches the integration on in the app's settings, any login can be linked to a mvm2factor account, and mvmPasswords gains a button that copies its current six-digit code. Filling a login that has two-factor set up puts the code on the clipboard at the same time, so the second step is one paste away instead of a trip to another app. The code is always computed by mvm2factor and asked for only when you press the button, so nothing is slowed down and no shared secret ever reaches the password manager.

Password check

A menu entry checks every login for two common problems: the same password used on more than one entry, and a password weak enough to guess — too short, too simple, or one of the passwords people pick most often. The check runs entirely in the browser on the passwords already decrypted for that vault, so nothing about it is sent anywhere.

About Premium

Reviews

Reviews and ratings are written from the App Store of an installed mvmOS system.

No reviews yet.