Docs · Setup & everyday use
PasswordCoded
PasswordCoded is a local-first password and secrets vault. It encrypts the vault on your device, works free in a browser, installs as a PWA, and can add encrypted multi-device sync through Gattaca Plus.
Set it up
Open PasswordCoded
Open the hosted app in a modern browser. There is no installer to download and no API key to paste. You can use the local vault without a subscription; a Gattaca account and Plus are only needed for cloud sync.
Open PasswordCoded →Create a master password
Choose a unique master password you can remember. It encrypts and unlocks the vault on your device. Gattaca never receives it and cannot reset, recover, or override it. Resetting your Gattaca account password does not reset the vault master password.
Save the recovery kit
PasswordCoded offers a recovery kit immediately after vault creation. Download the encrypted backup and keep it somewhere separate from the device. The printable sheet leaves the master-password line blank for you to write by hand, so the app never sends the plaintext password through a printer.
Install it if you want an app icon
On Chrome or Edge, use the browser's Install app command. Android offers Install app or Add to Home screen; iPhone and iPad use Add to Home Screen from Safari's Share menu. Installation is optional—the same vault works in the browser. PasswordCoded is still completing its real-device iOS and Android validation during early access.
Sign in when you want sync
Open Sync & account and continue with Gattaca. Plus adds an encrypted cloud copy, realtime updates, and multiple devices. PasswordCoded uses the shared account session; the Gattaca API key shown elsewhere in your account is only for Codon MCP.
Open your Gattaca account →
Everyday use
What stays private
Encryption and decryption happen on your device. The sync service receives an encrypted envelope, not the master password or readable vault entries. While the vault is unlocked, the key lives only in memory and the app locks again after inactivity.
Add and organize entries
- Store account logins, passwords, secret phrases, notes, and other sensitive records.
- Search the vault, group entries by category, and use the built-in generator when you need a new password.
- Import entries from a supported CSV export, review the result, and keep an encrypted backup before removing the old copy.
Use more than one device
With Plus active, sign in with the same Gattaca account on the second device and download the encrypted vault. Unlock it with the same master password. Changes sync entry by entry, including deletions, and an open editor is not replaced underneath you.
Backups and recovery
- Export an encrypted backup after important changes and keep at least one copy away from the device.
- If you forget the master password, support cannot open the vault. Restore a backup only if you still know the password that encrypted it.
- If there is no usable backup and the master password is lost, the local vault can be erased so you can start again; the old encrypted data remains unreadable.
Biometric unlock
Supported devices can enroll biometric unlock after the vault is working. It is a convenience for that device, not a replacement for the master password or recovery kit. If the browser or authenticator does not support the required WebAuthn feature, the normal master-password path remains available.
If Plus ends
Your local vault and encrypted exports remain available. Uploading new cloud changes and realtime cloud writes pause when paid access ends, while the existing encrypted cloud copy remains available for you to read, download, or delete. Billing never takes away the local copy or the ability to export it. Re-enable Plus to resume cloud writes.
Early-access limits
Cross-site autofill is not included yet. PasswordCoded is also completing real-device validation and an external security review. Until that work is signed off, keep an encrypted backup and do not make it the only copy of credentials you cannot afford to lose.