- not sent
Private phrase
hidden while you type
- recognized
Account context
music.example
- working
On-device derivation
PBKDF2-SHA256, 600,000 rounds
- not saved
Password or PIN
available to copy
Your secrets stay local
Same inputs, same result
Your Master Key stays on your device. Add the account details you recognize, and MoolKey creates the same result whenever you need it.
Private phrase
hidden while you type
Account context
music.example
On-device derivation
PBKDF2-SHA256, 600,000 rounds
Password or PIN
available to copy
Your secrets stay local
Same inputs, same result
A saved password manager retrieves a secret. MoolKey repeats a calculation. That difference changes what the service needs to hold.
See the exact data boundaryYou choose a familiar site or app name and the account identifier you use there. These details tell MoolKey which result to create.
The Master Key is used on this device. MoolKey does not send it to its servers or save it for later.
MoolKey runs the inputs through PBKDF2-SHA256 with 600,000 rounds. The same inputs produce the same password or PIN.
The result appears for you to use. MoolKey does not add that password or PIN to a stored vault.
Some account details are saved so you can return to the right login. The secret that opens it is not.
These stay under your control on the device where you use them.
MoolKey keeps enough context to find the right account and repeat your choices. It does not keep the password itself.

A second device does not need a copy of your password vault. It needs the same private phrase and the account context that identifies the result.
Use the same private phrase and account details when you need that login again.
Each device creates the result instead of downloading a saved password list.
After setup, an unavailable connection does not block the derivation step.
MoolKey removes a stored password vault from its service. You still need a strong private phrase, a secure device, and care around phishing.
Malware on your device can observe what you type or copy. A phishing page can capture a password you paste. MoolKey changes where secrets are stored; it does not replace device security or careful sign-in habits.
Because MoolKey never receives your Master Key, nobody at MoolKey can email it back or replace it. Your backup plan is part of the security model.
Length and randomness matter more than forced symbols or a familiar quote.
Do not reuse it for email, banking, or any other account.
If you need a backup, write it once and store it somewhere secure and offline.
The security model should make sense in plain words. The implementation guides are here when you want to inspect the mechanics.
Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.