Request a beta invite

About Rekey

Password managers only warn you. Apple finally fixes it, but only on Apple. Rekey fixes it everywhere.

Rekey started with a familiar, stupid little moment: another "your password was found in a data breach" email, one of dozens, and the realisation that no tool would actually do anything about it.

Your password manager will happily tell you which of your logins are weak, reused, or leaked. It'll show you a red number: 12, 30, 70 accounts at risk. And then it stops. Fixing them means doing 70 password resets by hand, one login flow at a time, so most of us never do. The warnings just pile up.

That's the gap Rekey closes, on every platform, not just Apple's. It's a browser extension that gets your breached passwords fixed the moment a leak is found: it takes you to each change page and saves the new one, and keeps the old password until the new one is confirmed to work, so you're never locked out. It's the part that comes after "your data was compromised," the boring, essential part.

Trust is the whole game

We asked a lot of people what would stop them using something like this. The answer was never "will it work?" It was always the same, deeper worry: do I trust a new tool to touch all my accounts?

So we built the answer into the architecture instead of promising it on a page. Your passwords are encrypted on your own device with a master password only you know. Sync across your devices is optional and zero-knowledge: our server only ever stores ciphertext it cannot read, so even we can't see your passwords, and a leak of it would spill nothing but scrambled bytes. The code is open source on GitHub, so you don't have to take our word for any of it. And Rekey never needs access to your email; when a site can't be changed automatically, it simply hands the task back to you.

We're building it in public

Before writing a line of product code, we did a hands-on teardown of nine competing password managers, went and read the exact complaints people post about this problem, and put up a waitlist to see if the need is real. It is. We publish what we can rotate and what we can't, honestly, rather than pretending to cover everything.

We also take the security consensus seriously: forcing password changes on a timer is bad advice, and NIST agrees. So Rekey's default isn't arbitrary rotation, it's rotation with a reason: a reported breach, a shared account handed back, a device you lost.

Where we are

Rekey is in development. The waitlist is open, the feasibility of the hard part is being proven, and we won't handle a single real password until both the demand and the engineering are validated. If any of this sounds like something you'd have wanted the last time that email landed, come along for the build.

Who's building it

Rekey is a small, independent project, built by someone who needed it to exist and got tired of waiting for the big managers to ship it. That's usually the strongest sign there's a real product underneath: we're building the thing we ourselves keep wishing we had. As the team and the product grow, this page grows with it.

Join the waitlist
We use Google Analytics cookies to see how the site is used. No ads, no cross-site tracking. See our Privacy Policy.