Your Identity Vault.
No Backend.
Privacy-first OAuth tracking, Same-Site identity resolution, and local credential management. It all runs in your browser — no account, no backend.
example.com
3 Saved Identities
github.com
OAuth & API Key Registry
Detecting LoginLens Extension status...
Experience the Vault Interface
Click across the simulated domains below to see how LoginLens categorizes website accounts, OAuth providers, and API keys.
Personal & Work Logins
example.com
Method: password
Method: password
dev_token_user
Method: oauth · Provider: github.com
Designed for Modern Identity Tracking
Everything you need to organize passwords, OAuth flows, and MFA without cloud lock-in.
Universal OAuth Tracker
Automatically records "Sign in with Google" or GitHub auth callbacks in service workers without manual typing.
Zero-Server Architecture
Everything lives in your browser's own storage. No account, no backend of ours, no telemetry. The two things that can go outbound — a favicon fetch and encrypted cross-device sync — are both off until you turn them on.
Same-Site Alias Resolver
Consolidates multiple accounts on the same domain into clean cards with 1-click same-site alias resolution.
In-Browser Decryptor
Recover encrypted backups directly in your browser without needing Python scripts or third-party software.
Password Reuse Alerts
Each password becomes a keyed HMAC-SHA256 fingerprint, using a key generated on your machine that never leaves it. Reuse across sites is detected by comparing fingerprints; the password itself is never stored.
API & Token Registry
Store and tag API tokens, secret keys, and developer credentials with scopes and environment labels.
How LoginLens works
There is no sign-up, no onboarding wizard and no server to wait on. You install it and it starts noticing things.
Install it
Load the build for your browser. Nothing to create, nothing to log into — the vault exists the moment the extension does.
Keep browsing
When you sign in somewhere, LoginLens notices the account and how you got in — password, a "Sign in with Google" redirect, an API token — and offers to remember it. You confirm; it never saves silently.
See the whole map
Open the vault to find every account grouped by site, which identity each one belongs to, which sites depend on one OAuth provider, and where a password has been reused.
What it keeps. What it never sees.
"Private" is easy to say. Here is the actual contents of the vault, and the things that are deliberately not in it.
Stored on your device
- The sites you have accounts on, and the usernames on each
- How you sign in to each one: password, OAuth provider, passkey, API token
- Which authenticator app or key covers which account
- A keyed fingerprint per password — enough to spot reuse, not enough to recover the password
- Your own notes, tags and links between accounts
Never stored, never sent
- Your passwords — LoginLens is not a password manager and has nowhere to put one
- TOTP secrets or anything that could generate your 2FA codes
- Session cookies, tokens or anything that could sign in as you
- Analytics, crash reports, usage pings, install counts
- Anything at all on a server we run, because there is no server we run
Optional encrypted sync exists for people who want their vault on more than one machine. It is off until you turn it on, it uses your browser's own sync rather than anything of ours, and it is encrypted with a passphrase before it leaves the device.
Frequently Asked Questions
Everything you need to know about LoginLens security and privacy.
Take Control of Your Identity
Install LoginLens for Chrome, Firefox, or Edge today. No account, no backend, no telemetry.