[ Distribution // Cross-Platform ]

Runs everywhere.
Trusted nowhere.

Zero-knowledge means every device does its own crypto. Pick your surface.

In plain English: your passwords are scrambled on your phone or laptop before they ever leave it, so even we can't read them. Pick the app you want to use SPCTR from.

Platforms & apps

[ STABLE ]

Web Vault

The full SPCTR suite in your browser.

Sign in from any browser — nothing to install.

[ STABLE ]

Chrome / Chromium Extension (v0.7.0)

MV3 popup: credential vault, secure notes, TOTP codes and autofill, email masks, save-password prompt, breach shield with a vault health score, passkey unlock, and SPCTR as your passkey provider.

Chrome, Edge, Brave, Arc, Opera and Vivaldi. Install from the store — only store installs update themselves.

[ STABLE ]

Firefox Extension (v0.7.0)

Firefox-native packaging with the background script list and Mozilla's data-consent declaration.

Runs on Firefox 121+. Signed on Firefox Add-ons for one-click, auto-updating installs.

[ SOON ]

Safari Extension

macOS 14+ / iOS 17+.

Native Safari build for Mac and iPhone. Queued behind the mobile apps.

[ SOON ]

iOS App

The SPCTR vault packaged natively, with Face ID unlock and passkey autofill.

In build. The app bundles the vault on-device — TestFlight first, App Store after review.

[ SOON ]

Android App

The SPCTR vault packaged natively, with fingerprint unlock and autofill service.

In build and shipping first. Play Store closed testing, then open release.

[ Install the extension // pick your browser ]

Load the browser extension

Install from the store. Store copies are signed and update themselves — a hand-installed copy never will, which is the usual reason someone is stuck on an old version. The zips are the exact same code, kept here for anyone who wants to inspect it or stay off the stores.

/ chromium

Chrome, Edge, Brave, Arc, Opera, Vivaldi

Easiest: install from the Chrome Web Store. Edge, Brave, Arc, Opera and Vivaldi all install Chrome Web Store items — Edge asks you to “Allow extensions from other stores” first, Opera needs the “Install Chrome Extensions” add-on.

manual install (advanced) — never auto-updates
  1. Click Download .zip, then unzip it — double-click on macOS, right-click → Extract All on Windows. Keep the unzipped folder somewhere permanent; deleting it removes the extension.
  2. Open a new tab and go to chrome://extensions.
  3. Turn on Developer mode (top-right toggle in Chrome/Brave/Arc/Vivaldi, bottom-left in Edge).
  4. Click Load unpacked and select the unzipped folder — the one containing manifest.json, not the zip itself.
  5. Pin SPCTR from the puzzle-piece toolbar menu, open it, and pair it from Settings → Security → Pair browser extension.

Manually loaded builds never auto-update, and Chrome warns about developer-mode extensions on each launch. Repeat the download and drop the new folder over the old one for updates, or switch to the store install.

/ firefox

Firefox 121+

Easiest: install from Firefox Add-ons — click Add to Firefox, confirm the permissions, then pin SPCTR to the toolbar. Signed and auto-updating.

manual install (advanced)
  1. Signed .xpi: download it, then drag the file onto a Firefox window (or about:addons → gear icon → Install Add-on From File…) and confirm. This one stays installed after a restart.
  2. Developer zip: download the Firefox .zip, go to about:debugging#/runtime/this-firefox, click Load Temporary Add-on… and pick the zip or its manifest.json.
  3. Open the SPCTR icon and pair it from Settings → Security → Pair browser extension.

Temporary add-ons unload when Firefox restarts. The AMO build and the signed .xpi both persist and update on their own.

/ how updates work

Staying on the latest build

  • Store installs update themselves. Your browser checks for new versions in the background and installs them within about a day.
  • Manually loaded zips do not. Chrome and Firefox never auto-update an extension you loaded from a folder — download the new zip and load it again.
  • The extension tells you. When a newer version exists, a banner appears at the top of the popup with the version number and a link to the update. Nothing is downloaded or executed automatically — SPCTR never loads remote code.

Firefox users who install from AMO get background updates automatically, and the self-hosted .xpi is Mozilla-signed so it updates from spctrvault.app too.

v0.6.9 is the readability pass for the extension: higher-contrast text on every dark theme, dropdowns and form controls that match the rest of the UI, clearer focus outlines, and update wording that no longer says “Chrome” when you're on Firefox. v0.6.8 puts the real site logo next to every login, 2FA code and note — fetched through SPCTR's own proxy, so the site you saved never learns you looked. v0.6.7 adds anonymous install counts so we can see adoption without identifying anyone. v0.6.6 and v0.6.5 finally kill the autofill icon that lingered over pages after you signed in. v0.6.4 makes extension sessions durable — no more “session expired” after a browser update or an idle afternoon. v0.6.3 lets you force an update check by clicking the version line. v0.6.2 ships the store-review build. v0.6.1 fixes the Account tab: the theme picker now works (and is available before you pair), the auto-lock timeout saves and confirms, the passkey list is collapsed behind a count instead of crowding the tab, and pairing opens the new tabbed Settings page straight to the pairing card. Browser updates no longer drop the session, so Chrome no longer asks you to re-pair after every update. v0.6.0 syncs themes between the web app and the extension — keep one global theme or pin a different one to this browser. v0.5.4 keeps the packaged builds, the version shown in the popup and the Firefox update manifest in step, so self-hosted installs pick up the current build automatically. v0.5.3 fixes vault unlock in the extension: it now reads your account’s key material fresh from your account on every unlock instead of the copy saved when you paired, so a passphrase that works on the web app works here too, and it understands Argon2id-protected vaults. Items that still can’t be opened are counted in the list rather than quietly hidden, so a partial sync can no longer look like a short vault. v0.5.2 keeps the save-password prompt on screen until you answer it — it now survives the page reload that follows a login and only disappears when you save or dismiss it. v0.5.1 makes secure notes editable straight from the popup — open the Notes tab, tap Edit, and the note is re-encrypted on your device before it syncs, with a revision check that blocks silent overwrites when another device changed the same item. v0.5.0 turns SPCTR into a passkey provider: switch it on in the Account tab and sites that offer passkeys can create and use ones stored in your vault, with a confirmation prompt every time and a one-click fallback to the browser. The same release adds a read-only Notes tab (secure notes, keys, cards, identities), one-time-code autofill straight into 2FA boxes — including split one-digit-per-box forms — and a vault health score in the Shield that grades reuse, weak passwords and known breaches. v0.4.3 clears the autofill marker as soon as the login field loses focus or the form is removed, so the SPCTR icon no longer lingers over the page. v0.4.2 clears Mozilla add-on review: the Firefox build declares the new data-consent key, drops the unsupported background worker entry, and every popup/autofill surface now renders through an inert DOM parser instead of innerHTML. v0.4.1 cleared the Chrome install warning (MV3 background worker) and let the breach shield arm background scanning straight from a passkey unlock — no passphrase retype. v0.3.9 fixed long 2FA account names overflowing the popup (labels now truncate so the code and countdown ring stay visible). v0.3.8 gave the 2FA tab a facelift — big account names on the left, the code and a live countdown ring on the right, tap to copy. Passkey unlock still lets you skip the passphrase: SPCTR opens spctrvault.app, unwraps your vault key with your passkey, and hands it back sealed to a one-time code. Your vault stays unlocked for an hour, inline autofill uses the transparent SPCTR ghost, and credential vault, TOTP codes, one-tap email masks and the password generator all decrypt locally.