Browser credentials

The token and optional remembered password are stored unencrypted in localStorage for jeffkao.ca. Any script running on this origin could read them. This tool sends the token only to GitHub’s API, but you should still use a dedicated, expiring token.

Leave blank to keep using the token already remembered by this browser.

Choose it when creating the vault; enter the current password if the vault already exists. Setup verifies but does not rotate it, and there is no password recovery. Leave blank to reuse a remembered password.

Bookmarklet

Drag this button to the bookmarks bar in Chrome or the bookmarks toolbar in Firefox:

Save to reading list

Alternatively, copy the code, create a bookmark, and paste it into the bookmark’s URL field.

Bookmarklets work on ordinary web pages, but browsers block them on internal pages such as chrome://, about:, extension stores, and some built-in PDF viewers.