You focus a field
The content script notices a login field and asks the app for the credentials that belong to this site.
Product / Autofill
The extension matches by registrable domain, not by URL string, so a shared host never receives the wrong credential. The dropdown renders inside a closed Shadow DOM the page cannot reach.
A URL is reduced to its registrable domain using the full Mozilla Public Suffix List, embedded in the extension as a hash-pinned snapshot. Hostnames are never compared as raw strings, so a subdomain cannot borrow a credential that belongs to a different site.
The dropdown, the password generator and the phishing warning all render inside a closed Shadow DOM attached to the page. The page's own JavaScript cannot read them, rewrite them, or overlay them to capture what you type.
The extension talks to the desktop app over a dynamic loopback port, and message frames are encrypted. Copying a password puts it on the clipboard on a timer, so it does not sit there indefinitely.
The content script notices a login field and asks the app for the credentials that belong to this site.
Your URL is normalised to eTLD+1 with the embedded Public Suffix List, then matched against the vault's stored domains.
The dropdown shows only the records for that domain, and the chosen one is typed into the field.
The extension is one front end to the same local vault, so a credential you add on the desktop is available to the browser immediately.
Autofill fills a form; it does not decide whether the site is honest. The extension checks for obvious phishing by comparing the domain against what your vault already knows, but a site that impersonates a domain you have never saved will look new rather than familiar. A password manager reduces typing errors and reuse. It does not replace two-factor authentication, and it cannot help once credentials have already been entered into a page that was hostile all along.
Built on the full Mozilla Public Suffix List as a hash-pinned snapshot, so shared hosting is handled correctly.
Dropdown, generator and phishing warning render where the page's own script cannot see or modify them.
Content scripts match http and https only, so internal browser schemes are out of scope.
No. Everything it needs is on your device: the vault is local, and the connection to the desktop app is a loopback port on your own machine.
The popup says the vault is locked and the dropdown reports no records. Nothing is cached in the browser, so a closed app means no autofill.
Chrome, Edge and Firefox, using Manifest V3. A Safari build exists and needs a local wrapper to run it.