HavenKeys sürüm geçmişi - 11 sürüm
HavenKeys geliştiren: Samuel Rocha
HavenKeys sürüm geçmişi - 11 sürüm
Eski sürümlere dikkat edin! Bu sürümler yalnızca test veya referans amacıyla sunulmaktadır.Her zaman eklentilerin son sürümlerini kullanmalısınız.
Son sürüm
Sürüm 0.15.0
3 Eki 2026 tarihinde çıktı - 417,14 KBfirefox 128.0 ve üstü ile çalışırHavenKeys browser extension 0.16.0
New: password settings in the new-password menu
- When a site asks you to create a password, the "Generate strong password" row now has a settings button. It opens a
panel where you set length, uppercase, lowercase, numbers and symbols, then Generate and fill.
- The panel starts from the settings saved in the desktop app's Generator tab. Changes in the panel apply only to the
password you're generating and are never saved.
- The row itself still uses your saved settings with one click, as before.
- Requires HavenKeys desktop 0.16.0 or later. The desktop's Generator tab now saves its settings in your encrypted
vault.
Fixed: your Identity is offered on signup forms that say "Sign in"
- Some signup pages contain only "sign in" wording, such as Yahoo's "Create a Yahoo account" with its "Sign in with
Google" button. They were mistaken for login forms, so first name, last name and birth date got no Identity menu.
- "Sign in with Google / Apple / …" buttons no longer make a form count as a login. "Sign in with a passkey" still
does.
- A password field next to fields asking for a name or birthday is now recognised as a signup.Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Eski sürümler
Sürüm 0.13.0
1 Eki 2026 tarihinde çıktı - 411,28 KBfirefox 128.0 ve üstü ile çalışırHavenKeys 0.13.0
A maintenance release that keeps the extension's version in step with HavenKeys desktop 0.13.0.- No changes to autofill, saving logins, passkeys or the menu under login fields.
- Works with HavenKeys desktop 0.13.0. The desktop's link to the browser was tidied up internally; the messages and
checks the extension relies on are unchanged. - Custom fields added to logins in the desktop app stay in the desktop app. The extension can't read them, and it
doesn't fill them.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.10.1
29 Eyl 2026 tarihinde çıktı - 325,25 KBfirefox 128.0 ve üstü ile çalışır### Sign in with Google, Microsoft, GitHub and Apple
- Save it once. Click "Sign in with Google" (or Microsoft, GitHub, Apple) on a site and pick your account. When you
come back, HavenKeys asks whether to save it. The account is filled in and you can edit it. Nothing is saved without
your confirmation.
- Sign in with one click. On a site's sign-in page, a small balloon in the top-right corner shows your saved "Sign
in with Google · you@gmail.com". Pick it and HavenKeys presses the site's button and finishes the provider's sign-in:
- if the account is already signed in, it clicks that account in the provider's account chooser;
- if it isn't, it clicks "Use another account" and signs in with your saved login for that provider and account:
email, password and one-time code.
- It stops rather than guess.
- It never grants permissions for you.
- It stops on a consent screen, a CAPTCHA, or a phone or security-key prompt, and when you have zero or several saved
logins for that account.
- Touching the provider's page yourself ends it.
- The provider's password is filled only on the provider's own sign-in site, and only when automatic sign-in is on.
- Sign-in-with logins also appear in the menu under login fields and in the toolbar popup. A login that also has a
password still fills its password.
### Fixes
- In a long list of logins under a login field, the first click now picks the login you clicked instead of scrolling
back to the top.
### Notes
- No new permissions.
- Requires the HavenKeys desktop app 0.10.1.
- Not yet supported: Google's embedded "Sign in with Google" button and One Tap, and company single sign-on (Okta,
SAML).Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.10.0
29 Eyl 2026 tarihinde çıktı - 324,4 KBfirefox 128.0 ve üstü ile çalışırRelease notes (página da release desktop-v0.10.0)
## Sign in with Google, Microsoft, GitHub and Apple
HavenKeys now remembers which sites you sign in to with Google, Microsoft, GitHub or Apple, and which account you use
there.
In the browser extension
- Save it once. Click "Sign in with Google" (or Microsoft, GitHub, Apple) on a site and pick your account. When you
come back to the site, HavenKeys asks whether to save it. The account is filled in and you can edit it. Nothing is
saved without your confirmation.
- Sign in with one click. On a site's sign-in page, a small balloon in the top-right corner shows your saved "Sign
in with Google · you@gmail.com". Pick it and HavenKeys presses the site's button. On the provider's own page, it clicks
the saved account in the account chooser.
- It stops rather than guess. HavenKeys never grants permissions for you, never types a password on the provider's
page, and does nothing if the account isn't listed exactly once. If the provider asks for your password, pick your
Google/Microsoft login from the usual menu.
- Sign-in-with logins also appear in the field menu and the toolbar popup. A login that has a password as well still
fills its password as before.
In the desktop app
- A new Sign in with section in the login editor: choose the provider and, optionally, the account. A login can
have both a provider and a password.
- The login's page shows the provider and account. If the vault holds that provider's own login for the same account,
you can open it from there.
Importing from 1Password
- "Sign in with" logins from a 1Password export are now imported as such, instead of as a line in the notes.
- Importing the same.1puxagain adds "Sign in with" to logins you imported before. Nothing else in them changes, and
notes that were exactly the old "Sign in with …" line are cleared.
Security
- Which pages a login may be used on, and which provider pages a sign-in may continue into, are still decided in the
desktop app's Rust core. The list of provider sites is fixed: accounts.google.com, login.microsoftonline.com,
login.live.com, github.com and appleid.apple.com.
- No password or one-time code is involved on this path.
- No new browser permissions.
Known limitations
- Google's embedded "Sign in with Google" button and One Tap prompt (the ones drawn inside a Google frame on the site)
are not recognised yet. Sites with their own provider button work.
- Company single sign-on (Okta, SAML and similar) is not supported.
This software has not undergone an independent security audit.
Full Changelog: https://github.com/rochasamuel/havenkeys/compare/desktop-v0.9.1...desktop-v0.10.0Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.8.0
27 Eyl 2026 tarihinde çıktı - 297,76 KBfirefox 128.0 ve üstü ile çalışırRelease notes — HavenKeys 0.8.0
0.7.0 was never released, so 0.8.0 includes everything since 0.6.0.
New
Edit a login from the browser popup. In the extension's toolbar popup, hover over a login's initial and it turns into a pencil. Click it and the HavenKeys
desktop app comes forward with that login open in its editor, even if the app was hidden in the tray.
- It works only for a login saved for the site you're on.
- If you have unsaved changes in another item, HavenKeys asks before discarding them.
Set up two-factor codes from a QR code. A QR button in the one-time codes field works when you create a login and when you edit one.
- It reads a QR code screenshot from your clipboard first. If there isn't one, it looks for the code on screen: every monitor and every open window, including
windows behind HavenKeys and windows of any app.
- If several codes are found, you pick which one to use.
- The secret stays in the app's secure core and is never shown in the window.
Open a login's website. The website on a login's detail page is now a button that opens it in your browser. Only that login's saved http/https addresses can be
opened this way.
Fixed- gov.br: filling from the toolbar popup no longer says "No login form found" on the CPF step.
- gov.br: automatic sign-in now presses "Continuar" and "Entrar". HavenKeys now presses a site's button the way a person does, so sites that start their
sign-in from the button's click (for example to run a CAPTCHA check) work. - QR scan on Windows: codes the browser draws at 125% to 150% display scaling are now read. Before, they were often missed even when fully visible.
- The editor's focus outline now follows the rounded corners of each group.
Security- The edit button sends no passwords or login data to the extension. The desktop app checks the login against the current site the same way it does before
filling, and web pages can't trigger it. - The QR scan keeps images in memory only and keeps only otpauth://totp text. It now also captures windows hidden behind others; the threat model covers this.
- The extension asks for no new permissions.
Upgrading- Update the desktop app and the extension together. The edit button needs desktop 0.8.0 or later. With an older desktop app, clicking it shows an error.
- Building from source on Linux now also needs libpipewire-0.3-dev, libclang-dev and libgbm-dev (used by the QR screen capture).
- Screen capture may ask for screen-recording permission the first time: on macOS always, and on Linux under Wayland.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.7.0
27 Eyl 2026 tarihinde çıktı - 297,71 KBfirefox 128.0 ve üstü ile çalışırHavenKeys 0.7.0 — release notes
New
Edit a login from the browser popup. Each login in the extension's toolbar popup now has a pencil button, "Edit in HavenKeys". Click it and the desktop app
comes forward with that login open in its editor, even if the app was hidden in the tray.
- It works only for a login saved for the site you're on.
- If you have unsaved changes in another item, HavenKeys asks before discarding them.
Set up two-factor codes from a QR code. A new QR button in the one-time codes field works when you create a login and when you edit one.
- It reads a QR code screenshot from your clipboard first. If there isn't one, it finds the QR code on your screen.
- If several codes are found, you pick which one to use.
- The secret stays in the app's secure core and is never shown in the window.
Open a login's website. The website on a login's detail page is now a button that opens it in your browser. Only that login's saved http/https addresses can be
opened this way.
Fixed- The editor's focus outline now follows the rounded corners of each group.
Security- The new "Edit in HavenKeys" button sends no passwords or login data to the extension. The desktop app checks the login against the current site the same way
it does before filling, and web pages can't trigger it. - The extension asks for no new permissions.
- The security and threat model documents cover both new features.
Upgrading- Update the desktop app and the extension together. The pencil button needs desktop 0.7.0. With an older desktop app, clicking it shows an error.
- Building from source on Linux now also needs libpipewire-0.3-dev, libclang-dev and libgbm-dev (used by the QR screen capture).
- Screen capture may ask for screen-recording permission the first time: on macOS always, and on Linux under Wayland.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.6.0
26 Eyl 2026 tarihinde çıktı - 297,24 KBfirefox 128.0 ve üstü ile çalışırHavenKeys 0.6.0
New: Português (Brasil)
HavenKeys now speaks Brazilian Portuguese as well as English.- Browser extension: follows your browser's language automatically. The extension's name and description in the browser
and store are translated too. - Desktop app: follows your operating system's language. To choose, go to Settings → Language: Automatic, English or
Português (Brasil). The tray menu follows the same choice. - Which language wins: the first English or Portuguese language in your language list decides. If English is your main
language and Portuguese your second, the app stays in English. - Dates: shown in the app's language, keeping your regional format (for example, British dates in English).
Better login detection- gov.br: the CPF step and the password step are now recognised. Before, the CPF field showed no suggestions, and the
password field only offered to generate a new password instead of filling your saved one. - Document-number logins, Brazil and elsewhere: fields that ask for a document number are recognised as the username.
This covers:- Brazil: CPF, CNPJ, RG, documento, matrícula
- Portugal, Spain and Latin America: NIF, NIE, DNI, CIF, RUT, CUIT/CUIL, CURP, RFC, cédula
- Elsewhere: passport, national ID, codice fiscale
- Username-only steps: HavenKeys now recognises a field labelled only "CPF" or "DNI" on a sign-in page. The same field
on a checkout form is still ignored. - Sites that block browser autofill: some sites mark every field as a "new password" to stop the browser filling them.
HavenKeys now looks past that, and a field that asks for your current password is filled with your saved one.
Layout fixes- No cut-off text: buttons and labels no longer get cut off in either language. Every screen of the extension and the
desktop app has been checked in both languages and both themes, including the desktop app's smallest window size. - Extension: long error messages in the popup and the save prompt now wrap instead of being cut off. The suggestions
menu and save prompt size themselves to fit their content. - Passkey card: a website's account name stays on one line with "…". A site can no longer fill the card with its own
text. - Desktop app at small window sizes:
- The editor's buttons and website rows fit.
- The lock button no longer spills out of the sidebar.
- The removed-computer notice no longer covers the welcome screen.
- Vault list: items with both a one-time code and a passkey show both icons side by side.
Compatibility- Extension 0.6.0 works with desktop 0.5.0 or later. The messages between them haven't changed. Updating both is still
recommended. - Automatic language on macOS relies on the app declaring its languages and hasn't been tested on a Mac yet. If it
doesn't pick Portuguese there, choose the language in Settings.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
- Browser extension: follows your browser's language automatically. The extension's name and description in the browser
Sürüm 0.5.0
26 Eyl 2026 tarihinde çıktı - 257,99 KBfirefox 128.0 ve üstü ile çalışırHavenKeys extension 0.5.0
New: automatic sign-in
When you pick a login from the HavenKeys menu or the popup, HavenKeys now finishes the sign-in for you:- It fills your username and password and presses the site's sign-in button.
- If the site asks for your password on a second page, HavenKeys fills it there and presses the button again.
- If the login has a one-time code, HavenKeys fills the current code on the two-factor step and presses Verify.
Nothing happens until you pick a login. HavenKeys still never fills or submits anything on page load.
You're in control- Global switch: Desktop → Settings → Browser extension → Sign in automatically after filling.
- Per-login switch: open a login in the desktop app → Browser → Sign in automatically on this site.
- Both are on by default. With either one off, HavenKeys fills the fields and leaves pressing the button to you, as
before. - Typing, clicking or pressing a key on the page stops an automatic sign-in at once.
Safety limits- Your pick starts it: an automatic sign-in starts only from your pick. A webpage can't start one or extend it.
- Scope: it stays in the same tab and frame, on the exact site (scheme, host and port) where you picked the login. It
moves forward one step at a time, each step at most once, and ends after 2 minutes. - Origin re-check: before each step, the desktop app checks your password or one-time code against the site the page is
on. Nothing is reused from an earlier step. - When it holds back: HavenKeys doesn't press when it can't clearly tell which button signs in, or when a CAPTCHA or
bot check is showing. It does handle Google's invisible reCAPTCHA. - No storage, no logging: nothing about a sign-in in progress is saved or logged.
Known limitations- Sign-ins that jump to a different site part-way (for example, a separate identity-provider domain) stop at the jump.
- Some sites ignore scripted button presses. In that case you press the button yourself.
- A sign-in spread over several pages works only with in-page suggestions turned on.
Compatibility
Update the desktop app to 0.5.0 together with the extension. The desktop app now tells the extension whether it may
sign in automatically. Neither the new extension nor the old one accepts the other version's fill replies, so filling
fails until both are on 0.5.0.
That compatibility warning comes from how the message parser works: each side accepts only messages with exactly the
fields it expects. You may want to ship the store update and the desktop release together. I can also publish these
notes as a page you can share.Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
Sürüm 0.4.4
26 Eyl 2026 tarihinde çıktı - 254,41 KBfirefox 128.0 ve üstü ile çalışırHavenKeys extension 0.4.4
New- HavenKeys icon in login fields. When you focus a username, password or one-time-code field, a small HavenKeys icon
appears inside it. Click the icon to open or close your suggestions. On a site with nothing saved, it tells you so
instead of doing nothing. - Suggestions open as you type. If a site puts the cursor in the login field for you, start typing and your matching
logins appear. It won't reopen in a field after you close it there. - Easier to turn on. When suggestions in login fields are off, the toolbar popup offers a Turn on button. The settings
page now explains that the same switch lets HavenKeys save and use passkeys.
Improved- Redesigned passkey cards.
- Cards are exactly as tall as their content, with no empty gaps.
- When saving a passkey, each login is listed with its username, so logins with the same title can be told apart.
"New login" is always offered. - Buttons fit on one line: Cancel and Save, with "Use another device" as a link on the left.
- The sign-in and "HavenKeys is locked" cards are compact.
Fixed- The suggestion list under login fields was cut off, with its first row hidden behind the header.
- The suggestion list always scrolled by a couple of pixels, even when every login fit.
- Suggestions only showed up after you had filled from the toolbar popup at least once. In-page suggestions and
passkeys now clearly depend on the Turn on setting.
Security notes- The field icon shows no vault data. HavenKeys ignores clicks on it that the page's own scripts fake.
- The passkey card's size is passed along by the extension's background script, so the website can't fake or change it.
The card ignores clicks until it is fully shown. - A page can see the icon when a login field is focused, which tells it HavenKeys is installed and active there. This
is listed under known limitations in docs/autofill.md.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
- HavenKeys icon in login fields. When you focus a username, password or one-time-code field, a small HavenKeys icon
Sürüm 0.4.2
25 Eyl 2026 tarihinde çıktı - 251,12 KBfirefox 128.0 ve üstü ile çalışırHavenKeys 0.4.2- Easier setup: the extension now works with just the HavenKeys desktop app
installed. From desktop 0.4.2 on, the app connects your browsers by itself
when you open it — no scripts or manual steps. - Clearer "Not connected" message: instead of pointing to developer docs,
the popup now tells you to install or update the HavenKeys app and open it
once.
Kaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
- Easier setup: the extension now works with just the HavenKeys desktop app
Sürüm 0.4.1
25 Eyl 2026 tarihinde çıktı - 251,1 KBfirefox 128.0 ve üstü ile çalışırHavenKeys 0.4.1
Everything since 0.1.0: passkeys, a redesigned app and extension, safer
master-password changes, the Secret Key moved into the OS keychain, and a way
to remove a device.
HIGHLIGHTS
Passkeys (0.4.0, 0.4.1)
HavenKeys can now act as the passkey provider for websites.- Create and save a passkey that a site offers, onto an existing login or a
new one. - Sign in with it from a passkey chooser, or from the field menu (passkey
autofill). - Automatic passkey upgrade: right after HavenKeys fills a password, a site
that offers an automatic upgrade gets a passkey saved to that same login.
By default this happens without a prompt and shows a short notice. Turn off
Settings > "Add passkeys automatically after I sign in" to get an
"Add a passkey?" card instead. An automatic upgrade only ever adds a
passkey. Replacing an existing one always goes through the card. - Passkey hint: on sites known to support passkeys where you have a password
saved but no passkey yet, the field menu links to that site's passkey help
(from the Passkeys Directory). - Manage them in the desktop app: each login lists its passkeys (site,
account, created) and each one can be deleted. - "Use another device" always hands the request back to the browser.
The private key is created, stored and used only in the desktop's Rust core
and never reaches the extension. The site's relying-party ID is checked in
Rust against the page the browser reports, and passkeys require a secure
(HTTPS) top-level page.
Passkeys work on the sites you have granted the extension access to. They are
unit-tested but have not yet been checked against real sites in a browser.
See docs/security-review.md (Passkeys) for known limitations.
Accounts and devices (0.3.0)
- Master password change goes to the server first. It updates the
credentials in one atomic request and signs out your other sessions. Your
other devices pick up a change made elsewhere at their next unlock. If the
server's answer is lost, the app asks the server whether the change applied
instead of guessing.
- Secret Key in the OS keychain, falling back to device.json when no keychain
is available. If the keychain is slow or still installing, the app asks you
to retry rather than asking for your Emergency Kit.
- Remove this device: revokes the device on the server and returns the app to
first run. The local vault file is set aside, not deleted.
- Unreadable items are retried on every sync and shown until resolved,
instead of being silently skipped.
- Open at login (Settings > Startup): HavenKeys can start with your session,
locked in the tray, and only one instance runKaynak kodu Apache Lisansı 2.0 lisansıyla yayımlandı
- Create and save a passkey that a site offers, onto an existing login or a