KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

Help center

KeyCare Pass Help

How to use the web vault and the browser extension, import your passwords, share with Send, keep your account safe, run an organization and host KeyCare Pass yourself.

Last updated 6 October 2026

KeyCare Pass is GovPAM's password manager for people and organizations. This page covers the web vault at vault.keycarepass.com, the KeyCare Pass browser extension, organizations, and running KeyCare Pass on your own server. Menu paths such as Settings > Security refer to the web vault unless a section says otherwise.

KeyCare Pass was called KeyGuard Password before it moved to keycarepass.com. Links to keyguard.govpam.com still work and lead here.

Getting started

Getting started

KeyCare Pass keeps your passwords, passkeys, cards, identities, secure notes and SSH keys in an encrypted vault. Your master password encrypts the vault on your device before anything reaches the server, so GovPAM cannot read it. To begin, create an account, install the browser extension, then import the passwords you already have and turn on two-step login. Every KeyCare Pass plan includes all premium features, such as file attachments, emergency access, verification codes (TOTP) and vault health reports, at no extra cost.

Create an account

Open the web vault (or your organization's own KeyCare Pass server) and choose Create account. Enter your email address and name, open the verification link KeyCare Pass emails you, and then choose your master password. Nobody can see or reset your master password, including GovPAM and your organization's administrators, so choose a long passphrase you will remember and add a hint that only you understand. If the server's administrator has turned off open sign-up, you can still create an account from an organization invitation.

Browser extension

Install KeyCare Pass from the Chrome Web Store: choose Add to Chrome, pin KeyCare Pass from the puzzle-piece menu, then sign in. Chrome, Brave and Vivaldi install it straight from the store; Microsoft Edge and Opera first ask you to allow extensions from other stores. The browser keeps KeyCare Pass up to date. IT administrators can install it on managed computers with the ExtensionInstallForcelist policy and extension ID flhkcdahnfdcmlmnpocghcnidhpgainm; the download page has the details, and a self-hosted package for networks that block the Chrome Web Store. The extension connects to vault.keycarepass.com; to use your organization's own server, choose Self-hosted on the sign-in screen and enter its address.

Language

KeyCare Pass is available in many languages. In the web vault, choose Settings > Appearance > Language; the default follows your browser's language. The browser extension always uses your browser's language. Some translations are incomplete, and untranslated text appears in English.

WebAssembly

KeyCare Pass needs WebAssembly, which current versions of Chrome, Edge, Brave, Opera and Vivaldi include. If the extension says WebAssembly is not supported, a browser setting or your organization's policy has turned it off; some security settings that turn off JavaScript optimization do so as well. Allow WebAssembly again and restart the browser, or ask your administrator.

Desktop app on Linux (Snap)

The KeyCare Pass desktop app is not released yet. When it is, the Snap package needs one more command after installing it, so that it can use your system's password store: sudo snap connect keycarepass:password-manager-service.

Using your vault

Searching your vault

Type in the search box at the top of the vault to find items by name, username, website or notes. Each word you type must appear somewhere in the item, in any order, so work email finds an item called Email Work. Use the filters beside the vault to narrow the list to favorites, an item type, a folder, a collection or an organization. For advanced searches, start with > and name a field, for example >name:bank* or >login.username:alice.

Copying usernames, passwords and codes

Every login has copy buttons for its username, password and verification code, in the web vault's item menu and in the extension. In the extension, turn on Settings > Appearance > Show quick copy actions in vault to copy straight from the list. Under Settings > Autofill, Clear clipboard removes copied values after the time you choose, and Copy TOTP automatically puts a login's verification code on the clipboard after autofill so you can paste it on the next screen.

Keyboard shortcuts

These are the extension's default shortcuts. On a Mac, use Cmd instead of Ctrl.

Shortcut What it does
Ctrl+Shift+L Fill the last used login for the current website. Press it again to cycle through the other matching logins.
Ctrl+Shift+Y Open the KeyCare Pass popup (Ctrl+Shift+U on Linux).
Ctrl+Shift+9 Generate a new password and copy it to the clipboard.

Filling a card, filling an identity and locking the vault have no default shortcut. Set or change any of them at chrome://extensions/shortcuts (edge://extensions/shortcuts in Edge). If a shortcut does nothing, another extension may already be using it.

Turning off the browser's password manager

Chrome and Edge have their own password managers, which can offer to save passwords KeyCare Pass already keeps and show their suggestions on top of KeyCare Pass's. In the extension, go to Settings > Autofill, choose Continue under Make your autofill experience better, and allow the permission the browser asks for; KeyCare Pass then becomes your default password manager and turns the browser's one off. You can also do it yourself in chrome://password-manager/settings (turn off Offer to save passwords and Sign in automatically) or in Edge under Settings > Passwords and autofill. Export the passwords saved in your browser and import them into KeyCare Pass first.

Autofill on page load

The extension can fill a login form as soon as the page loads, with the login that matches the page (see URI match detection). It is off by default. Turn it on in the extension under Settings > Autofill > Autofill on page load, and change it for a single login in that login's autofill options. Use it only on websites you trust: a compromised page can read what is filled into it.

Blocked domains

In the extension under Settings > Autofill > Blocked domains, list the websites where KeyCare Pass should not offer autofill and the features that go with it. Refresh a page that is already open after changing the list.

Fill assist

Fill assist (extension Settings > Autofill) fills forms with site-specific rules that the server publishes. It collects and saves no data. KeyCare Pass servers publish no rules yet, so with fill assist on, the extension keeps filling the usual way.

URI match detection

URI match detection decides which logins KeyCare Pass suggests on a page. The default, Base domain, matches the website and all its subdomains, so a login saved for example.com is offered on login.example.com. Host also matches the port, Starts with matches addresses that begin with the saved URI, Exact needs the whole address to match, Regular expression is for advanced patterns, and Never turns suggestions off for that URI. Change it for one website in the login's URI settings, or change the default in the extension under Settings > Autofill > Default URI match detection; an organization can also set a default with a policy.

Website icons

KeyCare Pass shows each website's icon next to its logins and can find the page where you change a site's password. Your KeyCare Pass server looks these up from the saved website addresses, so the websites see a request from the server rather than from your browser, and nothing about you is stored. To turn this off, clear Show website icons and retrieve change password URLs under Settings > Appearance, in the web vault and in the extension.

File attachments

You can attach files to any vault item from the item's Attachments option. Files are encrypted on your device before they are uploaded, and each file can be up to 500 MB. Each account has 1 GB of storage by default and each organization 10 GB; on a self-hosted server the administrator sets these amounts. The .json and .csv exports do not include attachments, so use the .zip export or download important files separately.

SSH keys

KeyCare Pass stores SSH keys as vault items. Choose New > SSH key to generate an Ed25519 or RSA key, or use Import to paste an existing private key from the clipboard; the item shows the public key and fingerprint to copy onto your servers. SSH keys can be shared with a team through organization collections like any other item. KeyCare Pass currently has a web vault and a browser extension but no desktop app, so it does not run an SSH agent. Copy the key into your SSH client or agent when you need it.

Import and export

Importing your data

First export your data from the old password manager or browser. Then, in the web vault, open Tools > Import, choose the matching file format, optionally choose a folder or an organization collection, and select the file. An import only adds items and never replaces existing ones, so importing the same file twice creates duplicates. Delete the export file afterwards, because anyone who finds a plain-text export can read your passwords. Organization owners and admins import shared items from Admin Console > Settings > Import.

Import from 1Password

In the 1Password 8 app, choose File > Export, pick the account, enter your password and save the file in 1PUX format. In KeyCare Pass, choose the format 1Password (1pux/json) and select the file. Exports from 1Password 6 and 7 (.1pif or .csv) also work: choose the 1Password format that matches your file.

Import from LastPass

In LastPass, open Advanced Options > Export in the web vault or browser extension and save the export as a .csv file. If LastPass shows the export as text in a browser tab, select all of it and save it in a text file ending in .csv. In KeyCare Pass, choose the format LastPass and select the file. LastPass folders become KeyCare Pass folders.

Import from Keeper

In Keeper's web vault or desktop app, go to Settings > Export and export as JSON, which keeps folders and shared folders, or as CSV. In KeyCare Pass, choose the format Keeper, pick the method that matches your file, and select it. Keeper does not include file attachments in these exports, so add important files to KeyCare Pass separately.

Import from KeePass

In KeePass 2, choose File > Export and save as KeePass XML (2.x), then in KeyCare Pass choose the format KeePass 2 (xml) and select the file. You can also choose KeePass (kdbx) to import the database file itself, entering its master password and key file when asked. For KeePassX or KeePassXC, export to CSV and choose KeePassX (csv).

Import from Chrome or Edge

In Chrome, open chrome://password-manager/settings, choose Export passwords and confirm with your computer's password to save a .csv file. In Edge, go to Settings > Passwords, open the More actions menu and choose Export passwords. In KeyCare Pass, choose the entry for your browser (Chrome for Chrome) and select the file, then delete the file and turn off the browser's password manager.

Import from Firefox

In Firefox, open about:logins, choose the menu (three dots) and Export passwords, and save the .csv file. In KeyCare Pass, choose the format Firefox (csv) and select the file. Delete the file when the import has finished.

Import from Safari

On a Mac, open Safari and choose File > Export > Passwords, or in the Passwords app choose File > Export All Passwords, and save the .csv file. In KeyCare Pass, choose the format Safari and macOS (csv) and select the file. Delete the file when the import has finished.

Exporting your data

In the web vault, open Tools > Export, choose a format and confirm with your master password. The .json and .csv formats are plain text that anyone can read, so prefer .json (Encrypted): Password protected can be imported into any KeyCare Pass account with the file password you set, while Account restricted can only be imported into your own account and stops working if you rotate your account encryption key. The .zip (with attachments) format includes your files, and .csv contains only logins and secure notes, without passkeys. Owners and admins export an organization's vault from Admin Console > Settings > Export.

Send and passkeys

Send

Send shares text or a file with anyone, even people without KeyCare Pass, through an encrypted link. Create one under Send in the web vault or extension, and set a deletion date of up to 31 days. You can also set an expiration date, a maximum number of views, a password, and whether to hide your email address from the recipient. The link itself holds the key that decrypts the Send, so share it only with the intended person and give any password through a different channel.

Opening a Send

Open the Send link in any web browser; you do not need a KeyCare Pass account. If the Send is protected, enter the password the sender gave you, then copy the text or download the file. A Send that has expired, reached its view limit or been deleted shows as unavailable, so ask the sender for a new one. If you did not expect a Send, check with the sender through another channel before opening any file.

Passkeys

A passkey replaces a password with a pair of keys: the website keeps a public key and KeyCare Pass keeps the private key in your encrypted vault, so there is nothing to phish or reuse. KeyCare Pass can save passkeys for websites and use them on every device where you sign in to KeyCare Pass, and you can log in to KeyCare Pass itself with a passkey.

Saving passkeys for websites

When a website offers to create a passkey, the KeyCare Pass extension asks where to save it: choose an existing login or save it as a new login. The next time you sign in, choose the website's passkey option and confirm in KeyCare Pass. Each login holds one passkey, and passkeys are included in .json exports but not in .csv exports. If you would rather use your device or a hardware key, choose that option in the KeyCare Pass prompt, or turn off Settings > Notifications > Ask to save and use passkeys in the extension.

Log in to KeyCare Pass with a passkey

You can sign in to the KeyCare Pass web vault with a passkey instead of your email and master password. Set one up under Settings > Security > Master password > Log in with passkey, confirm your master password, and follow your browser's prompts; your device's fingerprint, face, PIN or security key then protects it. If your browser supports it, turn on vault encryption for the passkey so that it also unlocks your vault. A passkey works only on the server it was created for, so one made for vault.keycarepass.com does not work on your organization's own server.

Account security

Two-step login

Two-step login asks for a second proof, such as a code from your phone, after your master password. Turn it on under Settings > Security > Two-step login. You can use an authenticator app, a passkey or security key (FIDO2 WebAuthn, including YubiKey), codes sent by email, or Duo. Save your recovery code somewhere safe outside KeyCare Pass, because it is your way back in if you lose your second step.

Security keys and passkeys are tied to the address they were added on. Those added on keyguard.govpam.com, before the move to vault.keycarepass.com, do not work there: sign in with another two-step method or your recovery code, add the key again under Settings > Security, and remove the old entry.

Lost your two-step login device

If you set up more than one method, choose a different one on the two-step login screen. Otherwise use your recovery code: choose Recovery code on that screen, or open vault.keycarepass.com/#/recover-2fa and enter your email, master password and recovery code. This turns off every two-step login method on your account, so sign in and set two-step login up again, which also gives you a new recovery code. Without a recovery code, nobody can turn two-step login off for you, including GovPAM and your organization's administrators.

Fingerprint phrase

Your fingerprint phrase is a set of words derived from your account's public encryption key. Find yours under Settings > My account, or in the extension under Settings > Account security. When an organization admin confirms you, or you confirm an emergency contact, the two of you should compare the phrase over a channel you trust, such as a phone call. If the phrases differ, stop and contact [email protected].

KDF algorithms

Before your master password becomes an encryption key, KeyCare Pass runs it through a key derivation function (KDF), which makes guessing it slow for an attacker. KeyCare Pass supports PBKDF2-SHA256 (600,000 iterations by default) and Argon2id (by default 6 iterations, 32 MiB of memory and a parallelism of 4). Change it under Settings > Security > Keys > Encryption key settings. Higher settings are stronger but slower to unlock, so raise them in small steps and test on your slowest device; changing them signs you out everywhere.

Account encryption key

Your account encryption key encrypts everything in your vault, and your master password protects that key. If you think your master password or a device has been compromised, change your master password under Settings > Security > Master password and tick Also rotate my account's encryption key, which re-encrypts your vault with a new key. Afterwards, sign out of every KeyCare Pass app and extension and sign in again. Account restricted exports made with the old key can no longer be imported, so make a new export if you need one.

Emergency access

Emergency access lets a trusted person with their own KeyCare Pass account on the same server reach your vault if something happens to you. Invite them under Settings > Emergency access, choose View (they can read your vault) or Takeover (they can set a new master password for your account), and choose a wait time. After they accept, confirm them once you have compared fingerprint phrases. When they request access you get an email and can reject it; if you do nothing, access is granted when the wait time ends.

Phishing warnings

When you open a website that is on Phishing.Database, an open-source list of known phishing sites, the extension shows a warning instead of the page. Close the tab. Continue only if you are certain the site is safe, and never enter your master password on a page you reached through an unexpected link.

Organizations

Organizations

An organization lets a team share passwords and other items through collections, with groups, custom roles, policies and event logs. Every member has all KeyCare Pass features. On vault.keycarepass.com, you create an organization by choosing Families, Teams or Enterprise on the plan page and paying for its seats through PayFast (see pricing). On your own KeyCare Pass server, the administrators listed in ORG_CREATORS create organizations from the web vault's New organization page, and anyone else uses a KeyCare Pass license from GovPAM. KeyCare Pass does not include single sign-on (SSO) or SCIM provisioning.

Managing your organization

Owners and admins manage an organization from the Admin Console, which you open from the product switcher or the organization's menu in the web vault. It has Collections, Members, Groups, Reporting (event logs and reports), Billing (the license) and Settings (organization info, policies, import and export). Owners can rename the organization, view its API key and delete it under Settings > Organization info.

Members and groups

Members are the people in your organization. Each member has a role and can reach only the collections they are given, either directly or through groups. A group, such as Finance or IT Support, gathers members so you can give many people access to collections at once; create groups under Groups and add members to them there or when you edit a member.

Inviting and managing members

Invite people under Members > Invite member with their email addresses, a role, and their collections or groups; each person gets an email invitation and creates a KeyCare Pass account if they do not have one. After they accept, an owner or admin must confirm them (Members, filter Needs confirmation), which gives them the organization's encryption key, so compare fingerprint phrases first. Revoke access to suspend a member without removing them, Restore access to bring them back, and Remove people who leave. Invitations need the server's email to be set up.

Roles and access control

Owners manage everything, including other owners, the license and deleting the organization. Admins manage members, groups, collections, policies and settings. Users see only the collections they are given, and custom roles grant just the permissions you pick, such as managing members or reading event logs. In each collection, a member or group can View items, View items with hidden passwords, Edit items, Edit items with hidden passwords, or Manage collection. Hidden passwords can still be autofilled, so treat them as a convenience rather than a security boundary.

Collection management

Collections hold the items an organization shares. Create them under Collections in the Admin Console (or New > Collection in the web vault) and give members and groups access with the permissions above. Under Settings > Organization info > Collection management, owners choose whether only owners and admins may create or delete collections, whether deleting items needs the Manage collection permission, and whether owners and admins can manage all collections and items from the Admin Console.

Policies

Policies apply rules to your organization's members. Owners and admins set them in the Admin Console under Settings > Policies. They include Require two-step login, Master password requirements, Password generator, Single organization, Account recovery administration, Centralize organization ownership, Remove Send and Send options, Remove card item type, Remove Unlock with PIN and Default URI match detection. Most policies do not apply to owners and admins, and some, such as account recovery, need the Single organization policy to be on first.

Account recovery

Account recovery lets owners and admins reset the master password of a member who has forgotten it. Turn on the Account recovery administration policy (after Single organization); members then enrol from the organization's menu in their vault, or you can enrol new members automatically. To help someone, open Members, choose Recover account from the member's menu and set a new master password, which the member must change when they next sign in. Recovery does not turn off the member's two-step login.

Automatic confirmation

Automatic confirmation would add invited members to an organization as soon as they accept, without an admin checking them. KeyCare Pass organizations do not offer it: an owner or admin confirms each member under Members, which keeps a person in the loop before the organization's key is shared. To confirm many people at once, select them and choose Confirm.

Claimed accounts

A claimed account is one that an organization controls because it has verified ownership of the account's email domain. KeyCare Pass organizations do not use domain verification, so KeyCare Pass accounts are never claimed. Your account stays yours when you join an organization: its administrators manage your membership and your access to shared items, not your account's email, name or personal vault.

Centralize organization ownership

The Centralize organization ownership policy makes the organization the owner of the items members store: members can no longer save items to their individual vault, only to the organization's collections. Owners and admins are exempt. Members who already have individual items may be asked to transfer them to the organization. Turn it on under Settings > Policies.

Transferring ownership

To move one of your items into an organization, open its menu and choose Assign to collections (Move to organization in some views); from then on it belongs to the organization. When an organization requires organization ownership, Accept transfer moves your individual items to it, while Decline and leave keeps them in your account but removes your access to the organization until an admin restores it. To hand over the organization itself, an owner makes another confirmed member an Owner under Members; an organization can have several owners.

API

The organization API key, under Admin Console > Settings > Organization info > View API key (owners only), lets your own tools manage members, groups, collections and policies and read event logs. Get a token from https://<your server>/identity/connect/token with the OAuth 2.0 client credentials grant, your client ID and secret, and the scope api.organization, then call the endpoints under https://<your server>/api/public/. Your personal API key, under Settings > Security > Keys, signs in command-line tools as you. Keep both secret, and rotate a key if it leaks.

Onboarding playbook

A rollout that works well for most organizations:

  1. Get your organization: choose a plan for it on vault.keycarepass.com, or create it on your own server.
  2. Before inviting anyone, turn on the policies you need: Require two-step login, Master password requirements, Single organization and Account recovery administration with automatic enrolment.
  3. Create collections for the systems you share, and groups that match your teams.
  4. Import shared credentials into those collections from Admin Console > Settings > Import.
  5. Install the browser extension on managed computers with the ExtensionInstallForcelist policy.
  6. Invite members team by team, confirm them promptly, and point them to this page's Getting started and Importing sections.
  7. Review Reporting > Event logs and Reports regularly.

Your own KeyCare Pass server

Self-hosting KeyCare Pass

Organizations can run KeyCare Pass on their own Docker host; contact [email protected] for the server package. Its deploy/docker/compose.yml runs two containers, keycare_server (every KeyCare Pass service and the web vault) and keycare_db (PostgreSQL 16), behind your reverse proxy, which terminates TLS for KeyCare Pass's hostname and forwards everything to keycare:8080. Put the settings in an env file, start or update the stack as shown below, and wait for keycare: ready in the log. Back up the database, the state volume (signing certificate, keys and settings) and the attachments together, because the database alone cannot be restored.

docker compose -p keycare -f deploy/docker/compose.yml --env-file /path/to/keycare.env up -d --build
docker logs -f keycare_server

Server settings (environment variables)

These go in the env file you pass with --env-file. After changing them, run the up -d command again to apply them.

Variable Meaning
KEYCARE_URL Required. The server's public address, for example https://keycarepass.example.gov. Links in emails and passkeys depend on it, so set it before people sign up.
MAIL_FROM Required. The address KeyCare Pass's emails come from.
DB_PASSWORD Required. The password of the stack's PostgreSQL database. Generate a long random value when you create the stack, and keep it.
SMTP_PASSWORD A Cloudflare API token with Email Sending: Edit. KeyCare Pass sends email through Cloudflare Email Service, so the domain of MAIL_FROM must be set up there. Empty means no email, so invitations, verification emails and email two-step codes do not work.
ADMIN_EMAILS Comma-separated email addresses allowed into the server's admin portal at /admin, which signs in with an emailed link. Empty keeps it closed.
ORG_CREATORS Comma-separated email addresses of the KeyCare Pass users who may create organizations from the New organization page, or * for everyone. Empty means organizations come only from licenses.
ORG_STORAGE_GB File storage for each organization, in GB. Default 10.
USER_STORAGE_GB File storage for each user, in GB. Default 1.
DISABLE_USER_REGISTRATION true stops open sign-up; people invited to an organization can still create an account. Default false.
KEYCARE_WEB_DIR Required. The folder on the host that holds the web vault build, mounted read-only into the server.
PROXY_NETWORK Required. The name of the existing Docker network your reverse proxy is on. Only the server container joins it; the database stays on the stack's own network.
KEYCARE_ATTACHMENTS_DIR Optional. A folder on the host for attachments and Send files. Point it at a filesystem of fixed size so uploads can never fill the host's disk. Without it, files go in a Docker volume.

Licenses

A KeyCare Pass license lets you create an organization on your own KeyCare Pass server without being listed in ORG_CREATORS. GovPAM issues each license for one server, bound to that server's installation id, and it runs until its expiry date; licenses signed by anyone else are refused. Organizations that a server's administrators create directly need no license and do not expire. To request a license, send the installation id, the organization's name and its billing email to [email protected]. The server logs its installation id each time it starts:

docker logs keycare_server | grep "installation id"

The id stays the same as long as the server keeps its state volume; a server rebuilt with a new volume gets a new id and needs a new license.

Applying a license on your server

Sign in to the web vault on the server the license was issued for, choose New organization, and upload the license file; you become the new organization's owner. To renew or replace a license, the owner opens the organization in the Admin Console, goes to Billing > Subscription and uses Upload license, and the organization takes the new expiry date. When a license expires, the server disables the organization at its next nightly check, so upload a renewal before the date shown under Billing > Subscription. The organization's data stays on your server throughout.

Sponsorships and license sync

Family plan sponsorships and automatic license sync are not part of KeyCare Pass. Every KeyCare Pass plan already includes all premium features, so there is nothing to sponsor, and a KeyCare Pass server never connects to a billing service. To update a license, upload the new file under Billing > Subscription > Upload license, as described in Applying a license.

Help

Contact

For help with KeyCare Pass, licenses or organizations on vault.keycarepass.com, email [email protected]. Report security issues to [email protected]. We never ask for your master password, and nobody at GovPAM can see it, so never share it with anyone who asks.

Back to contents