Firefox Browser Add-ons
  • Extensions
  • Themes
    • for Firefox
    • Dictionaries & Language Packs
Log in
Add-on icon

Lockwright version history - 10 versions

Lockwright by MozDev

There are no ratings yet
0 Stars out of 5
5
0
4
0
3
0
2
0
1
0
Lockwright version history - 10 versions
  • Be careful with old versions! These versions are displayed for testing and reference purposes.You should always use the latest version of an add-on.

  • Latest version

    Version 0.0.31

    Released Sep 30, 2026 - 1.01 MB
    Works with firefox 140.0 and later, android 142.0 and later
    Security
    - Passkeys are bound to the site asking for them. The origin comes from the browser, not the page; the relying party must match the page's site; the result goes back only to the frame that asked; and the popup shows which site is asking.
    - Sites on shared hosting (vercel.app, github.io, netlify.app, pages.dev and similar) are now separate sites for autofill, passkeys and saving logins. Previously a login saved for one tenant could be offered on another.
    - Autofill from the popup fills the top frame only and skips hidden fields.
    - The desktop app only accepts relayed messages from the extension's own pages, and only for known commands. Auto-lock settings travel over the encrypted channel.
    - The local key is derived with 600,000 PBKDF2 iterations. Existing keys are upgraded on the next unlock.
    - The popup's content security policy is tighter.
    - Vault update: a protected vault's key no longer sits in the vault list, pairing refuses a vault that is already on the device, and a device that leaves a vault loses write access.

    Changed
    - Smaller and faster: the page script dropped from 212 KB to 63 KB, and unused libraries, fonts and images are gone.
    - The revoke dialog explains that a removed device can still read the vault until it is moved to a new one.

    Source code released under Apache License 2.0

    Download Firefox and get the extension
    Download file
  • Older versions

    Version 0.0.28

    Released Sep 24, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    • Saving a login now uses the page title as the entry name.
    • A locked vault no longer reopens the logo iframe.
    • The toolbar popup in Zen keeps its size.
    • Clipboard replacement can now be turned off.
    • Generator history shows each site and entry a generated password was used for.
    • The toolbar popup opens correctly again instead of showing an empty dark panel.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.27

    Released Sep 24, 2026 - 1.64 MB
    Works with firefox 140.0 and later, android 142.0 and later
    0.0.27 (2026-09-24)
    • Save card title uses the page title.
    • Locked vault does not reopen the logo iframe.
    • Zen toolbar popup keeps its size.
    • Clipboard replacement can be turned off.
    • Generator history shows each site and entry a generated password was used for.
    • A 2FA field labeled OTP matches when the input name is _auth_code.
    • Authenticator and Generator sit in one sidebar group.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.26

    Released Sep 22, 2026 - 1.64 MB
    Works with firefox 140.0 and later, android 142.0 and later
    0.0.25 (2026-09-14)
    - Auto Lock timeout menu shows durations (30 seconds, 1 Minute, Never) instead of Lingui message ids.
    - Password strength label Safe is a compiled Lingui message. It no longer warns as uncompiled.
    - Desktop-unavailable checkAvailability timeouts and native-host disconnects stay out of the console unless Debug logging is on.
    - Inactivity auto-lock does not throw when vault status refetch returns nothing.
    - Password generator history no longer passes Tailwind className into kit Text (Strict DOM invalid prop "className").
    - Password recommendation box has an X. Paste and confirm-password no longer trap it.
    - Android browsers skip the desktop native host. Onboarding no longer asks for a pair code or clip at 600px.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.23

    Released Sep 11, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    The first time you pair this extension with the Lockwright desktop app, a correct master password is no longer shown as wrong. Pairing still waits until the vault accepts the password.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.22

    Released Sep 7, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    Fixed an issue in Firefox where the popup was stuck on “Just a moment…” when the desktop vault check failed or Firefox never answered sendMessage. It now times native messages out at 10s and shows the connection UI instead of spinning forever.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.21

    Released Sep 5, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    0.0.18 — Pairing sends the browser name so desktop can tell clients apart. Wrong pairing password stays retryable; the prompt stays up.

    0.0.19 — Settings Debug logging (off by default). Wrong password, lockout probes, and favicon misses no longer spam console.error. Auto-lock timeout labels are real Lingui strings.

    0.0.20 — Authenticator requests OTP codes so digits and the 1s timer show after Home stopped generating them for the whole vault.

    0.0.21 — Login URIs store as typed. Opening a glued https://androidapp://… row and saving writes androidapp://….

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.17

    Released Sep 3, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    Autofill from login right-click. Add site was only on Current Site (URL already known). New URIs match on host.
    Close login-detect after a successful save. Empty i18n painted a blank error bar; Not now stayed disabled. Vault pin so a v1 timeout after a v2 write is not a failed save.
    Cap onboarding wordmark so the pair step fits.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.16

    Released Sep 1, 2026 - 1.65 MB
    Works with firefox 140.0 and later, android 142.0 and later
    Lockwright 0.0.16

    Needs a current Lockwright desktop app (browser sync on). This build will not pair with PearPass or with an older Lockwright desktop.
    • Pairing uses the Lockwright handshake. Re-pair if the extension was paired before this update.
    • Lockwright icons and brass UI.
    • Password generator remembers the last length you set.
    • Onboarding pair step no longer clips the wordmark.
    • Terms and privacy links go to lockwright.dexterity.works.

    Source code released under Apache License 2.0

    Download file
  • Version 0.0.3

    Released Aug 29, 2026 - 1.66 MB
    Works with firefox 140.0 and later, android 142.0 and later

    Source code released under Apache License 2.0

    Download file
Go to Mozilla's homepage

Add-ons

  • About
  • Firefox Add-ons Blog
  • Extension Workshop
  • Developer Hub
  • Developer Policies
  • Community Blog
  • Forum
  • Report a bug
  • Review Guide

Download

  • Download Firefox
  • Windows
  • macOS
  • iOS
  • Android
  • Linux
  • All

Latest Builds

  • Nightly
  • Beta

Firefox for Business

  • Enterprise

Community

  • Connect
  • Contribute
  • Developer

Follow

  • Instagram
  • YouTube
  • TikTok
  • Bluesky
  • Podcast
  • Privacy
  • Cookies
  • Legal

Except where otherwise noted, content on this site is licensed under the Creative Commons Attribution Share-Alike License v3.0 or any later version.