Your key should have a smaller journey than you do.
Anonymous tools keep the key in the browser tab. Optional cross-device storage encrypts it before upload with a passphrase the server never receives.
Direct tools
Connection Doctor, Playground and Compare call only cataloged provider endpoints from your browser. FreeToken.link does not proxy these requests. Some providers block browser cross-origin access; in that case we recommend a local config.
Encrypted Vault
The browser derives an AES-256-GCM key from your passphrase using PBKDF2-SHA-256 with a random salt and 250,000 iterations. Each item receives a fresh random IV. The service stores ciphertext, salt, IV, provider label and encryption version.
Recovery tradeoff
There is no server-side passphrase reset. If you forget the passphrase, you must delete the ciphertext and save the key again. This is the cost of keeping decryption authority out of the service.
Advertising boundary
Ads are reserved for public discovery and editorial pages. They are excluded from key-entry tools, the Vault, live responses and config output surfaces.