Caja Fuerte

Encrypted, local-only link vault with a decoy password, auto-expiring links, time-locked entries and serverless encrypted sharing.

As of June 2026, Caja Fuerte has users in the Privacy & Security category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
1.0.0
Manifest V3

History

1 snapshots

Tracking since Jun 7, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
Jun 7, 20261.0.0
Now1.0.0

Permissions & access

Permissions
storageclipboardWriteactiveTab
Host access
None declared

Screenshots

Caja Fuerte screenshot 1Caja Fuerte screenshot 2Caja Fuerte screenshot 3Caja Fuerte screenshot 4Caja Fuerte screenshot 5

About

Caja Fuerte keeps your private links in an encrypted, local-only vault. Each URL and title is encrypted with AES-256-GCM (key derived with PBKDF2-SHA256,
  600,000 iterations), held in memory only. No account, no server, no sync, no tracking — everything stays in your Firefox profile.

  **Features**

  • **Decoy (duress) password** — a second password that opens a separate, innocuous set of bookmarks. If forced to unlock, hand over the decoy while your
  real entries stay encrypted. Plausible deniability of content, not a hidden volume.

  • **Auto-expiring entries** — set an expiry date or a maximum number of opens; the record is deleted on the next unlock. An app-enforced auto-tidy, not
  guaranteed unrecoverable destruction.

  • **Scheduled reveal** — keep an entry hidden until a date you pick. A display rule, not a cryptographic seal.

  • **Serverless encrypted sharing** — turn a link into a self-contained encrypted code and QR. The recipient needs both the code and a separate passphrase,
  sent through a different channel. Nothing touches any server.

  • **Encrypted backup** — export the whole vault to a file encrypted under a passphrase you choose, and restore it on a fresh install or new device. The
  backup never contains plaintext.

  • **Display ciphers** (Morse/Binary/Caesar/Atbash) — cosmetic only; AES-256-GCM is the real protection.

  • **Auto-lock** after a configurable inactivity timeout (default 5 minutes).

  • Available in **7 languages**.

 There is no password recovery — if you forget your master password, the data cannot be decrypted. The expiry and scheduled-reveal features are app-level
  conveniences, not a replacement for full-disk encryption.

Technical

Version
1.0.0
Manifest
V3
Size
109KiB
Min Chrome
88
Languages
7
Featured
No

Metadata

ID
cejjbojkfpnagmjijbmmccbdpcekhheb
Developer ID
u4091f26376a27bb5a17649f87fdd2981
Developer Email
[email protected]
Created
Jun 6, 2026
Last Updated (Store)
Jun 6, 2026
Last Scraped
Jun 7, 2026
Website
Support URL

Data sourced from the Chrome Web Store · last verified Jun 7, 2026.