Crypto self-test
This page runs the entire zero-knowledge stack in your browser — mnemonic generation, key derivation, authenticated encryption, and ECDH key-wrapping for sharing — and reports each step. Nothing is transmitted or stored. If every check passes, your device can fully participate in the SecureIDsafe perimeter.
WebCrypto SubtleCrypto available
AES-GCM, PBKDF2, ECDH + CSPRNG present
Generate 24-word BIP-39 mnemonic (256-bit entropy)
energy security wonder crawl … (24 words)
Mnemonic passes BIP-39 wordlist validation
all 24 words are valid BIP-39 English
PBKDF2-SHA512 seed derivation (2048 iterations → 64 bytes)
64 bytes derived
Derive AES-256-GCM vault key (PBKDF2-SHA256, 600k)
vault key held in memory (extractable for sharing)
Key verifier is deterministic (PBKDF2 100k)
ab8a707d6dda34a5… (stable across calls)
Seal/open string round-trip (AES-256-GCM)
sealed 84 chars → decrypted OK
Generate ECDH P-256 keypair (Alice)
P-256 keypair
Generate ECDH P-256 keypair (Bob)
P-256 keypair
Export & re-import public keys (base64)
public keys are portable
ECDH shared key matches on both sides
Alice and Bob derive the same AES key
Wrap vault key → unwrap with peer → decrypt owner data
recipient-side unwrap decrypts owner ciphertext
All cryptographic primitives verified.
Your browser generates strong entropy, derives keys identically across sessions, and supports the ECDH key-wrapping that powers recipient-bound sharing. The zero-knowledge guarantees on this device are intact.
Is this password compromised?
Check whether a password has appeared in a known data breach. Your password is hashed in your browser and only the first 5 characters of its SHA-1 hash are sent — the full hash never leaves this tab. Powered by the free HaveIBeenPwned Pwned Passwords API.
