BoxOwl sees the form
The extension reads the field labels, types, and context. Even on single-page apps and dynamically rendered forms.
BoxOwl is your personal stack — your secrets, your data, and the AI tools you already use. Universal autofill, a public profile you control, per-field privacy. One source of truth.
The browser extension reads the form, asks you, and fills it. You stay in control — per field.
The extension reads the field labels, types, and context. Even on single-page apps and dynamically rendered forms.
Field-level pickers: which address is this — home, work, billing? Defaults are smart; the choice is yours.
All matched fields populate, with a subtle highlight as confirmation. Wrong field? Edit inline. Nothing leaves your device that you didn't approve.
Your saved cards are tied to the addresses in your vault — yours, your household's, family, friends, even one-time gift destinations. At checkout a merchant can ask BoxOwl "is this card+ship-to combination one this shopper recognizes?" and get back a yes / no / step-up answer with a signed receipt — without ever seeing your identity or address. A stolen card can't be shipped to a thief. Shared cards just work: every co-owner's address book is part of the trust universe. How the Trust Triangle works →
boxowl.me/u/{handle}.One link that holds your bio, contact, and the things you choose to show. Style it your way, share via QR.
One scoped token. The assistant talks to your local-vault daemon over MCP (or REST for ChatGPT-style hosts) — your secrets never leave your machine in plaintext.
Edit one JSON file. MCP-native. Setup walkthrough →
One command: npx @boxowl/skills add. Setup walkthrough →
MCP-native code editor. Skills installer handles the config. Setup walkthrough →
GitHub Copilot's MCP host in VS Code. Skills installer knows about the servers key quirk. Setup walkthrough →
The recommended fully-local orchestration partner. Hermes Agent runs Hermes on your hardware and talks to BoxOwl over MCP — vault + audit stay local. Setup walkthrough →
Custom GPT with BoxOwl's REST API as an Action. No MCP needed. Setup walkthrough →
Also works one-shot via @boxowl/skills on Windsurf, Codex, and Gemini CLI —
see all hosts.
Three guarantees that work the same way no matter which section you're touching: one structured vault, per-field visibility on each row, encrypted local sync you can take with you.
Every field has its own visibility. Revoke anytime. Export, or delete the vault entirely.
Encrypted local cache means BoxOwl works on the train. Full JSON export, anytime. Deletion is one tap.
SQLCipher-encrypted local cache. Delta sync only changed fields. Last-write-wins on conflict.
Your data, in a portable, structured format. Drop it anywhere; we don't lock you in.
Erase the entire vault and any connected org grants. CCPA & GDPR delete obligations satisfied.
A portable, cryptographic identity at did:web:boxowl.me:you. Resolvable, verifiable, yours.
BoxOwl offers two ways to integrate — SMRT for lightweight identity, PDaaS as a full data layer.
BoxOwl is in private beta. Join the waitlist to receive a registration token.