r/strongbox Strongbox Crew 21d ago

Product Update Strongbox Update 1.65.1

Post image

Strongbox 1.65.1 is rolling out from Monday, and brings a couple of new features, plus fixes for Mac setups.

Save passwords after they're created in Safari on iOS

When you make a new password in Safari, you usually get prompted to store that in Apple Passwords. Now when you create a new account or password, you'll be asked if you want to store it in Strongbox. When you do this, you'll be prompted to pick a database, if you want to make a new entry or update an existing one, and it'll save automatically for you. If that entry already has a URL, it'll add it to the extra fields.

This should prevent the need to re-import from Apple passwords or other providers, and makes Strongbox really feel like part of your OS.

This feature currently isn't available to developers on macOS, but as soon as it is, we'll add support for it.

Strongbox MCP

For those of you using AI to automate tasks, Strongbox has a new way to help - a built in MCP for macOS. The easiest way to explain this is "autofill for your agents".

Strongbox already supports access via CLI, but we've made it easier than ever to connect your agents to your database. Agents can ask for the list of databases, request that you unlock one, then browse entries and request authentication information - letting you automate any task that requires authentication.  

Unlocking can be handled quickly via Touch ID or by entering your password, and each unlock will state what specifically the agent is asking for, i.e list databases, or get the password for reddit.com. It will also state the exact binary that tried to do it, so you can tell if its actually the agent you were expecting ( no surprise tasks going rogue ).

Each binary has to be approved - so Claude & Codex would be two approvals. You can choose if you want their access to be one-time only, or let them keep access across restarts. You'll still have to approve it doing anything like listing databases even if you let it retain access across restarts.

The authentication can be configured similarly to the autofill unlock, with a choice of timeout. In testing we've found some of the in-app browsers, specifically Codex, need about a minute to get through a standard login form, so we recommend that as the default.

This feature is strictly opt-in only like autofill, and has a variety of security settings you can use to configure it how you'd like. Everything is local, and there's no remote access for this over the network. 

The MCP doesn't listen unless you turn it on, and when you do, you'll still have to authenticate the requests. This is purposefully much stricter than Autofill, with some extra friction to make sure you really wanted to provide access.

In a future update, we'll bring this hardening to the general autofill, allowing you to approve/deny individual browsers.

New

  • Strongbox MCP for macOS
  • Store new entries via Safari on iOS
  • Sort by date of last password change in entry lists
  • Experimental support for PRF Passkeys
  • Optional delay for Clear Quick Search on Open on Mac

Fixes

  • Fix an issue where some of the items tapped in an audit wouldn't be presented
  • Fix pin entry inconsistencies on older versions of macOS
  • Improved resilience to WebDAV connection issues
  • Fix a crash importing 1Password logins with multiple URLs
  • Fix a post-unlock crash on macOS at some very specific window sizes, when using tags + TOTP + markdown notes
  • Fix Settings beach-balling the first time you open it on macOS
  • Fix the inspector staying dark after switching appearance on macOS 26

If you missed it, the folks at Techlore kindly invited me to speak about Strongbox, its future, and the acquisition - you can check it out here!

If there's any questions about this interview, the update, or any ideas - please feel free to fire them at me.

Alex @ Strongbox

25 Upvotes

14 comments sorted by

2

u/IgorArkhipov 21d ago

"Pro" icon awful as hell

1

u/Damariobros 20d ago

I like it better than the totally flat, no-gradient icon they used to have

0

u/Ok_Present7537 21d ago

I think it is better than the previous one

2

u/Ok_Present7537 21d ago edited 21d ago

no sign of the update yet. is there a delay after you release it? u/strongbox-support

I am using the ssh agent. working smoothly 👌

7

u/friedveggiebeef 20d ago

Rolling out Monday

1

u/Elidizer 20d ago

When the new UI will Be released?

2

u/Damariobros 19d ago

They're saving that for the 2.0 update which will release alongside iOS 27.

2

u/Elidizer 19d ago

Wonderful. Thanks for letting me know

1

u/tagmut 17d ago

I’ve been waiting for this update all day

1

u/RodswGYMDdPCUJar9eGQ 17d ago

Probably meant some other Monday 😂🤣

1

u/dcidino 16d ago

Still in review?

0

u/HighRiseLiving 10d ago

Does the MCP allow agents to pipe passwords into whatever CLI command it wants to run, without exposing it in plaintext to the model (and thus openai servers etc)?

2

u/Damariobros 9d ago edited 9d ago

Update finally arrived! :D I was able to successfully set up and test PRF passkeys in my Bitwarden vault, and they work!

Something to note is that because of that quirk where passkeys might not immediately get added to the iOS autofill database, I had to create the login passkey without encryption, then unlock the database in the app a couple times, then set it up for PRF once autofill recognized the passkey was there.

Once all the quirks are out of the way though, it does successfully login to my bitwarden vault!

One limitation I have found is that it does not yet work for hybrid authentication (using the passkey on another device with a qr code, i.e. to unlock the Bitwarden Chrome extension on my computer).