Yab keeps your passwords in the macOS keychain, encrypted by the system and readable only by Yab, only while your Mac is unlocked. Nothing is kept anywhere else.
Saving#
Once a sign-in has actually worked, Yab asks Save password for …?. ↩ saves it. Not now parks the offer as a key on the tab, for later, and Never on This Site stops asking there. A password you change is offered as an update.
Filling#
Nothing is filled by itself. Click in a sign-in box and your accounts for that site appear just under it, the one used last first. ↑ ↓ and ↩ fill one, or keep typing to narrow them. On a sign-in in two steps, the password step fills itself.
Turn on Settings › Passwords › Ask for Touch ID before filling for Touch ID first. One yes lasts five minutes, until the Mac locks.
Your passwords#
⌥⌘L lists them in the field, the site you are on first. Seeing the list needs nothing; copying or showing a password asks for Touch ID.
⌘K also opens the site’s own page for changing a password, adds a one-time code, and exports your passwords as a CSV file.
Leaked, reused, weak#
Passwords you use on more than one site, or that are easy to guess, are marked. Check for Leaks… looks for yours in known breaches. Only the first five characters of each password’s hash are sent, so no one, including the checking service, learns the password.