vaultkeeper

Local-first, zero-knowledge password manager β€” AES-256-GCM + PBKDF2 encryption, optional self-hosted sync (React, TypeScript)

GitHubTypeScriptCSSJavaScriptDockerfileHTML
πŸ‘ 50 vuesSync GitHub: 10/9/2026
aes-256encryptionlocal-firstpassword-managerreactsecurityself-hostedzero-knowledge

VaultKeeper

Local-First Password Manager with End-to-End Encryption and Optional Self-Hosted Sync

CI License: MIT React TypeScript

Features

  • Local-first β€” All data stored encrypted in your browser's localStorage
  • E2E encryption β€” AES-256-GCM with PBKDF2 key derivation (600,000 iterations)
  • Zero-knowledge β€” The server never sees your plaintext data or master password
  • Optional self-hosted sync β€” Sync across devices with your own server
  • Password generator β€” Configurable length, character sets, passphrase mode
  • Password strength meter β€” Real-time entropy calculation
  • Categories & tags β€” Organize entries with categories and tags
  • Favorites β€” Mark frequently used entries
  • Search & filter β€” Full-text search across all fields
  • Auto-lock β€” Vault locks after 15 minutes of inactivity
  • Modern UI β€” Dark theme with TailwindCSS, Lucide icons

Security Architecture

Master Password
      β”‚
      β–Ό
  PBKDF2 (600,000 iterations, SHA-256, 32-byte salt)
      β”‚
      β–Ό
  AES-256-GCM Key (non-extractable)
      β”‚
      β”œβ”€β”€β–Ί Encrypt each vault entry (individual IV per entry)
      β”œβ”€β”€β–Ί Create verifier token (to validate password on unlock)
      └──► Never stored, never sent to server
  • Key derivation: PBKDF2 with 600,000 iterations and SHA-256
  • Encryption: AES-256-GCM (authenticated encryption)
  • Key storage: CryptoKey objects are non-extractable (never serialized)
  • Sync: Only encrypted vault data is sent to the server
  • Server: Stores encrypted blobs, never has access to plaintext

Quick Start

Frontend (Web App)

npm install
npm run dev

Open http://localhost:5174

Sync Server (Optional)

npm run dev:server

Server runs on http://localhost:3001

Docker

docker-compose up

Usage

  1. Create your vault β€” Choose a strong master password (min 12 chars)
  2. Add entries β€” Store passwords, usernames, URLs, notes
  3. Generate passwords β€” Use the built-in generator with configurable options
  4. Organize β€” Use categories, tags, and favorites
  5. Sync (optional) β€” Set up your sync server to sync across devices

Project Structure

vaultkeeper/
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ components/
β”‚   β”‚   β”œβ”€β”€ LockScreen.tsx
β”‚   β”‚   β”œβ”€β”€ SetupScreen.tsx
β”‚   β”‚   β”œβ”€β”€ Sidebar.tsx
β”‚   β”‚   β”œβ”€β”€ EntryList.tsx
β”‚   β”‚   β”œβ”€β”€ EntryDetail.tsx
β”‚   β”‚   β”œβ”€β”€ EntryForm.tsx
β”‚   β”‚   β”œβ”€β”€ SyncSettings.tsx
β”‚   β”‚   └── SearchBar.tsx
β”‚   β”œβ”€β”€ crypto.ts          # Web Crypto API wrapper
β”‚   β”œβ”€β”€ vault.ts           # Vault management class
β”‚   β”œβ”€β”€ sync.ts            # Sync client
β”‚   β”œβ”€β”€ passwordGenerator.ts
β”‚   β”œβ”€β”€ types.ts
β”‚   β”œβ”€β”€ App.tsx
β”‚   β”œβ”€β”€ main.tsx
β”‚   └── index.css
β”œβ”€β”€ server/
β”‚   β”œβ”€β”€ index.ts           # Express sync server
β”‚   └── tsconfig.json
β”œβ”€β”€ tests/
β”‚   └── passwordGenerator.test.ts
β”œβ”€β”€ Dockerfile
β”œβ”€β”€ docker-compose.yml
β”œβ”€β”€ nginx.conf
└── package.json

Development

npm install
npm run dev          # Start frontend dev server
npm run dev:server   # Start sync server
npm test             # Run tests
npm run typecheck    # Type checking
npm run lint         # Lint
npm run build        # Build for production

License

MIT