VaultKeeper
Local-First Password Manager with End-to-End Encryption and Optional Self-Hosted Sync
Features
- Local-first β All data stored encrypted in your browser's localStorage
- E2E encryption β AES-256-GCM with PBKDF2 key derivation (600,000 iterations)
- Zero-knowledge β The server never sees your plaintext data or master password
- Optional self-hosted sync β Sync across devices with your own server
- Password generator β Configurable length, character sets, passphrase mode
- Password strength meter β Real-time entropy calculation
- Categories & tags β Organize entries with categories and tags
- Favorites β Mark frequently used entries
- Search & filter β Full-text search across all fields
- Auto-lock β Vault locks after 15 minutes of inactivity
- Modern UI β Dark theme with TailwindCSS, Lucide icons
Security Architecture
Master Password
β
βΌ
PBKDF2 (600,000 iterations, SHA-256, 32-byte salt)
β
βΌ
AES-256-GCM Key (non-extractable)
β
ββββΊ Encrypt each vault entry (individual IV per entry)
ββββΊ Create verifier token (to validate password on unlock)
ββββΊ Never stored, never sent to server
- Key derivation: PBKDF2 with 600,000 iterations and SHA-256
- Encryption: AES-256-GCM (authenticated encryption)
- Key storage: CryptoKey objects are non-extractable (never serialized)
- Sync: Only encrypted vault data is sent to the server
- Server: Stores encrypted blobs, never has access to plaintext
Quick Start
Frontend (Web App)
npm install
npm run dev
Sync Server (Optional)
npm run dev:server
Server runs on http://localhost:3001
Docker
docker-compose up
Usage
- Create your vault β Choose a strong master password (min 12 chars)
- Add entries β Store passwords, usernames, URLs, notes
- Generate passwords β Use the built-in generator with configurable options
- Organize β Use categories, tags, and favorites
- Sync (optional) β Set up your sync server to sync across devices
Project Structure
vaultkeeper/
βββ src/
β βββ components/
β β βββ LockScreen.tsx
β β βββ SetupScreen.tsx
β β βββ Sidebar.tsx
β β βββ EntryList.tsx
β β βββ EntryDetail.tsx
β β βββ EntryForm.tsx
β β βββ SyncSettings.tsx
β β βββ SearchBar.tsx
β βββ crypto.ts # Web Crypto API wrapper
β βββ vault.ts # Vault management class
β βββ sync.ts # Sync client
β βββ passwordGenerator.ts
β βββ types.ts
β βββ App.tsx
β βββ main.tsx
β βββ index.css
βββ server/
β βββ index.ts # Express sync server
β βββ tsconfig.json
βββ tests/
β βββ passwordGenerator.test.ts
βββ Dockerfile
βββ docker-compose.yml
βββ nginx.conf
βββ package.json
Development
npm install
npm run dev # Start frontend dev server
npm run dev:server # Start sync server
npm test # Run tests
npm run typecheck # Type checking
npm run lint # Lint
npm run build # Build for production
License
MIT