OPEN SOURCE / HARDWARE-BACKED

Your secrets.
Under your control.

A password manager built around hardware security keys. No master password. No hidden trust. Just cryptography you can verify.

vaultkey — zsh
$ vaultkey init --hardware-key
Hardware key registered: YubiKey 5C NFC
Vault created and encrypted locally
0master passwords
256-bitencryption
100%open source
MITlicensed
01 / BUILT DIFFERENT

Security that starts
with hardware.

Vaultkey moves the root of trust off your laptop and into something you physically own. Your key never leaves the device.

Hardware security

Your encryption key is derived from a physical device you control.

Zero-knowledge

The server never sees your passwords. Only ciphertext leaves your machine.

Every interface

CLI, web UI, and browser extension — use Vaultkey wherever you work.

Modern crypto

ChaCha20-Poly1305 AEAD encryption keeps every secret sealed.

Cross-device sync

Sync an encrypted vault across devices without exposing the contents.

Open source

MIT licensed, auditable, and built in the open by security-minded people.

02 / GET STARTED

Up and running
in seconds.

Install the CLI, connect your hardware key, and create your first encrypted vault. No account required to begin.

terminal
$ git clone https://github.com/shuva-kharel/vaultkey.git
cd vaultkey

# Start the server
docker-compose up -d --build
Works on macOS, Linux, and Windows via WSL
03 / YOUR WAY

One vault.
Everywhere.

Use the interface that fits your workflow. The same encrypted vault, wherever you need it.

CLI
$ vaultkey listNAME UPDATEDgithub 2m agoaws-production 1h agopersonal-email 3d ago$ vaultkey get github✓ copied password to clipboard
WEB UI
My vault
⌕ Search your vault
GCode2github.com••••••••
AAWS Productionconsole.aws.amazon.com••••••••
EXTENSION
vaultkey
github.com/login
Protected by YubiKey
04 / THE MODEL

Trust is a
physical thing.

Your hardwareYubiKey / TPM / Passkey
derives key
Local encryptionChaCha20-Poly1305
syncs ciphertext
Encrypted vaultServer sees nothing
05 / QUESTIONS

Good security
means good answers.

Vaultkey supports multiple enrolled authenticators. Add a backup key, passkey, or TPM during setup so you always have a recovery path.

READY WHEN YOU ARE

Take back
your keys.

Open source. Hardware-backed. Yours.

Install Vaultkey