Web · TypeScript
Secure Vault
A self-hosted password manager and TOTP (2FA) authenticator. All encryption happens in the browser; the server never sees the master password or unencrypted vault data.
-
Secure Vault
TypeScript
yrambler2001/vault
Password manager and authenticator with a React 19 + Vite frontend and a Node.js + Express backend, designed for single-user self-hosted deployment.
- Zero-knowledge: AES-256-GCM encryption strictly client-side, Argon2id key derivation
- Unlock with device biometrics or security keys through the WebAuthn PRF extension
- Built-in TOTP authenticator: QR code scanning, image import or manual entry
- Nested folders, custom fields, password generator, light and dark themes
- Automatic offline replication of the encrypted vault to several USB drives (RAID-1)
- Hardened backend: rate limiting, CSRF tokens, strict CSP, httpOnly SameSite=Strict cookies