Web · TypeScript

Secure Vault

A self-hosted password manager and TOTP (2FA) authenticator. All encryption happens in the browser; the server never sees the master password or unencrypted vault data.

  1. Secure Vault

    TypeScript

    yrambler2001/vault

    Password manager and authenticator with a React 19 + Vite frontend and a Node.js + Express backend, designed for single-user self-hosted deployment.

    • Zero-knowledge: AES-256-GCM encryption strictly client-side, Argon2id key derivation
    • Unlock with device biometrics or security keys through the WebAuthn PRF extension
    • Built-in TOTP authenticator: QR code scanning, image import or manual entry
    • Nested folders, custom fields, password generator, light and dark themes
    • Automatic offline replication of the encrypted vault to several USB drives (RAID-1)
    • Hardened backend: rate limiting, CSRF tokens, strict CSP, httpOnly SameSite=Strict cookies