A local, offline-first password & secrets manager for desktop.
Electron + vanilla JS, AES-256-GCM, single encrypted file, no cloud.
- Typed entries — logins, API keys, servers (SSH), databases, crypto wallets (seed phrases), secure notes; each type has its own fields
- One-click copy chips — the most important fields of every entry (password, host, address…) are copied straight from the list; secret values never touch the DOM
- Password generator — uniform (bias-free) sampling, guarantees at least one character from every selected class
- Search — across titles, notes and all non-secret fields
- Seed phrase grid — wallet seed phrases are revealed as a numbered word grid
- Service icons (opt-in) — favicons resolved by entry domain, cached locally for 7 days; disabled by default, see Privacy
- Light / dark theme, keyboard navigation, focus traps, reduced-motion support
- The vault is a single encrypted file (
vault.enc) stored in the OS user-data directory — it never leaves your machine - AES-256-GCM authenticated encryption; a random salt per vault, a random IV per write
- Key derived from the master password with PBKDF2-SHA512, 600,000 iterations; the iteration count is stored in an authenticated (AAD) file header, so parameters can be raised over time and tampering with them is detected
- Vaults created by older versions (100k iterations, headerless format) are transparently upgraded on the next successful unlock
- Crash-safe writes: write to a temp file →
fsync→ atomic rename; the previous vault version is kept asvault.enc.bak - The master password is never stored; the derived key is dropped from memory on lock
- Renderer hardening:
contextIsolation: true,nodeIntegration: false, strict CSP; external links open only via the system browser (shell.openExternal),http(s)only
PwdPie makes no network requests by default. The only optional network feature is service icons: when you explicitly enable it (globe button in the header), the app fetches favicons for the domains of your entries from public favicon services (DuckDuckGo, Google) and caches them locally. Secret values are never sent anywhere.
This is a personal / hobby project. It has not been professionally audited. For high-stakes secrets, prefer an established, audited password manager (Bitwarden, KeePassXC, 1Password). Use at your own risk.
npm install
npm start # run in development
npm run build:mac # package for macOS (dmg, zip)
npm run build:win # Windows (nsis, portable)
npm run build:linux # Linux (AppImage, deb)| OS | Vault location |
|---|---|
| macOS | ~/Library/Application Support/pwdpie/data/vault.enc |
| Windows | %APPDATA%/pwdpie/data/vault.enc |
| Linux | ~/.config/pwdpie/data/vault.enc |
Back up this file (and remember your master password — there is no recovery).
- UI sounds from Pixabay (Pixabay Content License)
