Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PwdPie logo

PwdPie

A local, offline-first password & secrets manager for desktop.
Electron + vanilla JS, AES-256-GCM, single encrypted file, no cloud.


Features

  • Typed entries — logins, API keys, servers (SSH), databases, crypto wallets (seed phrases), secure notes; each type has its own fields
  • One-click copy chips — the most important fields of every entry (password, host, address…) are copied straight from the list; secret values never touch the DOM
  • Password generator — uniform (bias-free) sampling, guarantees at least one character from every selected class
  • Search — across titles, notes and all non-secret fields
  • Seed phrase grid — wallet seed phrases are revealed as a numbered word grid
  • Service icons (opt-in) — favicons resolved by entry domain, cached locally for 7 days; disabled by default, see Privacy
  • Light / dark theme, keyboard navigation, focus traps, reduced-motion support

Security model

  • The vault is a single encrypted file (vault.enc) stored in the OS user-data directory — it never leaves your machine
  • AES-256-GCM authenticated encryption; a random salt per vault, a random IV per write
  • Key derived from the master password with PBKDF2-SHA512, 600,000 iterations; the iteration count is stored in an authenticated (AAD) file header, so parameters can be raised over time and tampering with them is detected
  • Vaults created by older versions (100k iterations, headerless format) are transparently upgraded on the next successful unlock
  • Crash-safe writes: write to a temp file → fsync → atomic rename; the previous vault version is kept as vault.enc.bak
  • The master password is never stored; the derived key is dropped from memory on lock
  • Renderer hardening: contextIsolation: true, nodeIntegration: false, strict CSP; external links open only via the system browser (shell.openExternal), http(s) only

Privacy

PwdPie makes no network requests by default. The only optional network feature is service icons: when you explicitly enable it (globe button in the header), the app fetches favicons for the domains of your entries from public favicon services (DuckDuckGo, Google) and caches them locally. Secret values are never sent anywhere.

Disclaimer

This is a personal / hobby project. It has not been professionally audited. For high-stakes secrets, prefer an established, audited password manager (Bitwarden, KeePassXC, 1Password). Use at your own risk.

Getting started

npm install
npm start           # run in development

npm run build:mac   # package for macOS (dmg, zip)
npm run build:win   # Windows (nsis, portable)
npm run build:linux # Linux (AppImage, deb)

Where is my data?

OS Vault location
macOS ~/Library/Application Support/pwdpie/data/vault.enc
Windows %APPDATA%/pwdpie/data/vault.enc
Linux ~/.config/pwdpie/data/vault.enc

Back up this file (and remember your master password — there is no recovery).

Credits

  • UI sounds from Pixabay (Pixabay Content License)

License

MIT

About

Local offline-first password & secrets manager. Electron, AES-256-GCM, single encrypted vault, no cloud.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages