Skip to content

About

A local, master-password-encrypted CLI password vault. No cloud, no server.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

Password Vault

Tests

A local, master-password-encrypted CLI password vault. No cloud, no server, no account — just a single encrypted file on your own disk.

How it works

  • Your master password is never stored. A 256-bit key is derived from it with PBKDF2-HMAC-SHA256 (600,000 iterations, a random salt per vault) — the OWASP-recommended minimum as of 2023.
  • All entries (usernames, passwords, URLs, notes) are encrypted together with Fernet (AES-128-CBC + HMAC) from Python's cryptography library.
  • The vault file never contains plaintext secrets — only a salt, an iteration count, and ciphertext.
  • Nothing leaves your machine. There is no network code in this project.

This is a personal/learning-grade vault, not an audited product — good for understanding how password managers work and for personal use, but weigh that against a mature tool (Bitwarden, 1Password, KeePass) for anything critical.

Installation

git clone https://github.com/SafraNako/password-vault.git
cd password-vault
pip install -e .

Usage

# Create a new vault (prompts for a master password, twice to confirm)
pwvault init ~/.vault.json

# Add an entry with a password you type yourself
pwvault add ~/.vault.json github --username octocat --url github.com

# ...or let the vault generate a strong one for you
pwvault add ~/.vault.json aws --username me@example.com --generate --length 24

# List entry names (passwords are never shown here)
pwvault list ~/.vault.json

# Reveal a single entry, including its password
pwvault get ~/.vault.json github

# Delete an entry
pwvault remove ~/.vault.json github

# Re-encrypt the whole vault under a new master password
pwvault change-master ~/.vault.json

# Generate a password without touching any vault
pwvault generate --length 24 --count 3

Every command that touches the vault prompts for your master password interactively (hidden input, never echoed). For scripting, you can set PWVAULT_MASTER_PASSWORD in the environment instead — only do this in contexts where your shell environment isn't exposed to others.

Development

pip install -e ".[dev]"
pytest -v

License

MIT — see LICENSE.

About

A local, master-password-encrypted CLI password vault. No cloud, no server.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages