A local, master-password-encrypted CLI password vault. No cloud, no server, no account — just a single encrypted file on your own disk.
- Your master password is never stored. A 256-bit key is derived from it with PBKDF2-HMAC-SHA256 (600,000 iterations, a random salt per vault) — the OWASP-recommended minimum as of 2023.
- All entries (usernames, passwords, URLs, notes) are encrypted together with
Fernet (AES-128-CBC + HMAC) from Python's
cryptographylibrary. - The vault file never contains plaintext secrets — only a salt, an iteration count, and ciphertext.
- Nothing leaves your machine. There is no network code in this project.
This is a personal/learning-grade vault, not an audited product — good for understanding how password managers work and for personal use, but weigh that against a mature tool (Bitwarden, 1Password, KeePass) for anything critical.
git clone https://github.com/SafraNako/password-vault.git
cd password-vault
pip install -e .# Create a new vault (prompts for a master password, twice to confirm)
pwvault init ~/.vault.json
# Add an entry with a password you type yourself
pwvault add ~/.vault.json github --username octocat --url github.com
# ...or let the vault generate a strong one for you
pwvault add ~/.vault.json aws --username me@example.com --generate --length 24
# List entry names (passwords are never shown here)
pwvault list ~/.vault.json
# Reveal a single entry, including its password
pwvault get ~/.vault.json github
# Delete an entry
pwvault remove ~/.vault.json github
# Re-encrypt the whole vault under a new master password
pwvault change-master ~/.vault.json
# Generate a password without touching any vault
pwvault generate --length 24 --count 3Every command that touches the vault prompts for your master password
interactively (hidden input, never echoed). For scripting, you can set
PWVAULT_MASTER_PASSWORD in the environment instead — only do this in
contexts where your shell environment isn't exposed to others.
pip install -e ".[dev]"
pytest -vMIT — see LICENSE.