Keep your passwords, passkeys and private notes in an encrypted vault on your own device. The core features work offline, and you don’t need a cloud account.
Your accounts and codes in one vault.Illustration with made-up data
01Works offline02Encrypted local storage03Optional device sync
Inside Vault
Your accounts and codes, right where you need them.
Sign in with Smart Login, tie your vault to a USB drive, and keep codes and strong passwords handy. Encrypted device pairing brings it to your phone.
Smart LoginAnimated walkthrough
Yntra Vault
All items4Search…
GitHubalex@example.com
Googlecasey@example.com
Proton Mailsam@example.com
Spotifyalex@example.com
GitHubhttps://github.com
Usernamealex@example.com
Password••••••••••••
URLhttps://github.com
Smart Login
From an unlocked vault
github.com/login
Sign in to GitHub
Username or email addressPasswordForgot password?Sign in
New to GitHub? Create an account
Choose Smart Login00:00 / 00:18
Smart Login
From your vault straight into your account.
Pick an account and start Smart Login. Vault finds a supported sign-in form, checks the website and puts your saved username and password in the right fields. The walkthrough shows a GitHub example with a saved authenticator code.
01
Start from your account.
Unlock Vault, select the entry and choose Smart Login. Confirm the browser setup if it asks.
02
Check the destination.
Vault checks the HTTPS destination and focused login field before sending credentials.
03
Fill in the right fields.
Your saved details follow the form. If Vault recognizes a two-factor step, it can use the current code from your saved authenticator.
04
Check the result.
Vault looks for signs that you’re signed in. If it can’t tell, the result stays unconfirmed.
CAPTCHAs, security-key prompts and extra approvals are up to you. Support for websites, browsers and operating systems depends on your setup.
The walkthroughs use made-up data. What works varies between websites, browsers and operating systems.
Tools inside Vault
Tools for every day and for the bad ones.
Move your accounts into Vault, keep them up to date, and have a plan for getting back in if you lose access.
01Passkeys & Smart Login
Use your saved sign-ins.
Start Smart Login from a saved entry. Vault opens the website, checks that it’s the right one and finds the sign-in fields before filling in your details. It can handle supported multi-step forms, and if it spots a compatible two-factor prompt, it can enter your saved authenticator code. Passkeys are a separate sign-in method that you confirm yourself.
02Security dashboard
Find passwords worth changing.
The local dashboard points out weak and reused passwords. Turn on Have I Been Pwned checks and Vault looks for known breaches using only a hash prefix. Your password itself isn’t sent.
03History & trash
Go back to an earlier password.
See a password’s history and restore an older one. Deleted entries stay in the trash until you remove them for good.
04Import, backup & recovery
Plan for losing access.
Import your existing logins and export encrypted backups. Set up an emergency kit or split recovery shares, and keep them somewhere other than the vault.
05Optional synchronization
Your vault on both devices.
Move your vault from your computer to your phone over the same Wi-Fi. Scan a temporary QR code and the vault is sent encrypted, then saved locally on the phone. Once they’re paired, P2P sync keeps your entries up to date without a cloud account.
06Developer tools
Use Vault from your terminal.
Use the vault from the CLI or the terminal interface. There’s also secret injection, Git credential integration and an SSH agent. The documentation explains how to set them up.
How Vault protects your data
Several layers of protection.
Vault encrypts the local file and uses separate keys for separate jobs. Auto-lock, an optional key file and clipboard clearing help while you’re using it.
01 / Argon2id
Guessing gets slow and expensive.
Argon2id turns your master password into a key using a memory-heavy calculation. That makes guessing passwords against a stolen vault file more expensive.
02 / HKDF-SHA512
One key per job.
HKDF-SHA512 derives separate keys for the vault, its entries, integrity checks and search. Every entry also gets its own encryption key.
03 / XChaCha20-Poly1305
Encrypted and authenticated.
XChaCha20-Poly1305 encrypts the vault and its entries. Its authentication checks reject encrypted data that’s been modified.
Lock when you step away.
Set a timeout and the vault locks when you’re inactive. On supported platforms, Vault also watches for workstation locking and whether a removable vault is still there.
Add your own key file.
Use an optional key file together with your master password. Back it up separately. If you lose a required key file, you may not be able to open the vault.
Copied secrets don’t linger.
Sensitive clipboard copies can be cleared automatically. Key cleanup and platform-specific memory protection reduce exposure while Vault is in use.
Open to scrutiny
Read how it works.
The source code, threat model and disclosure policy are public. Vault is still in active development and hasn’t had an independent third-party security audit yet.
No. The encrypted vault stays on your device and the core features work offline. Optional sync and breach checks need a network connection.
Can I bring my existing passwords?
Yes. Vault has import tools and encrypted backups. Check the current documentation for supported formats, and make a separate backup before moving anything important.
What about signing in and passkeys?
Smart Login starts from an unlocked vault and a saved HTTPS website. It checks the destination and the focused field before filling in or submitting anything. Regular Chromium forms go through the browser integration; Google sign-in on Windows uses the native browser flow. CAPTCHAs, security-key prompts, unknown challenges and extra approvals are up to you, and browser setup may ask you to confirm. See the current release documentation for compatibility. The animation shows a supported GitHub flow, not a live account.
What if someone obtains a copy of the vault file?
The USB binding stays with the encrypted file, even if it’s renamed or copied to another computer. The password isn’t enough: normal unlocking also needs the bound device’s identifier and any key file you’ve set up. That identifier is public and can be spoofed by someone who gets hold of it. Two valid recovery shares are a separate way back in.
What if I lose the bound USB device?
Recovery v2 gives you three shares. Any two different shares from the same active kit can recover the existing local vault file. Store them separately and keep a separate file backup, since recovery can’t bring back a deleted vault. Recovering sets a new password and removes the USB requirement, so afterwards you’ll want to set up a new kit and enroll your device again. USB enrollment currently only works on Windows. It relies on a public device identifier, not a hardware secret that can’t be exported.
Has Vault had an independent security audit?
No, not yet. Vault is in active development and available for evaluation and community review. The security policy covers scope and how to report vulnerabilities.
Explore the project
Have a look.
Read the documentation and release notes before you install. They cover supported platforms, setup and what changed in each version.