Local-first credential vault

Your secrets.On your terms.

An end-to-end encrypted home for your credentials. Use them in your apps and AI agents, without handing the keys to a server.

git clone https://github.com/chr33s/vault.git

Source availableBuilt in SwiftYours to self-host

A little less exposure.

.env — example configuration

# Commit references. Not credentials.
DATABASE_URL=vault://personal/database
API_TOKEN=vault://personal/service
NODE_ENV=development

Resolve locally. Run normally.

vault run --env .env -- ./server
↳ Secrets passed to your process.
Resolved values stay off disklocal replica

Your workflow gets the secrets. Your repo doesn’t.

Fits the way
you already work
CLI native .env friendly Agent ready Device to device

Less trust. More control.

Local first. Private by design.

Keep credentials close and infrastructure at arm’s length.
Your relay doesn’t need to read what it helps you sync.

Explore the architecture (opens in a new tab)
02 / SYNC

Sync without the trust.

Send ciphertext through a zero-knowledge relay, or sync directly over your tailnet. Enroll devices and share access with signed grants.

Connect your devices (opens in a new tab)

The relay never gets your vault keys.

The relay stores ciphertext and signed metadata, not plaintext credentials. Self-host it, or use the Cloudflare Worker relay.

Make yourself at home

Small setup.
Your own vault.

Build the CLI from source, initialize a vault, and take it from there. No hosted account to create.

Read the setup guide (opens in a new tab)

Requires Swift 6. macOS arm64 is locally verified; Linux and Windows support is not yet verified locally.

Build from source
# Get the source and build
git clone https://github.com/chr33s/vault.git
cd vault/swift
swift build -c release
export PATH="$PWD/.build/release:$PATH"

# Create your first encrypted vault
vault init
You’ll be prompted for a passphrase. Keep it somewhere safe.