Your device is the source.
Read from your encrypted local replica, even offline. Keep logins, notes, cards, identities, and TOTP codes close at hand.
Meet your local vault (opens in a new tab)Local-first credential vault
An end-to-end encrypted home for your credentials. Use them in your apps and AI agents, without handing the keys to a server.
git clone https://github.com/chr33s/vault.git
Source availableBuilt in SwiftYours to self-host
.env — example configuration
# Commit references. Not credentials.
DATABASE_URL=vault://personal/database
API_TOKEN=vault://personal/service
NODE_ENV=development
Resolve locally. Run normally.
vault run --env .env -- ./server
↳ Secrets passed to your process.
policy.env — example configuration
# The agent gets access. Not the key.
UPSTREAM=https://api.anthropic.com
x-api-key=vault://personal/anthropic
# Credentials injected on egress.
Use a secret. Without seeing it.
vault proxy --config policy.env -- claude
↳ Key attached to the allowed upstream.
Your workflow gets the secrets. Your repo doesn’t.
Less trust. More control.
Keep credentials close and infrastructure at arm’s length.
Your relay doesn’t
need to read what it helps you sync.
Read from your encrypted local replica, even offline. Keep logins, notes, cards, identities, and TOTP codes close at hand.
Meet your local vault (opens in a new tab)Send ciphertext through a zero-knowledge relay, or sync directly over your tailnet. Enroll devices and share access with signed grants.
Connect your devices (opens in a new tab)
Pass secrets to your apps with vault run. Use
vault proxy to attach credentials to allowed agent
requests, outside the agent itself.
The relay stores ciphertext and signed metadata, not plaintext credentials. Self-host it, or use the Cloudflare Worker relay.
Make yourself at home
Build the CLI from source, initialize a vault, and take it from there. No hosted account to create.
Read the setup guide (opens in a new tab)Requires Swift 6. macOS arm64 is locally verified; Linux and Windows support is not yet verified locally.
# Get the source and build
git clone https://github.com/chr33s/vault.git
cd vault/swift
swift build -c release
export PATH="$PWD/.build/release:$PATH"
# Create your first encrypted vault
vault init