A local, encrypted password manager. Your vault lives on your device, under keys only you can produce.

No cloud. No accounts. No servers. Open source and free.

Overview

Most password managers keep your vault on their servers. That makes their servers a target, and your passwords are only as safe as someone else's infrastructure.

Valid Vault keeps everything on your own device, encrypted. There is no account to create and no company holding a copy, so there is nothing to breach, subpoena, or sell. When you want your vault on another device, you move it yourself, as ciphertext, over a QR code or an encrypted file.

It runs as a browser extension for Chromium browsers, with an Android app built from the same code. Logins, personal details, private notes, crypto wallet seed phrases, and bookmarks all live in one encrypted vault.

Core Features

Password Generator
New password fields get an inverted V. One click fills both the new and confirm boxes with a random password that follows the site's rules. Length ranges from 16 up to 64, set in Settings.
Click-to-Fill Autofill
Login, password, and personal info fields get a small V tag. Click it and pick what to fill. Nothing is ever filled without your click.
Fingerprint Unlock
Windows Hello fingerprint or device PIN on the extension, hardware-backed biometrics on Android, with your master password as the fallback.
Previous Password Safety Net
Change a password and the old one is kept as a labeled backup with one-click restore, in case the site never took the change.
Save As You Go
Sign up or log in and Valid Vault offers to save it, even through sign-in redirects and multi-step login flows.
Personal Info
Name, phone, address, and ranked emails, filled into signup and address forms from one encrypted profile.
Crypto Wallets
Seed phrases by wallet and account, checked word by word against the standard 2048-word list, fully offline. Words only show while you choose to show them.
Encrypted Bookmarks
Save a page from the popup and find it in a searchable side panel. Unlike browser bookmarks, nothing about them is readable at rest.
Misc Credentials
Wi-Fi passwords, license keys, and other secrets, organized by category.
Auto-Lock
Locks itself after the idle time you choose, from 10 seconds to 2 hours. Only real mouse, scroll, click, and key activity keeps it open.

How it Works

One random 256-bit master key encrypts your vault. That key is never stored as is. It is wrapped separately under each unlock method you set up: your password (PBKDF2-SHA256 at 600,000 iterations), your fingerprint or device PIN, and on Android a hardware-backed Keystore key.

Unlocking is the act of unwrapping. A wrong password simply fails to open the key, because the AES-GCM authentication tag is the only check. There is no password hash stored anywhere for an attacker to test guesses against.

Sealed at rest

Kept away from web pages

Valid Vault makes no network requests. Every script ships inside the extension, with no remote code, no analytics, and no tracking.

Moving Between Your Devices

There is no sync server. You carry your vault from one device to another yourself, and it travels as ciphertext the whole way.

  1. Share the key once. The first device shows your master key as a QR code, wrapped under a passphrase and three security questions you choose, stretched with 1,000,000 PBKDF2 rounds.
  2. Unlock it on the new device. The receiving device scans it and must enter the passphrase and all three answers before the key can be used.
  3. Share the vault. Share Vault streams your encrypted vault as an animated QR code, or Export Vault saves it as a file.
  4. Merge. The receiving device merges by timestamp. The newest edit wins, and deletes carry across.

A photographed vault QR is ciphertext. A photographed key QR is useless without the passphrase and answers. A stolen key file is inert on its own.

Current Status

v0.7.2
VERSION
AES-256
GCM ENCRYPTION
0
SERVERS
Beta
ACTIVE TESTING

The browser extension carries the full feature set. The Android app is being brought up to match it in the next releases.

The Mission

Your passwords should belong to you. Valid Vault keeps them with you.

A cloud password manager asks you to trust a company, its servers, its staff, and every future owner of its business. Valid Vault removes that trust from the picture entirely.

Into the Future

Every release keeps the same rule: your data stays encrypted on your devices, and nothing about new features changes how it is protected.

Install

Chrome Web Store: listing coming soon.

From a release: works today in Chrome, Brave, Edge, and other Chromium browsers.

  1. Download the latest release from GitHub and unzip it.
  2. Open your browser's extensions page (chrome://extensions) and turn on Developer mode.
  3. Load unpacked and choose the extension folder.
  4. Open the popup and set a master password to create your vault.

Build from source

# Clone and build the web bundle
git clone https://github.com/HiImRook/valid-vault-password-manager.git
cd valid-vault-password-manager
node build.js

# Android (optional)
npm install
npx cap sync
npx cap open android
Beta: Valid Vault is under active testing. Keep an Export Vault backup and your key file somewhere safe. A lost master key, passphrase, and answers cannot be recovered by anyone.