โ ๐ Keyper - Self-Hosted Credential Management
โจ Your Credentials. Your Security. Your Rules. โจ
A modern, secure, self-hosted credential management application for storing and organizing your digital credentials with complete privacy and control.
โ ๐ Features
โ ๐ Secure Credential Storage
๐ API Keys - Store and organize your API credentials
๐ Login Credentials - Username/password combinations
๐คซ Secrets - Sensitive configuration values
๐ซ Tokens - Authentication and access tokens
๐ Certificates - SSL certificates and keys
๐ Documents - Secure file uploads for .pdf, .doc, .docx, .odt, .txt, .md
๐งฉ Miscellaneous - Large multiline secure notes/commands/scripts that donโt fit fixed types
โ ๐ท๏ธ Smart Organization
๐ Categories - Group credentials by service or type
๐ Tags - Flexible labeling system
โก Priority Levels - Low, Medium, High, Critical
๐
Expiration Tracking - Never miss renewal dates
๐ Real-time Search - Find credentials instantly
๐๏ธ Quick Reveal & Copy - Reveal and copy sensitive values directly from the credential detail view
๐๏ธ Inline Text Document Preview - Text-like document credentials (.txt, .md, text/*) can be previewed inline in credential detail view
โฌ๏ธ Secure Document Download - All document credentials can be downloaded from detail view
โ ๐ก๏ธ Enterprise-Grade Security
๐ Row Level Security (RLS) - Database-level isolation
๐ End-to-End Encryption - Client-side encryption, zero-knowledge architecture
๐ค Multi-User Support - Self-service registration, account switching, and per-user vault isolation
๐ Secure Connections - HTTPS/TLS encryption
๐ Self-Hosted - Complete control over your data
โ ๐ Advanced Encryption Features
Zero-Knowledge Architecture - All encryption happens client-side
AES-256-GCM Encryption - Industry-standard authenticated encryption
Argon2id Key Derivation - Memory-hard, ASIC-resistant (with PBKDF2 fallback)
Auto-Lock Protection - 15-minute inactivity timeout with activity detection
Simplified Bcrypt Master Passphrase - Secure bcrypt-only authentication for new users
Backwards Compatibility - Legacy wrapped DEK system maintained for existing users
User-Controlled Reset - Secure emergency passphrase reset without admin backdoors
Database-Only Storage - No localStorage usage except for database config
Professional Security Audit - EXCELLENT security rating
โ ๐ Try the Demo
Want to try Keyper before installing? Visit our hosted demo:
๐ app.keyper.icu โ
Just enter your own Supabase credentials and start managing your encrypted credentials instantly! Your data stays completely private since all encryption happens in your browser.
Demo Usage:
โ
Completely Secure - Zero-knowledge architecture means your data never leaves your browser
โ
Real Functionality - Full Keyper experience with your own Supabase instance
โ
No External Signup Required - Just bring your Supabase URL and anon/publishable key
โ
In-App User Registration Available - Create multiple isolated user vaults directly inside Keyper
โ ๏ธ Demo Limitations - Recommended for testing and light usage only
๐ Self-Host for Production - Install locally for best performance and full control
Note: The demo uses the same secure architecture as self-hosted Keyper. Your Supabase credentials are stored only in your browser's localStorage and never transmitted to our servers.
โ ๐๏ธ Database Setup
Keyper supports two database backends โ choose the one that fits your workflow:
Feature SQLite (Local) Supabase (Cloud) Setup required None โ auto-configured Project creation + SQL script Internet connection โ Not required โ
Required Multi-device sync โ Not supported โ
Supported Works in browser/PWA โ
Yes โ
Yes Works in Electron desktop โ
Yes โ
Yes Data location Your device (IndexedDB in browser/PWA, optional file path in Electron) Your Supabase project
โ Option A: SQLite (Local โ Zero Config)
Start Keyper and open the app in your browser, PWA, or Electron desktop build
In the setup wizard, select "SQLite (Local)" as your database provider
Master Passphrase : Create your encryption passphrase
Start Managing : Add your first encrypted credential! ๐
SQLite mode stores your encrypted vault locally with no external service required. In browser/PWA mode it uses IndexedDB automatically; in Electron you can also point Keyper at a SQLite file on disk.
โ Option B: Supabase (Hosted Cloud)
โ Step 1: Create Your Supabase Project
Visit supabase.comโ and sign up/login
Click "New Project"
Configure your project:
Name : keyper-db (or your preference)
Database Password : Generate a strong password
Region : Choose closest to your location
Wait 1-2 minutes for setup completion
โ Step 2: Get Your Credentials
In Supabase dashboard: Settings โ API
Copy these values:
Project URL : https://your-project.supabase.co
anon/public key : eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
โ ๏ธ Important : Use the anon/public key, NOT the service_role key!
โ Step 3: Configure Keyper
Start Keyper: keyper
Open http://localhost:4173โ
Database Setup : Configure your Supabase connection
Enter your Supabase URL and anon/publishable key
Copy and run the complete SQL setup script in Supabase SQL Editor
If you already have an existing Keyper database, run the update script too (migration-add-document-misc-types.sql) so document and misc credential types work
The script creates tables with the latest security features:
raw_dek and bcrypt_hash columns for the new simplified security model
Backwards compatibility for existing users with legacy wrapped_dek system
Latest credential type support (api_key, login, secret, token, certificate, document, misc)
Test the connection
Master Passphrase : Create your encryption passphrase
Choose a strong passphrase (8+ characters recommended)
New users get the simplified bcrypt-only authentication system
This encrypts all your credentials client-side with secure emergency reset capabilities
Start Managing : Add your first encrypted credential! ๐
โ ๐ฑ Mobile Installation
Open Keyper in your mobile browser
Tap the browser menu (โฎ)
Select "Add to Home Screen" or "Install App"
Access from your home screen
โ โจ PWA Benefits
๐ฑ Native app experience
๐ Faster loading times
๐ Offline functionality
๐ Background updates
๐ฒ Push notifications (coming soon)
โ ๐ง Troubleshooting
โ Common Issues
โ "Connection failed: Database connection failed"
Verify URL format - now supports any valid HTTP/HTTPS URL (v1.0.6+)
โ
Cloud: https://your-project.supabase.co
โ
Local: http://localhost:54321, http://192.168.1.100:8000
โ
Custom: https://supabase.mydomain.com
Use anon/public key, not service_role
Check that your Supabase project is active
โ "relation 'credentials' does not exist"
Run the complete SQL setup script in Supabase SQL Editor
Ensure the script completed without errors
โ New document or misc credentials fail to save
Run the existing-database update script: migration-add-document-misc-types.sql
Confirm credentials_credential_type_check includes document and misc
โ Dashboard shows "No credentials found"
Click "Refresh App" button
Clear browser cache and reload
For PWA: Uninstall and reinstall the app
โ Can't enter new credentials after clearing configuration
Refresh the page after clearing configuration
Ensure you're using a valid HTTP/HTTPS URL (any format supported in v1.0.6+)
Try clearing browser cache if form inputs appear stuck
โ Categories dropdown is empty when using custom username
This issue has been resolved in the latest version
Categories should now appear for all usernames (both default and custom)
If still experiencing issues, try refreshing the page after setting your username
โ App doesn't show setup wizard after clearing database
Clear browser cache and cookies for the site
For Chrome/Edge: Settings โ Privacy โ Clear browsing data โ Cookies and cached files
For Firefox: Settings โ Privacy โ Clear Data โ Cookies and Site Data + Cached Web Content
Refresh the page to see the initial setup screen
โ Stuck in configuration loops or can't access settings
Clear browser cache and localStorage completely
Refresh the page and reconfigure your database connection
Ensure your Supabase credentials are correct
Use the built-in database health checks to verify table integrity
โ Multi-user vault conflicts
Each user has their own isolated encrypted vault
Use Dashboard Settings โ User Management to switch users
Use Create New User from the lock screen or Add New User in user management
Refresh after user-switch actions if prompted for the cleanest vault context handoff
Each user's data is completely separate and encrypted individually
โ ๐ Master Passphrase Reset
Forgot your master passphrase? No problem! Your encrypted data is completely safe and you can securely reset your passphrase:
Important : It's not possible to view your current master passphrase, but you can update/change it using our secure bcrypt-based reset system.
๐ Complete Reset Guide : For detailed step-by-step instructions, see our comprehensive Emergency Passphrase Reset Guideโ
Quick Overview:
For Supabase users:
Access your Supabase dashboard and navigate to the vault_config table
Generate a new bcrypt hash using your desired new passphrase
Replace the bcrypt_hash value in your database
Login with your new passphrase
For SQLite (local) users:
Open your browser's DevTools โ Application โ IndexedDB โ find the Keyper database
Alternatively, use the in-app Settings โ Reset tab for guided instructions
Generate a new bcrypt hash using your desired new passphrase
Replace the bcrypt_hash value in the vault_config table and reload
Security Benefits:
โ
No Backdoors : Complete elimination of admin override capabilities
โ
User Control : Only you can reset your own passphrase
โ
Data Safety : Your encrypted credentials remain completely safe
โ
Industry Standard : Uses proven bcrypt hashing technology
โ
Zero Knowledge : Hash-only storage ensures maximum security
โ Getting Help
Check the Self-Hosting Guideโ
Review browser console for errors (F12 โ Console)
Verify your database provider logs (Supabase dashboard โ Logs, or browser DevTools โ Console for SQLite errors)
Use the master passphrase reset process above for password issues
Report issues on GitHubโ
โ ๐ก๏ธ Security & Privacy
โ Your Data, Your Control
โ
Self-Hosted - Run on your own infrastructure
โ
Private Database - Your Supabase instance or local SQLite storage
โ
No Tracking - Zero telemetry or analytics
โ
Open Source - Fully auditable code
โ Security Features
๐ Row Level Security - Database-level access control
๐ Encryption - Data encrypted at rest and in transit
๐ค User Isolation - Each user sees only their data
๐ก๏ธ Offline-First Option - SQLite mode requires no internet and stores data entirely on-device
โ Multi-User Notes
Registration : Users can self-register from the lock screen via Create New User ; no admin account is required.
User Management : Dashboard includes a User Management area that lists registered users and supports secure switching.
Isolation : Every username has its own vault_config, passphrase verifier, encryption key material, credentials, and categories.
No Backdoors : Switching users never bypasses passphrase verification, and there is no admin recovery path.
Reset Model : Emergency passphrase reset remains self-service per user via that userโs bcrypt_hash record.
โ ๐ Tech Stack
Frontend : React 19.1 + TypeScript
Build Tool : Vite 7.0
Styling : Tailwind CSS + shadcn/ui
Database : Supabase (PostgreSQL + Auth) or SQLite (sql.js / IndexedDB)
State Management : TanStack Query
Forms : React Hook Form + Zod
PWA : Vite PWA Plugin + Workbox
โ ๐ License
This project is licensed under the Apache License 2.0 - see the LICENSEโ file for details.
โ Made with ๐
Created by Pink Pixel โจ
Dream it, Pixel it
โญ Star this repo if Keyper helps secure your digital life! โญ