Zeyad-101/Keypeer

Local-first password manager browser extension. AES-256-GCM + Argon2id, zero backend, zero network calls. React/Vite popup, autofill and save-prompt via content scripts.

β˜… 0Forks 0TypeScriptGitHub β†—Compare
aes-gcmautofillbrowser-extensionchrome-extensionencryptionmanifest-v3passwordpassword-managerpassword-securityprivacyreactsecuritytypescriptvite

README

manifest v3 AES-256-GCM Argon2id MIT license

πŸ”‘ Keypeer

A local-first password manager that lives in your browser.

No servers. No accounts. No sync you didn't ask for. Your vault stays on your machine, encrypted with your master password.


πŸ›‘οΈ Why this exists

Most password managers ask you to trust a company's server with your credentials. Keypeer doesn't have a server. Everything is encrypted and stored in chrome.storage.local β€” if it's not on your device, it doesn't exist.

⚑ What it does

  • πŸ” Encrypts everything at rest β€” AES-256-GCM per entry, master key derived with Argon2id and held in memory only
  • πŸ–±οΈ Autofills login forms β€” detects username/password fields on any page and offers a one-click fill
  • πŸ’Ύ Prompts to save new logins β€” catches credentials on submit, asks before storing
  • ✏️ Full CRUD β€” add, edit, delete, and search entries from a popup UI
  • ⏱️ Auto-locks β€” configurable idle timeout clears the key from memory
  • πŸ“¦ Encrypted export/import β€” back up your vault as a file without ever decrypting it outside the extension

🧩 Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  Content Script  │◄────►│  Background Worker    │◄────►│  chrome.storage  β”‚
β”‚  (per tab)       β”‚      β”‚  (holds key in memory) β”‚      β”‚  .local          β”‚
β”‚                  β”‚      β”‚                        β”‚      β”‚  (encrypted)     β”‚
β”‚ β€’ form detection β”‚      β”‚ β€’ Argon2id KDF         β”‚      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ β€’ autofill icon  β”‚      β”‚ β€’ AES-GCM encrypt/     β”‚
β”‚ β€’ save prompt    β”‚      β”‚   decrypt              β”‚      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β”‚ β€’ auto-lock timer      │◄────►│  Popup / Options β”‚
                          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β”‚  (React + Vite)   β”‚
                                                          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The master key never touches disk. Lock the vault, close the browser, or let the idle timer run out, and the key is gone until you unlock again.

πŸ› οΈ Stack

Layer Choice
Extension Manifest V3
UI React 18 + Vite + Tailwind CSS
Crypto Argon2id (KDF) + AES-256-GCM (Web Crypto API)
Storage chrome.storage.local, no backend
Targets Chrome, Edge, Brave

πŸ“‚ Project structure

keypeer/
β”œβ”€β”€ manifest.json
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ background/     # service worker, session, vault controller
β”‚   β”œβ”€β”€ crypto/         # Argon2id KDF, AES-GCM helpers
β”‚   β”œβ”€β”€ storage/         # schema + chrome.storage wrapper
β”‚   β”œβ”€β”€ content/         # form detection, autofill, save prompt
β”‚   β”œβ”€β”€ messaging/       # typed background <-> UI message contracts
β”‚   β”œβ”€β”€ popup/           # unlock, vault list, entry detail screens
β”‚   β”œβ”€β”€ options/         # settings, backup/restore
β”‚   └── shared/          # components and hooks shared across UI
└── tests/               # crypto, storage, and form-detection tests

πŸš€ Getting started

git clone <repo-url>
cd keypeer
npm install
npm run build

Then load it as an unpacked extension:

  1. Open chrome://extensions
  2. Enable Developer mode
  3. Click Load unpacked and select the dist/ folder

πŸ”’ Security notes

  • Master password is never stored β€” only its Argon2id-derived key exists, in memory, until lock
  • Each entry has its own random IV; no two encrypted blobs look alike even for identical passwords
  • Changing your master password re-encrypts every entry with the new key
  • No network requests. Full stop.

If you find a security issue, please don't open a public issue β€” reach out privately first.

πŸ—ΊοΈ Status

Actively in development. Core crypto, storage, and the popup UI are built first; autofill and the save-prompt flow come after the vault itself is solid. See the implementation plan for the full task breakdown.

πŸ“„ License

MIT β€” do what you want with it, just don't blame me if you lose your own vault file.


Built by Zeyad Waled

Contributors

Zeyad-101

Issues