A local-first password manager that lives in your browser.
No servers. No accounts. No sync you didn't ask for. Your vault stays on your machine, encrypted with your master password.
Most password managers ask you to trust a company's server with your credentials. Keypeer doesn't have a server. Everything is encrypted and stored in chrome.storage.local β if it's not on your device, it doesn't exist.
- π Encrypts everything at rest β AES-256-GCM per entry, master key derived with Argon2id and held in memory only
- π±οΈ Autofills login forms β detects username/password fields on any page and offers a one-click fill
- πΎ Prompts to save new logins β catches credentials on submit, asks before storing
- βοΈ Full CRUD β add, edit, delete, and search entries from a popup UI
- β±οΈ Auto-locks β configurable idle timeout clears the key from memory
- π¦ Encrypted export/import β back up your vault as a file without ever decrypting it outside the extension
βββββββββββββββββββ ββββββββββββββββββββββββ βββββββββββββββββββ
β Content Script βββββββΊβ Background Worker βββββββΊβ chrome.storage β
β (per tab) β β (holds key in memory) β β .local β
β β β β β (encrypted) β
β β’ form detection β β β’ Argon2id KDF β βββββββββββββββββββ
β β’ autofill icon β β β’ AES-GCM encrypt/ β
β β’ save prompt β β decrypt β βββββββββββββββββββ
βββββββββββββββββββ β β’ auto-lock timer βββββββΊβ Popup / Options β
ββββββββββββββββββββββββ β (React + Vite) β
βββββββββββββββββββ
The master key never touches disk. Lock the vault, close the browser, or let the idle timer run out, and the key is gone until you unlock again.
| Layer | Choice |
|---|---|
| Extension | Manifest V3 |
| UI | React 18 + Vite + Tailwind CSS |
| Crypto | Argon2id (KDF) + AES-256-GCM (Web Crypto API) |
| Storage | chrome.storage.local, no backend |
| Targets | Chrome, Edge, Brave |
keypeer/
βββ manifest.json
βββ src/
β βββ background/ # service worker, session, vault controller
β βββ crypto/ # Argon2id KDF, AES-GCM helpers
β βββ storage/ # schema + chrome.storage wrapper
β βββ content/ # form detection, autofill, save prompt
β βββ messaging/ # typed background <-> UI message contracts
β βββ popup/ # unlock, vault list, entry detail screens
β βββ options/ # settings, backup/restore
β βββ shared/ # components and hooks shared across UI
βββ tests/ # crypto, storage, and form-detection tests
git clone <repo-url>
cd keypeer
npm install
npm run buildThen load it as an unpacked extension:
- Open
chrome://extensions - Enable Developer mode
- Click Load unpacked and select the
dist/folder
- Master password is never stored β only its Argon2id-derived key exists, in memory, until lock
- Each entry has its own random IV; no two encrypted blobs look alike even for identical passwords
- Changing your master password re-encrypts every entry with the new key
- No network requests. Full stop.
If you find a security issue, please don't open a public issue β reach out privately first.
Actively in development. Core crypto, storage, and the popup UI are built first; autofill and the save-prompt flow come after the vault itself is solid. See the implementation plan for the full task breakdown.
MIT β do what you want with it, just don't blame me if you lose your own vault file.