Web/source update · September 21, 2026
The web app now includes additional lock and KDBX validation hardening. Existing
downloadable installers, CLI and developer-extension archives predate this update and
retain their listed release behavior. Rebuilt and platform-tested packages are pending.
Read the current change log.
Vault 0.3.3 · Native apps & downloads
Your private world.
Within reach.
Passwords, cards, nested pages, checklists and project boards. The 0.3 desktop and Android
builds include the workspace editor, alongside the web app and developer extensions.
Encrypted locally. Sync native devices over your private Wi-Fi, with approval from your main
device.
Built to be tested thoughtfully.
Preview software; no independent security audit. macOS and Windows installers are
unsigned. Android is a signed release APK for direct installation. iOS source is prepared;
its build and Apple distribution are pending. Start with sample data.
macOS · 0.3.3
macOS 13+. Open the DMG and drag Vault into Applications. Choose Apple silicon for
M-series Macs or Intel for Intel Macs. Your main device can approve and review Wi-Fi
sync. macOS may block unsigned apps; these are not notarized releases.
Apple silicon DMG publication pending.
The 0.3.3 installer is built. Direct downloads will open when distribution is available.
Intel DMG publication pending.
The 0.3.3 installer is built. Direct downloads will open when distribution is available.
Windows · 0.3.3
Windows 10+ on Intel or AMD x64. Run the EXE installer for a per-user installation.
Main-device hosting and local sync are included. Windows runtime validation and signing
remain pending.
Windows installer publication pending.
The 0.3.3 installer is built. Direct downloads will open when distribution is available.
Android · 0.3.3
Android 10+. Local vault, protected pairing credentials and approved Wi-Fi sync. Enable
a device screen lock before pairing. The APK installs directly on compatible ARM and x86
devices. Google Play publication is pending.
Android APK publication pending.
The 0.3.3 installer is built. Direct downloads will open when distribution is available.
iPhone & iPad
Native project prepared with Keychain storage, a privacy screen and Wi-Fi sync code.
Compilation, device testing and Apple signing are still pending.
App Store release pending.
No installable iOS release or TestFlight invitation is available yet. Installation
will use Apple’s distribution system.
Mobile store availability
Google Play and Apple App Store listings have not been submitted. Store buttons will
appear after publication. You can use the browser app today.
Open Vault in your browser ↗
For developers
These archives contain source or developer extensions. They are separate from the native
app installers above.
Native project source · 0.3.3
Desktop, Android and iOS project files. Requires development tools; this ZIP is not an
app installer.
Native source ZIP ↓
macOS & Windows CLI
Manage encrypted vault files from your terminal. Workspace pages are readable and
preserved; edit their blocks in the app. Node 22.16+ required. File import/export;
native Wi-Fi sync is not in the CLI.
CLI + source ↓
Browser extensions · 0.3.3
Local encryption and click-to-fill matching websites. Developer installation; no
native Wi-Fi bridge.
Chrome / Edge ZIP ↓
Firefox developer ZIP ↓
Firefox signing and runtime validation remain pending.
A connection you approve.
-
Open Trusted devices on the unlocked main desktop. Start Wi-Fi sync and create an
invitation.
-
Paste that invitation into the receiving native app. Compare the six-digit code and
approve on the main device.
-
Fetch and review the main copy. Later edits return as a proposed update for the main
user to review.
The main app must stay open and unlocked. Transfers use pinned TLS and encrypted KDBX
files. Sync replaces a complete copy after review; it does not automatically merge
conflicting fields. The previous copy is kept among the last ten local sync/import
backups.
Wi-Fi/private-subnet checks cannot prove physical proximity. Guest-network isolation, a
changed address or VPN may prevent a connection.
Read the full setup, recovery and security boundaries.
Use the current security release.
Earlier preview downloads have been retired. Version 0.3.3 includes HTTPS-only extension
filling and stronger Wi-Fi request checks.
Install the CLI
npm ci
node cli.mjs create my-vault.kdbx
node cli.mjs add my-vault.kdbx
node cli.mjs list my-vault.kdbx
Run inside the extracted CLI folder. Secrets are entered at hidden prompts. For Chrome/Edge,
extract the extension and use Extensions → Developer mode → Load unpacked. Firefox uses
about:debugging → This Firefox → Load Temporary Add-on.
Verify your download ·
SHA-256 download checksums ·
Use Vault in your browser. Checksums detect changed downloads; they do not
replace signed releases or an audit.