Modern, minimal and selfhosted password manager - Keep securely encrypted password files on your server and access them wherever you want through the browser. No installation required.
- Military-grade and well-documented password encryption format
- Password vault collections
- Sleak interface
- Runs in a single Docker container - 1 minute deployment on your server - Full control of your data, no cloud dependencies
htpasswd -cm /home/campfire/data/other/passwords/.htpasswd myusername
chmod 600 /home/campfire/data/other/passwords/.htpasswd
- APP_PASSWORD_FILE=/app/data/passwords/.htpasswd
- /home/campfire/data/other/passwords/.htpasswd:/app/data/passwords/.htpasswd:ro
Modern self-hosted password manager - Securely store and manage your passwords with military-grade AES-256-GCM encryption. Access your password vault through a beautiful, intuitive interface.
- π Military-Grade Encryption - AES-256-GCM encryption with PBKDF2 key derivation (600,000 iterations)
- π Multiple Vaults - Create and manage multiple encrypted password files
- π Smart Search - Quickly find passwords by title, username, URL, or tags
- π― Password Generator - Generate strong, random passwords with customizable options
- π Password Strength Meter - Visual feedback on password security
- π·οΈ Tags & Organization - Organize passwords with tags and custom fields
- πΎ Auto-Save - Encrypted backups saved to your server
- π¨ Modern UI - Beautiful, responsive interface with Tailwind CSS
- π³ Docker Ready - Easy deployment with Docker Compose
- π Self-Hosted - Full control of your data, no cloud dependencies
OwnPassword is meant to run as self-hosted Docker container.
-
Prepare the data directory
Create a directory for your encrypted password files:
mkdir -p /path/to/your/passwords
Update the volume mount in
docker-compose.yaml:volumes: - /path/to/your/passwords:/app/data/passwords # Change this path
-
Build and run
docker compose up -d --build
-
Access the application
- Application runs on port 3009 (configure reverse proxy as needed)
- Open your browser and navigate to
http://localhost:3009 - Create your first password vault or open an existing
.passwoodfile
- Master Password: Never share or store your master password. It cannot be recovered if lost.
- Backup: Regularly backup your
.passwoodfiles to multiple secure locations - HTTPS: Always use HTTPS in production (configure your reverse proxy)
- Access Control: Restrict network access to the application
- File Permissions: Ensure proper file permissions on the passwords directory
- TypeScript - Type-safe JavaScript
- React - UI component library
- Vite - Fast build tool and dev server
- Tailwind CSS - Utility-first CSS framework
- Web Crypto API - Browser-native cryptography
- TypeScript - Type-safe JavaScript
- Express - Web framework for Node.js
- Node.js - JavaScript runtime
- AES-256-GCM - Authenticated encryption with associated data
- PBKDF2-SHA256 - Key derivation (600,000 iterations, OWASP recommended)
- HMAC-SHA256 - Header integrity verification
own-password/
βββ backend/ # Backend API
β βββ src/
β β βββ server.ts # Express server setup
β β βββ password_endpoints.ts # Password file API endpoints
β βββ data/
β β βββ passwords/ # Encrypted .passwood files
β βββ package.json
β βββ tsconfig.json
βββ frontend/ # Frontend React app
β βββ src/
β β βββ components/
β β β βββ MainPage.tsx # Main application component
β β β βββ PasswordFilePicker.tsx # File selection UI
β β β βββ PasswordFileEditor.tsx # Password vault editor
β β βββ cryptor/ # Encryption library
β β β βββ crypto.ts # Cryptographic primitives
β β β βββ format.ts # .passwood file format
β β β βββ types.ts # TypeScript interfaces
β β β βββ utils.ts # Helper functions
β β βββ api/
β β β βββ passwordApi.ts # Backend API client
β β βββ App.tsx
β βββ package.json
β βββ vite.config.ts
βββ docker-compose.yaml # Production deployment
βββ docker-compose-dev.yaml # Development setup
βββ README.md
- Node.js 18+
- Docker (optional, for containerized development)
-
Install dependencies
# Backend cd backend npm install # Frontend cd ../frontend npm install
-
Run in development mode
# Terminal 1 - Backend cd backend npm run dev # Terminal 2 - Frontend cd frontend npm run dev
-
Or use Docker
docker compose -f docker-compose-dev.yaml up --build
GET /api/password_files- List all .passwood filesGET /api/password_files/:filename- Download a password filePOST /api/password_files/:filename- Save/update a password fileDELETE /api/password_files/:filename- Delete a password file
See frontend/src/cryptor/README.md for detailed documentation on the encrypted file format.
- 256-byte header with metadata and HMAC
- AES-256-GCM encrypted payload
- Unique salt and IV per file
- JSON database structure (encrypted)
- Password strength validation
βββββββββββββββββββββββββββββββββββββββββββ
β User Master Password β
ββββββββββββββββ¬βββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββ
β PBKDF2-SHA256 (600k iterations) β
β + Random Salt (256-bit) β
ββββββββββββββββ¬βββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββ
β Encryption Key (256-bit) β
ββββββββββββββββ¬βββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββ
β AES-256-GCM Encryption β
β + Unique IV + Auth Tag β
ββββββββββββββββ¬βββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββ
β Encrypted .passwood File β
β (Header + Encrypted Payload) β
βββββββββββββββββββββββββββββββββββββββββββ
- Use a strong master password (12+ characters, mixed case, numbers, symbols)
- Never reuse your master password
- Keep backups of your .passwood files in secure locations
- Use the password generator for new passwords
- Regularly update stored passwords
- Lock the application when not in use
- Never log decrypted data
- Clear sensitive data from memory when done
- Use HTTPS in production
- Implement rate limiting on the backend
- Add authentication for multi-user deployments
- Regular security audits
Requires modern browsers with Web Crypto API support:
- β Chrome 60+
- β Firefox 57+
- β Safari 11+
- β Edge 79+
- Argon2id support via WebAssembly
- Hardware security key support (WebAuthn)
- Browser extension for auto-fill
- Mobile app (React Native)
- Password sharing with encryption
- 2FA/TOTP integration
- Password breach checking
- Import from other password managers
- Secure notes and documents
- Multi-user support with access control
MIT License - See LICENSE file for details
If you discover a security vulnerability, please email security@example.com. Do not open a public issue.
Built with β€οΈ for privacy and security