Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

165 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ” Nostr Secrets Vault

A secure, end-to-end encrypted password manager built on the Nostr protocol. Your secrets are encrypted locally and synced across devices using Nostr relays as encrypted self-addressed DMs.

License Platform Nostr Encryption

🌟 Overview

Nostr Secrets Vault is a zero-knowledge password manager that leverages the Nostr protocol for secure, decentralized secret synchronization. Unlike traditional password managers, there's no central server - your encrypted secrets are stored as messages to yourself on Nostr relays.

✨ Features

πŸ”‘ Key Management

  • Generate new Nostr key pairs (nsec/npub)
  • Import existing keys via nsec, hex, or NIP-19 format
  • Multiple key support with easy switching
  • Secure key storage with optional PIN encryption

πŸ”’ Military-Grade Security

  • AES-256-GCM vault encryption with PBKDF2 key derivation (100k iterations)
  • NIP-44 encryption for secrets (ChaCha20 + HMAC-SHA256)
  • Salt embedded in payload - no exposed cryptographic material
  • SHA-256 integrity verification with automatic self-healing
  • Optional PIN protection with biometric unlock (Android)

πŸ“‘ Decentralized Sync

  • Sync secrets across devices via Nostr relays
  • Self-addressed encrypted DMs (only you can decrypt)
  • Configurable relay list with connection status
  • Offline-first architecture with automatic sync

🎨 User Experience

  • Cyberpunk/neon dark theme
  • Mobile-first responsive design
  • Tag-based organization with color coding
  • Real-time search and filtering
  • Swipe navigation between screens
  • PWA support for app-like experience

πŸ›‘οΈ Security Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    User Device                          β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”‚
β”‚  β”‚  PIN/Bio    │───▢│  PBKDF2 Key Derivation      β”‚   β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β”‚  (100k iterations + salt)    β”‚   β”‚
β”‚                     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β”‚
β”‚                                 β”‚                       β”‚
β”‚                                 β–Ό                       β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚           AES-256-GCM Encrypted Vault            β”‚  β”‚
β”‚  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚  β”‚
β”‚  β”‚  β”‚ Nostr Keys β”‚  β”‚ Sign Logs  β”‚  β”‚ Settings  β”‚  β”‚  β”‚
β”‚  β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β”‚                                                         β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚  β”‚              NIP-44 Encrypted Secrets             β”‚  β”‚
β”‚  β”‚         (ChaCha20 + HMAC-SHA256 per secret)       β”‚  β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β”‚                          β”‚                              β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”‚β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                           β”‚
                           β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    Nostr Relays                         β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”‚
β”‚  β”‚ relay.damus β”‚  β”‚   nos.lol   β”‚  β”‚ nostr.band  β”‚     β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚
β”‚                                                         β”‚
β”‚         Encrypted DMs (Kind 4) - Self-Addressed         β”‚
β”‚         Only the owner can decrypt the content          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Security Guarantees

Layer Protection Details
Vault AES-256-GCM Keys & settings encrypted at rest
Salt Embedded PBKDF2 salt hidden in encrypted payload
Secrets NIP-44 Each secret individually encrypted
Transport TLS + NIP-44 End-to-end encrypted relay communication
Integrity SHA-256 Checksum verification with self-healing

πŸš€ Getting Started

Prerequisites

  • Node.js 18+ or Bun
  • Git

Installation

# Clone the repository
git clone https://github.com/AcierP/nostr-secrets.git
cd nostr-secrets

# Install dependencies
npm install
# or
bun install

# Start development server
npm run dev
# or
bun dev

Build for Production

npm run build
npm run preview

Android Build (Capacitor)

# Build web assets
npm run build

# Sync with Android
npx cap sync android

# Open in Android Studio
npx cap open android

πŸ“± Usage

First Launch

  1. Create or Import Key - Generate a new Nostr identity or import your existing nsec
  2. Optional PIN Setup - Enable PIN protection for vault encryption
  3. Add Your First Secret - Tap the + button to create a secret

Managing Secrets

  • Add: Tap + button, enter title and content, select tags
  • View: Tap the eye icon to decrypt and reveal content
  • Edit: Tap the pencil icon on any secret
  • Delete: Swipe left or use the delete button
  • Search: Use the search bar to filter by title
  • Filter: Tap tags to filter secrets by category

Syncing

  1. Go to Settings β†’ Manage Relays
  2. Add or remove relays as needed
  3. Secrets automatically sync when connected
  4. Green indicator = synced to all relays

πŸ”§ Configuration

Default Relays

wss://relay.damus.io
wss://relay.nostr.band
wss://nos.lol
wss://relay.primal.net

Available Tags

Tag Color Use Case
Login Blue Website credentials
Crypto Orange Wallet seeds, keys
Finance Green Banking, cards
Personal Pink Personal info
Work Purple Work-related
API Cyan API keys, tokens

πŸ—οΈ Tech Stack

Category Technology
Framework React 18 + TypeScript
Styling Tailwind CSS + shadcn/ui
Build Tool Vite
Mobile Capacitor
Crypto @noble/secp256k1, nostr-tools
State React Context + Custom Hooks

πŸ“ Project Structure

src/
β”œβ”€β”€ components/
β”‚   β”œβ”€β”€ SecretsScreen.tsx    # Main secrets list & management
β”‚   β”œβ”€β”€ AddSecretSheet.tsx   # Create/edit secret form
β”‚   β”œβ”€β”€ KeysScreen.tsx       # Nostr key management
β”‚   β”œβ”€β”€ SettingsScreen.tsx   # App settings
β”‚   β”œβ”€β”€ SecuritySheet.tsx    # PIN & biometrics settings
β”‚   β”œβ”€β”€ RelayManager.tsx     # Relay configuration
β”‚   └── ui/                  # shadcn/ui components
β”œβ”€β”€ context/
β”‚   └── VaultContext.tsx     # Global encrypted state
β”œβ”€β”€ hooks/
β”‚   β”œβ”€β”€ useRelaySync.ts      # Relay synchronization
β”‚   β”œβ”€β”€ useNostrDMs.ts       # DM fetching
β”‚   └── useBiometrics.ts     # Native biometric auth
β”œβ”€β”€ lib/
β”‚   β”œβ”€β”€ vault.ts             # AES-256-GCM encryption
β”‚   β”œβ”€β”€ nip44.ts             # NIP-44 implementation
β”‚   β”œβ”€β”€ keyStore.ts          # Key generation & storage
β”‚   β”œβ”€β”€ nostrRelay.ts        # Relay connections
β”‚   └── vaultIntegrity.ts    # SHA-256 checksums
└── pages/
    └── Index.tsx            # Main app layout

🀝 Contributing

Contributions are welcome! Please follow these steps:

  1. Fork the repository
  2. Create a feature branch: git checkout -b feature/amazing-feature
  3. Commit your changes: git commit -m 'Add amazing feature'
  4. Push to the branch: git push origin feature/amazing-feature
  5. Open a Pull Request

Code Style

  • TypeScript strict mode
  • Functional components with hooks
  • Tailwind CSS for styling
  • No inline styles

πŸ“„ License

πŸ“₯ Download

You can download the latest version of the application ready to install:

Download APK

Note: After downloading, you will need to allow installation from "Unknown Sources" in your Android phone's settings to be able to install the APK file.

This project is licensed under the MIT License - see the LICENSE file for details.

⚠️ Security Notice

  • Backup your nsec - Lost keys cannot be recovered
  • Use strong PINs - Short PINs are vulnerable to brute force
  • Verify relays - Only use trusted relay servers
  • Regular updates - Keep the app updated for security patches

πŸ™ Acknowledgments


Built with πŸ’œ for the Nostr community
Your keys, your secrets, your privacy.

About

Secure encrypted password vault built on Nostr with decentralized relay sync and zero-knowledge architecture.

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages