@deepakmarathe/vault-cli
v0.1.0
Published
Local-first credential vault CLI (list/get/generate) with Dashlane-compatible import/export
Readme
Vault MVP
An independently branded, local-first credential vault foundation for desktop. This project is not affiliated with Dashlane and does not copy Dashlane code, assets, services, or proprietary backup formats.
Current capabilities
- Encrypted local vault file with a versioned envelope.
- Password-derived wrapping key and a random vault key (envelope encryption).
- Login and secure-note records with encrypted-at-rest persistence.
- RFC 6238 TOTP code generation and secure password generation.
- Versioned, fixture-driven Dashlane CSV compatibility adapter for credentials and secure notes.
- Field-level portability reports: malformed rows, unknown fields, and non-portable data are reported rather than silently dropped.
Important security status
This is an early foundation, not production-ready password-manager software. Do not store production credentials in it. Before any release, it requires independent cryptographic review, penetration testing, platform secure-storage integrations, authenticated sync design, and real-client interoperability validation.
Data portability
The public CSV interchange path is inherently lossy for features such as binary attachments, sharing permissions, audit history, device metadata, and platform-bound passkeys. The importer preserves unmapped source fields in encrypted provenance metadata and reports them; the exporter reports items it cannot represent.
This project does not read, write, decode, or emulate Dashlane's proprietary .dash backup format. CXP/passkey transfer remains experimental until validated through public platform APIs and real-device acceptance tests.
Install
Desktop GUI (macOS): open the DMG from the latest Release and drag Vault.app to /Applications. Linux/Windows installers build per-platform — see docs/RELEASING.md.
CLI (vault): the repo is private, so the installer authenticates via GitHub:
gh auth login # or: export GITHUB_TOKEN=<token, 'repo' read scope>
bash scripts/install.sh # downloads the vault-<os>-<arch> binary → ~/.local/bin
vault generate # try it (also: list, get — needs VAULT_PATH + VAULT_PASSWORD)Or via npm once published: npm install -g @deepakmarathe/vault-cli.
Build & release
All per-platform build, packaging, and publish commands live in docs/RELEASING.md — GUI installers (cargo tauri build --bundles …), self-contained CLI binaries (bun build … --compile), the GitHub Release, npm, and Homebrew. The v0.1.0 Release is live with CLI binaries for macOS/Linux/Windows + the macOS DMG.
Development
Prerequisite: Node.js 22 or newer.
npm install
npm test
npm run lint
npm run typecheckElectron development launch:
npm startSensitive data policy
Never commit credentials, exported vaults, TOTP seeds, recovery codes, API keys, or real Dashlane exports. The repository permits only intentionally synthetic test fixtures under test/fixtures/.
Compatibility validation
Automated tests verify the project's documented CSV profile. A current Dashlane client round-trip must be manually verified with a user-provided, Git-ignored export before any compatibility claim is released. See docs/portability/dashlane-csv.md.
