PaperVault
papervault.xyzStore secrets and passwords on encrypted paper with distributed keys. Designed to last generations. Open source, client-side only, works offline.
- Homepage:papervault.xyz
- GitHub:github.com/boazeb/papervault
- Web info:web-check.xyz/check/papervault.xyz
PaperVault Source Code
Author
Description
Paper vault for passwords and secrets
Homepage
https://papervault.xyzRepository
- LicenseMIT
- Created03 Mar 26
- Primary languageJavaScript
- Size2,162 KB
- Stars62
- Forks5
- Watchers62
Top Contributors
@boazeb (40)
@dependabot[bot] (20)
@lissy93 (4)
@BittuBarnwal7479 (1)
Recent Commits
dependabot[bot](14 Aug 26)
chore(deps-dev): bump vite from 8.1.3 to 8.2.1 (#43) Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.2.1. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump actions/setup-node from 6 to 7 (#27) Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump trufflesecurity/trufflehog from 3.95.8 to 3.96.0 (#34) Bumps [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.95.8 to 3.96.0. - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](https://github.com/trufflesecurity/trufflehog/compare/v3.95.8...v3.96.0) --- updated-dependencies: - dependency-name: trufflesecurity/trufflehog dependency-version: 3.96.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump github/codeql-action from 4 to 4.37.3 (#37) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.3. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v4...v4.37.3) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.2 (#45) Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.7 to 0.6.2. - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.2) --- updated-dependencies: - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump moment-timezone from 0.6.2 to 0.6.3 (#36) Bumps [moment-timezone](https://github.com/moment/moment-timezone) from 0.6.2 to 0.6.3. - [Release notes](https://github.com/moment/moment-timezone/releases) - [Changelog](https://github.com/moment/moment-timezone/blob/develop/changelog.md) - [Commits](https://github.com/moment/moment-timezone/compare/0.6.2...0.6.3) --- updated-dependencies: - dependency-name: moment-timezone dependency-version: 0.6.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps-dev): bump @vitejs/plugin-react from 6.0.3 to 6.0.5 (#44) Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 6.0.3 to 6.0.5. - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/[email protected]/packages/plugin-react) --- updated-dependencies: - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps-dev): bump undici from 7.28.0 to 7.29.0 (#40) Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps-dev): bump postcss from 8.5.16 to 8.5.25 (#38) Bumps [postcss](https://github.com/postcss/postcss) from 8.5.16 to 8.5.25. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/postcss/postcss/compare/8.5.16...8.5.25) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.25 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump dompurify from 3.4.11 to 3.4.13 (#46) Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.11 to 3.4.13. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.13) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.13 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump body-parser from 2.2.2 to 2.3.0 in /papervault-mcp (#30) Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.2 to 2.3.0. - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0) --- updated-dependencies: - dependency-name: body-parser dependency-version: 2.3.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump @hono/node-server in /papervault-mcp (#48) Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.14 to 1.19.17. - [Release notes](https://github.com/honojs/node-server/releases) - [Commits](https://github.com/honojs/node-server/compare/v1.19.14...v1.19.17) --- updated-dependencies: - dependency-name: "@hono/node-server" dependency-version: 1.19.17 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump hono from 4.12.27 to 4.13.1 in /papervault-mcp (#47) Bumps [hono](https://github.com/honojs/hono) from 4.12.27 to 4.13.1. - [Release notes](https://github.com/honojs/hono/releases) - [Commits](https://github.com/honojs/hono/compare/v4.12.27...v4.13.1) --- updated-dependencies: - dependency-name: hono dependency-version: 4.13.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump ip-address from 10.2.0 to 10.4.0 in /papervault-mcp (#39) Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0. - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.4.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](14 Aug 26)
chore(deps): bump fast-uri from 3.1.2 to 3.1.5 in /papervault-mcp (#42) Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.5. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.5) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
BB(12 Jul 26)
fix(docker): apk upgrade in nginx stage to patch base-image CVEs (c-ares, libexpat)
BB(07 Jul 26)
docs: add Awesome Privacy badge to README
Boaz Bechar(07 Jul 26)
feat(build): migrate from CRA to Vite (#21) (#24) * feat(build): migrate from CRA (react-scripts) to Vite (#21) Replaces react-scripts + react-app-rewired + config-overrides.js with Vite 8, @vitejs/plugin-react and vite-plugin-node-polyfills. Jest -> Vitest. Clears the CRA build-toolchain vulns: npm audit 33 (13 high, 7 moderate) -> 6 (0 high/critical, 6 low). - JSX .js files renamed to .jsx; index.html moved to root (entry /src/index.jsx) - Buffer/process set as globals in entry; require() -> ESM imports (bip39 namespace) - build/ kept as outDir; vercel.json made explicit (outputDirectory + SPA rewrite) since the CRA preset auto-fallback no longer applies; modulePreload polyfill off for CSP - copy-wasm.js retained (self-hosted QR WASM) Verified: prod build, vitest, render (no console errors), crypto round-trips (AES-GCM v2, crypto-js v1, Shamir, bip39). * ci: drop Jest-only --watchAll flag now that tests run on Vitest
BB(06 Jul 26)
feat(dist): ship the Windows binary as a .zip (~40MB vs ~110MB) Compress the Windows .exe with PowerShell Compress-Archive so the download roughly halves, matching the macOS .app zip and Linux tar.gz.
BB(06 Jul 26)
docs: README reflects the macOS menu-bar app
BB(06 Jul 26)
feat(dist): macOS app lives in the menu bar (replaces the Quit dialog) PaperVault.app's main executable is now a small AppKit menu-bar app (Swift) instead of a blocking osascript dialog: a lock icon in the menu bar with Open / Quit. Cleans up the server on Quit and on SIGTERM/SIGINT. Drops launcher.sh.
BB(06 Jul 26)
feat(dist): native app bundles for the standalone binaries macOS ships as a double-clickable PaperVault.app (icon + Quit dialog) in a zip; Linux as a tar.gz that preserves the execute bit; Windows unchanged. Fixes the non-runnable raw-download problem. Release 1.3.0.
BB(06 Jul 26)
docs: add standalone single-file executable to Quick Start
BB(06 Jul 26)
chore: release 1.2.0
Boaz Bechar(06 Jul 26)
feat: single-file executable (Node SEA) (#23) * feat: single-file executable build (Node SEA) Download-and-run binary for self-hosters — no npm, no build, no Electron. Serves the embedded build over localhost (a secure context, needed for the QR-scanner WASM, camera, and Web Crypto) and opens the browser. Builds macOS/Linux/Windows binaries on X.Y.0 tags via release-binaries.yml, attached to the release with SLSA provenance. Co-Authored-By: Claude Opus 4.8 <[email protected]> * ci(release-binaries): suppress reviewed zizmor findings cache-poisoning on the npm cache step (matches release.yml's existing suppression) and the superfluous-actions notice on action-gh-release. --------- Co-authored-by: Claude Opus 4.8 <[email protected]>
BB(06 Jul 26)
chore: release 1.1.0 (release.yml yarn→npm)
Bittu kumar(06 Jul 26)
docs: add contributing guide (#19) * docs: add CONTRIBUTING.md * refactor: update CONTRIBUTING.md
dependabot[bot](05 Jul 26)
chore(deps): bump moment-timezone from 0.5.48 to 0.6.2 (#20) Bumps [moment-timezone](https://github.com/moment/moment-timezone) from 0.5.48 to 0.6.2. - [Release notes](https://github.com/moment/moment-timezone/releases) - [Changelog](https://github.com/moment/moment-timezone/blob/develop/changelog.md) - [Commits](https://github.com/moment/moment-timezone/compare/0.5.48...0.6.2) --- updated-dependencies: - dependency-name: moment-timezone dependency-version: 0.6.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](05 Jul 26)
chore(deps): bump actions/github-script from 8 to 9 (#9) Bumps [actions/github-script](https://github.com/actions/github-script) from 8 to 9. - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v8...v9) --- updated-dependencies: - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot[bot](05 Jul 26)
chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#8) Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7. - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](https://github.com/zizmorcore/zizmor-action/compare/v0.5.6...v0.5.7) --- updated-dependencies: - dependency-name: zizmorcore/zizmor-action dependency-version: 0.5.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
PaperVault Website
Website
PaperVault.xyz - Cold Storage Vault for Digital Assets and Passwords
Store secrets on paper with threshold encryption. Encrypt passwords, seed phrases and recovery codes, split the key using Shamir's Secret Sharing, and print as QR codes.
Redirects
Does not redirect
Security Checks
1 security checks failed (64 passed)
- Top-Level Domain Highly Abused
Server Details
- IP Address216.198.79.1
- LocationWalnut,California,United States of America,NA
- ISPVercel Inc
- ASNAS16509
Associated Countries
US
CA
Safety Score
Website marked as risky
70%
Blacklist Check
papervault.xyz was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
PaperVault Reviews
More Password Managers
Turn a recovery key, password, or other secret into 3 cards you can keep in different places. Open-source, client-side only, with an offline recovery page.
End-to-end encrypted open source password and alias manager with built-in email server. AliasVault protects your privacy by creating alternative identities, passwords and email addresses for every website you use. Use the cloud version, or self-host and deploy within minutes via Docker.
Fully-featured, open source password manager with cloud-sync. Bitwarden is easy-to-use with a clean UI and client apps for desktop, web and mobile. See also Vaultwarden, a self-hosted, Rust implementation of the Bitwarden server and compatible with upstream Bitwarden clients.
Hardened, secure and offline password manager. Does not have cloud-sync baked in, deemed to be gold standard for secure password managers. KeePass clients: Strongbox (Mac & iOS), KeePassDX (Android), KeeWeb (Web-based/ self-hosted), KeePassXC (Windows, Mac & Linux), see more KeePass clients and extensions at awesome-keepass by @lgg.
LessPass is a little different, since it generates your passwords using a hash of the website name, your username and a single main-passphrase that you reuse. It omits the need for you to ever need to store or sync your passwords. They have apps for all the common platforms and a CLI, but you can also self-host it.
The Standard Unix Password Manager
From the creators of ProtonMail, ProtonPass is a new addition to their suite of services. They have a full collection of user-friendly native mobile and desktop apps. ProtonPass is one of the few "trustworthy" providers that also offers a free plan.
About the Data: PaperVault
Change History
- Added #421
Edit PaperVault Data
You can edit PaperVault's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access PaperVault's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/papervaultThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share PaperVault
Help your friends compare Password Managers, and pick privacy-respecting software and services.
Share PaperVault and Awesome Privacy with your network!
