Skip to content
Home

Building

Keepid

A local-first credential platform for passwords, passkeys, API keys and machine identities—designed for people, applications and AI agents.

Current phase

In active development

Latest milestone

Foundation: vision, threat model, and architecture docs

Product story

Credentials should not live as plaintext files or be exposed to every process that asks for them. Keepid aims to give humans and agents a safer default for storing and using secrets with clear trust boundaries.

Security model

Protected assets: passwords, passkeys, API keys, machine identities. Trusted components: local vault, OS keystore, hardware keys. Explicit non-goals: becoming a general password manager clone without stronger identity boundaries.

Architecture

Client, local daemon, encrypted vault, OS keystore, policy engine, optional browser extension and sync—designed local-first with hardware-backed authentication where available.

Engineering journal

Milestone 0 — Product scope and non-goals.\nMilestone 1 — Local-first architecture and threat model.\nMilestone 2 — Envelope encryption and vault item model.\nUpcoming — Hardware-backed auth experiments and first CLI demo.

Live evidence

Public artefacts will include VISION, THREAT_MODEL, SECURITY, ROADMAP, ADRs, and the repository as they land. Live site: keepid.omrfrkcpr.com (later keepid.dev).

Stack

TypeScriptGoWebAuthnCryptographyLocal-first