Building
Keepid
A local-first credential platform for passwords, passkeys, API keys and machine identities—designed for people, applications and AI agents.
Current phase
In active development
Latest milestone
Foundation: vision, threat model, and architecture docs
Product story
Credentials should not live as plaintext files or be exposed to every process that asks for them. Keepid aims to give humans and agents a safer default for storing and using secrets with clear trust boundaries.
Security model
Protected assets: passwords, passkeys, API keys, machine identities. Trusted components: local vault, OS keystore, hardware keys. Explicit non-goals: becoming a general password manager clone without stronger identity boundaries.
Architecture
Client, local daemon, encrypted vault, OS keystore, policy engine, optional browser extension and sync—designed local-first with hardware-backed authentication where available.
Engineering journal
Milestone 0 — Product scope and non-goals.\nMilestone 1 — Local-first architecture and threat model.\nMilestone 2 — Envelope encryption and vault item model.\nUpcoming — Hardware-backed auth experiments and first CLI demo.
Live evidence
Public artefacts will include VISION, THREAT_MODEL, SECURITY, ROADMAP, ADRs, and the repository as they land. Live site: keepid.omrfrkcpr.com (later keepid.dev).