A local cli password manager writen in c++23 with git syncronization. A fully compatible rewrite of keeper with additional features
Before building, you can tweak default cryptography params, used extensions and other things by modifying params.hpp:
#pragma once
namespace params {
/*
* Number of iterations used to generate unique key.
* Key generated with '320000' iterations wont match a
* key generated with '244444' iterations.
* More iterations, more time it takes to unlock the locker.
* Optimal number of iterations is from 300000 to 400000
*/
const unsigned int ITERATIONS = 300000;
/*
* Token size, will affect only new generated token. In case
* if actual token is longer than it's size, will use first amount of bytes
* Optimal size: 32 to 64
*/
const unsigned int TOKEN_SIZE = 32;
/*
* Same but size of the salt that's added at the beginning of each locker.
* Warning! In case if locker's salt is less than number passed, will lead to
* unexpected and fatal errors. Optimal size: 16 to 32
*/
const unsigned int SALT_SIZE = 16;
/*
* Encryption backend to use, each backend encrypts passwords in different way
* Passwords encrypted with fernet backend wont be decrypted with AES one
*/
constexpr const char* BACKEND = "AES"; // or fernet
/*
* Portable build. Will look for token, lokers in the
* same directory where the script is located.
* Token should be in <keepr_dir>/data/
* .lk files should be in <keeper_dir>/storage
* Where keper_dir is the location where executable is located
*/
const bool IS_PORTABLE_BUILD = false;
// Extensions included in build. Leave list empty to disable any
constexpr const char* EXTENSIONS[] = {
"GitManager"
};
} // namespace paramsmake && sudo make installmakeFirstly generate a token - unique pepper for your .lk files stored on your local machine. If you're going to use ceeper on multiple devices, each device must have the same token.
Generate with:
cee --generate-tokenIt will then be stored at ~/.local/share/keeper/token
Add a triplet (tag/login/password) with google tag
cee add google # also cee a googleGet triplet with google tag
cee get google # also cee g googleList all triplets and show their passwords
cee list -s # also cee ls -sRemove triplet with google tag
cee remove google # also cee rm googleAdd a triplet with tag github and a 32 chars generated password
cee a github -g -l 32Generate a password and print it to stdout instead of copying to clipboard
cee -g -pGet current locker absolute file path
cee -c -aEncrypt a file in place
cee -e secrets.txt -iDecrypt file and store it as not_secrets.txt, remove encrypted file
cee -d secrets.enc -o not_secrets.txt -iInteractive / REPL mode
ceeEncrypt file seecrets.txt but use contents of key.txt as encryption passphrase
cee -e secrets.txt --key-file key.txtUsage: cee [--help] [--current] [--force] [--absolute] [--print] [--gen] [--no-letters] [--no-symbols] [--length VAR] [--encrypt FILE] [--decrypt FILE] [--out OUT] [--in-place] [--key-file FILE] [--generate-token] {add,change,edit,find,get,list,remove}
Subcommands:
add add a new triplet with given TAG [aliases: ["a"]]
change changes current locker file to LOCKER [aliases: ["c", "ch"]]
edit interactively edit triplet[s] by TAG[s] [aliases: ["e"]]
find look for triplets by given tag PART[s] [aliases: ["f"]]
get get password by TAG [aliases: ["g"]]
list list triplets [aliases: ["l", "ls"]]
remove remove triplet[s] by TAG[s] [aliases: ["r", "rm"]]
Optional arguments:
-h, --help shows help message and exits
-c, --current print current locker path
-f, --force force action, don't prompt for confirmation
-a, --absolute treat locker paths as non relative to storage dir
-p, --print print to stdout instead of copying
-g, --gen generate a password, copy, and store it with tag
-nl, --no-letters generate a password without any letters.
-ns, --no-symbols generate a password without any special symbols.
-l, --length length for newly generated password [default: 16]
-e, --encrypt FILE prompts for password, encrypts given file using your token
-d, --decrypt FILE prompts for password, decrypts given file using your token
-o, --out OUT use this out file with -e/-d
-i, --in-place after encrypting / decrypting, remove original file
-kf, --key-file FILE treat contents of this file as passphrase (do not pass too big files)
--generate-token generate a new token
Each password file is referred to as a "locker" and has a .lk extension.
You can manage multiple lockers, each containing different sets of passwords.
Passwords are stored in a triplet format: tag/login/password.
Use the tag to retrieve detailed information about each triplet.
Lockers are encrypted with a passphrase and your unique token.
If you want to use your lockers on multiple devices, you need the same token.
Files in which passwords are stored. format is the following:
[nbytes salt][sha256 of a tag][encrypted]\n
[sha256 of a tag][encrypted triplet]\n
[sha256 of a tag][encrypted triplet]\n
You can find your .lk files at:
~/.keeper_storage(linux, mac, termux)C:\Users\<Username>\.keeper_storage(windows)
Or alternatively you can set custom directory with $KEEPER_STORAGE_DIR environment variable, for example:
export KEEPER_STORAGE_DIR="$XDG_STATE_HOME/keeper_storage"
Available if compiled with GitManager extension.
Ensure all of your devices have the same token, otherwise, things won't decrypt
You will be prompted to setup a git repo if not found, altenatively setup a git repo in you storage_dir, after that everything will be managed automatically.
- Crossplatform build
- Windows support