| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| kavach-extension-0.1.0.zip | < 22 hours ago | 23.4 kB | |
| README.md | < 22 hours ago | 1.8 kB | |
| v0.1.0 source code.tar.gz | < 22 hours ago | 5.9 MB | |
| v0.1.0 source code.zip | < 22 hours ago | 5.9 MB | |
| Totals: 4 Items | 11.8 MB | 0 | |
First tagged release of Kavach: a self-hosted, multi-user password manager that also tells you which secrets need attention first, and why.
This is early software and it has not been independently audited. Read SECURITY.md (github.com) and the threat model in the README before you store anything you can't afford to lose.
Run it
:::bash
git clone https://github.com/bhushanrtandukar-trader/kavach && cd kavach
docker compose up -d --build # then open http://127.0.0.1:8050
or without Docker, see the Quick start in the README.
What's in it
- Organisation roles (owner, admin, member, auditor) and per-vault roles (manager, editor, viewer). Admins manage people without being able to read secrets.
- Personal and shared vaults, each with its own AES-256-GCM key sealed to every member with X25519. Removing a member or disabling an account rotates the key.
- Invite-only onboarding, optional TOTP two-factor, and a hash-chained audit log with insights that compare activity to each person's own baseline.
- Security intelligence: explainable per-account risk, reuse and password-family detection, a ranked list of the fixes worth the most, a score timeline. It runs on the server and returns verdicts only.
- Optional email over your own SMTP server, and an optional Have I Been Pwned range lookup (off by default).
- A Chrome extension that fills a login only on the site it belongs to and refuses lookalike pages.
The full list is in CHANGELOG.md (github.com).
Browser extension
kavach-extension-0.1.0.zip below is the extension, ready to load unpacked: unzip it, open chrome://extensions, turn on Developer mode and choose Load unpacked.