离线密码管理器 · Offline password manager (Electron, Argon2id + AES-256-GCM)
See the codeA fully local, offline password manager.
ChronoKeyData folder next to the executable for portable datalocales/ folder — pick one in the installer and it downloads together with the app, or drop a pack into locales/ next to the app manually. Switch under Settings → Appearance; every installed language is listed there.ChronoKey does not need and does not provide any server functionality:
Multi-device use is achieved through manual file syncing:
Encryption Scheme:
Electron Security:
contextIsolation: truesandbox: truenodeIntegration: falseconnect-src 'none'webRequest.onBeforeRequestThreat Model Boundaries (Honest Security Claims):
Protects Against:
Does Not Protect Against:
Format: CK1.<base64url(header + iv + tag + ciphertext)>.<crc32>
Header (27 bytes):
CKSK Magic (4 bytes)
0x01 Version (1 byte)
m,t,p Argon2id params (6 bytes: u32 + u8 + u8)
salt Salt (16 bytes)
Payload (gzip):
{
"app": "ChronoKey",
"kind": "history-super-key",
"version": 1,
"exportedAt": "2026-10-01T00:00:00.000Z",
"data": { ... }
}
Merge Rules:
updatedAt winsversions array| Key | Function |
|---|---|
Ctrl/⌘ + F | Focus search box |
Ctrl/⌘ + K | Focus search box (alternative) |
Ctrl/⌘ + N | New item |
Ctrl/⌘ + L | Lock vault |
Ctrl/⌘ + , | Open settings |
Ctrl/⌘ + G | Open password generator |
Ctrl/⌘ + S | Save item (in editor) |
Esc | Close modal |
↑/↓ | List navigation |
npm install
npm run dev # Start Vite dev server (http://localhost:5173)
In another terminal:
npm run electron:dev
Or visit http://localhost:5173 in a browser (uses demo data, password "demo").
npm test # Run all unit tests
npm run test:electron # Electron integration test
npm run dist # Build the Windows x64 portable zip: release/ChronoKey-<version>-win-x64.zip
installer/ holds a small online installer / uninstaller (WinForms, .NET Framework 4.8, built into Windows 10/11):
%LOCALAPPDATA%\Programs\ChronoKey, no admin rights needed)latest.json from GitHub Releases, with progress, speed and time remaininglanguages.json downloads together with the app into locales\Uninstall.exe in the install folder removes the app (vault data can be kept)Build by running installer\build.cmd (uses the csc that ships with Windows, no SDK). Icons are generated by installer/MakeIcon.cs.
Create a ChronoKeyData folder in the same directory as the executable, and data will be saved there instead of the user directory. Suitable for USB flash drives.
"Washi × Moss" from NIPPON COLORS:
All text contrast ≥ 4.5:1 (WCAG AA)
The encryption code (electron/crypto.cjs, electron/vault.cjs) is fully open source, on purpose:
The only secrets are your master password, recovery code, and super-key passphrase — and they never leave your computer. Please report security issues privately via GitHub (Security → Report a vulnerability), not as public issues.
MIT License — see LICENSE
Security Disclaimer: This project has not undergone third-party security audits. Password managers should be used with an understanding of their threat model. If you discover a security issue, please disclose it responsibly.
JavaScript
76.4%
C#
16.4%
CSS
7.1%
离线密码管理器 · Offline password manager (Electron, Argon2id + AES-256-GCM)
See the codeA fully local, offline password manager.
ChronoKeyData folder next to the executable for portable datalocales/ folder — pick one in the installer and it downloads together with the app, or drop a pack into locales/ next to the app manually. Switch under Settings → Appearance; every installed language is listed there.ChronoKey does not need and does not provide any server functionality:
Multi-device use is achieved through manual file syncing:
Encryption Scheme:
Electron Security:
contextIsolation: truesandbox: truenodeIntegration: falseconnect-src 'none'webRequest.onBeforeRequestThreat Model Boundaries (Honest Security Claims):
Protects Against:
Does Not Protect Against:
Format: CK1.<base64url(header + iv + tag + ciphertext)>.<crc32>
Header (27 bytes):
CKSK Magic (4 bytes)
0x01 Version (1 byte)
m,t,p Argon2id params (6 bytes: u32 + u8 + u8)
salt Salt (16 bytes)
Payload (gzip):
{
"app": "ChronoKey",
"kind": "history-super-key",
"version": 1,
"exportedAt": "2026-10-01T00:00:00.000Z",
"data": { ... }
}
Merge Rules:
updatedAt winsversions array| Key | Function |
|---|---|
Ctrl/⌘ + F | Focus search box |
Ctrl/⌘ + K | Focus search box (alternative) |
Ctrl/⌘ + N | New item |
Ctrl/⌘ + L | Lock vault |
Ctrl/⌘ + , | Open settings |
Ctrl/⌘ + G | Open password generator |
Ctrl/⌘ + S | Save item (in editor) |
Esc | Close modal |
↑/↓ | List navigation |
npm install
npm run dev # Start Vite dev server (http://localhost:5173)
In another terminal:
npm run electron:dev
Or visit http://localhost:5173 in a browser (uses demo data, password "demo").
npm test # Run all unit tests
npm run test:electron # Electron integration test
npm run dist # Build the Windows x64 portable zip: release/ChronoKey-<version>-win-x64.zip
installer/ holds a small online installer / uninstaller (WinForms, .NET Framework 4.8, built into Windows 10/11):
%LOCALAPPDATA%\Programs\ChronoKey, no admin rights needed)latest.json from GitHub Releases, with progress, speed and time remaininglanguages.json downloads together with the app into locales\Uninstall.exe in the install folder removes the app (vault data can be kept)Build by running installer\build.cmd (uses the csc that ships with Windows, no SDK). Icons are generated by installer/MakeIcon.cs.
Create a ChronoKeyData folder in the same directory as the executable, and data will be saved there instead of the user directory. Suitable for USB flash drives.
"Washi × Moss" from NIPPON COLORS:
All text contrast ≥ 4.5:1 (WCAG AA)
The encryption code (electron/crypto.cjs, electron/vault.cjs) is fully open source, on purpose:
The only secrets are your master password, recovery code, and super-key passphrase — and they never leave your computer. Please report security issues privately via GitHub (Security → Report a vulnerability), not as public issues.
MIT License — see LICENSE
Security Disclaimer: This project has not undergone third-party security audits. Password managers should be used with an understanding of their threat model. If you discover a security issue, please disclose it responsibly.
JavaScript
76.4%
C#
16.4%
CSS
7.1%