Decentralized Credential Manager Beta

Your Keys. Your Vault.
No Central Server.

NodeZero replaces LastPass with hardware security key unlock, DID-based identity and end-to-end encrypted email for Gmail. There is no backend to breach and no key directory to subpoena. No usage tracking — not even by us.

No account required · No server · No telemetry · Contact us

Beta — NodeZero is under active development and has not yet undergone a formal third-party security audit. Keep your 12-word recovery phrase safe and exercise caution with high-value credentials.

NodeZero
All By Domain By Login 8 entries
github.com 2
github.com dev@startup.io ••••••••••••
github.com admin@work.com ••••••••••••••
mail.google.com 1
G
mail.google.com hello@gmail.com ••••••••••
+ Add Credential
Synced to your Google Drive
~1.1 MB
Download size
0
Trackers & cookies
Zero
Servers holding your data
Zero
Accounts needed
Features

Everything you need, nothing you don't

Core security is never paywalled. Hardware keys, local encryption, and MFA are free for everyone.

One Key, Many Ways In

Your vault key is random and never derived from anything you type. Each unlock method — security key, passphrase, recovery phrase — holds its own encrypted copy of it, so adding or changing one never re-keys the vault.

DID-Based Identity

Your cryptographic identity is self-sovereign, portable, and free from any central authority.

Sealed at Rest

Usernames, passwords and notes are each encrypted separately with their own nonce. The whole bundle — titles and URLs included — is then sealed again before it reaches disk or Drive, so a lost laptop or a copied backup reveals no site list and no contacts while the vault is locked. Once you unlock it, that data is readable to anything running as you — sealing protects data at rest, not a machine someone is already inside.

Google Drive Sync

Your encrypted vault syncs across devices through your own Google Drive, in the app-private appDataFolder — your storage, your account, revocable from Google's settings whenever you like. Changes made on another device are merged before upload rather than overwritten. No central server.

One-Click Import

Migrate from LastPass, 1Password, Bitwarden, or Chrome in seconds with drag-and-drop CSV import. Duplicate detection built in.

Post-Quantum Message Bodies

A message you send today can sit in somebody else’s storage until a computer exists that can open it. So message bodies are sealed with a hybrid of two key encapsulations at once — ML-KEM-768, the post-quantum standard NIST published as FIPS 203, and X25519, the classical one. It is designed so that an attacker must break both. There is no classical mode to fall back to: the older formats were deleted, not deprecated, so nobody can quietly talk your mail down to weaker encryption. Scope, stated plainly: this covers message bodies between two people who have exchanged current key cards. It does not make your identity, your signatures, your attachments or who you write to post-quantum. And while ML-KEM-768 is a NIST standard, the way NodeZero combines it with X25519 is our own construction, which nobody outside the project has reviewed.

Two-Factor Codes, Beside the Password

NodeZero holds your 2FA codes with the logins they belong to. Enrol by scanning the QR a site shows during setup, by pasting a setup key, or by importing them with the rest of your vault. Codes are generated on your device with a live countdown, and the seed is encrypted like a password — never shown outside the editor. Unusual issuers work too: 8-digit codes, SHA-256 and 60-second periods are read from the setup link rather than assumed. The seed is not saved until you enter a code that matches what NodeZero generates from it — so a mis-scan, the wrong QR, or a clock that disagrees fails the enrolment rather than leaving you with a factor that never works. Worth weighing: a password and its second factor in one vault is a convenience with a cost — whoever opens the vault has both. The vault being local, and unlock able to require a hardware key, narrows that. It does not remove it.

Encrypted Email for Gmail

The message body is encrypted in your browser before Gmail receives it, so what Google stores is ciphertext. Replies encrypt themselves once you have exchanged encrypted mail before, and replying into a thread NodeZero decrypted arms encryption by itself, so the quoted plaintext is not sent onward unencrypted by accident. No PGP, no key servers. Rather than protect a message only partly, it refuses to send when you attach a file or paste an image it cannot encrypt.

What Google Still Sees

NodeZero encrypts the message body — not the envelope around it. Google still sees who you write to, when, and how often, roughly how long the message is, and that you used NodeZero at all. Attachments and inline images are not encrypted; NodeZero refuses the send rather than let them go out looking protected.

Security Key or Passphrase Unlock

Day-to-day unlock is a hardware security key that derives its own secret (YubiKey, SoloKeys, Titan, Feitian), or a passphrase stretched with Argon2id. There is deliberately no face or fingerprint unlock: a browser extension cannot bind a stored key to a Windows Hello or Touch ID scan, so any key it kept would be readable from a copy of the browser profile. Either way your 12-word phrase is the way back on a new device.

Argon2id Passphrase Protection

Your passphrase is stretched with Argon2id — memory-hard, so each guess costs an attacker real RAM rather than cheap parallel GPU work. Tuned to 19 MiB and two passes so unlock stays fast enough that nobody turns it off.

Key Cards & Safety Numbers

No key directory exists, deliberately — nobody can look up whether an address uses NodeZero. Keys travel as signed key cards you hand over, and you can verify one by comparing a safety number over a phone call. Contacts can be deleted, and the deletion sticks across every synced device.

Key-Card Invite

Writing to someone with no key on file? NodeZero can open a plain-text draft carrying your signed key card so they can get started. One named recipient at a time, only when you ask, and only after it has told you what travels in the clear. It opens the draft — you still press Send.

Security Audit Report

Automatic detection of weak, reused, and aging passwords. Composite security score from 0 to 100 with actionable insights.

Side Panel & Dashboard

Open NodeZero as a Chrome side panel for a persistent view. A dashboard landing page shows your security score and vault stats at a glance.

Passkeys You Can Recover

NodeZero can create and store passkeys in your vault, so they sync across your devices and come back with your recovery phrase. Every use needs a click in the NodeZero window. These are software passkeys, not hardware keys — you gain recovery and multi-device use, and give up the non-exportability a security key gives you.

Page Access, Off by Default

Three separate switches — save the logins you type, record passkeys you create elsewhere, act as a passkey. All off to begin with, and until you turn one on NodeZero holds no permission to read or change the sites you visit.

A Badge, Not a Popup

When NodeZero notices a login worth saving, it marks the toolbar icon rather than covering the page. Your browser already has a save prompt, and two of them competing is how a password ends up in the wrong place. The icon also changes colour while the vault is locked.

Lightweight & Fast

A browser extension that downloads in about a megabyte. No desktop app needed. No account required. Install and go.

See It In Action

Built for how you actually browse

Right-click to fill. Import in seconds. Sync across every device. No desktop app required.

Step 1

Setup in under a minute

Install the extension, register a hardware security key or set a passphrase, set a passphrase, and write down your 12-word recovery phrase. No email. No phone number. No account creation.

  • Passkey unlock, with an Argon2id passphrase as backup
  • 12-word recovery phrase you control
  • Works with YubiKey, SoloKeys, Titan and Feitian

Welcome to NodeZero

A decentralized password manager. Your vault is encrypted and synced via Google Drive — only you hold the keys.

Security key or passphrase unlock
Passphrase, stretched with Argon2id
12-word recovery phrase you control
Vault synced via your own Google Drive
Create New Vault ›
↺ Recover existing vault
NodeZero
Fill Credentials
Generate Password
Save This Login
Open NodeZero
Step 2

Right-click. Done.

No intrusive popups. No auto-fill surprises. Right-click any login form to fill credentials, generate a strong password, or save a new login. You're always in control.

  • Context-menu autofill — no DOM injection
  • One-click strong password generation
  • Password strength meter built in
Step 3

Switch in seconds

Export your passwords from Chrome, LastPass, 1Password, or Bitwarden as CSV. Drag and drop into NodeZero. Every entry is encrypted individually with unique random keys.

  • Import from 4 major password managers
  • Each entry encrypted with a unique key
  • CSV is never uploaded — parsed locally in your browser

Import Credentials

Where are you importing from?

Chrome
LastPass
Bitwarden
1Password
Other
How to export:
Go to chrome://settings/passwords → click ⋮ → Export passwords → Save CSV.
Next →
8 entries imported!
New

Encrypted email inside Gmail

Turn on Encrypt in any Gmail compose window and your message is encrypted for all recipients when you press Send. NodeZero mints a fresh ephemeral X25519 keypair for every message and wraps the content key separately for each recipient. There is no server and no directory — keys travel as signed cards you hand to the other person. Gmail autosaves drafts as you type, and those are not encrypted, so the privacy starts at Send.

  • Body encrypted for every recipient (To + CC + BCC)
  • Auto-decrypt with optional Gmail permission
  • No PGP, no key servers — uses your existing DID identity

What this does not cover: NodeZero encrypts the message body, not the envelope Gmail routes on. Google still sees who you wrote to, when, how often, and roughly how long the message was — and that NodeZero was used, because the ciphertext is plainly marked. Attachments and inline images are not encrypted at all; rather than send a half-protected message, NodeZero refuses the send. Gmail also autosaves drafts as you type, so anything you compose in a Gmail window has already reached Google before you press Send.

Subject lines: an encrypted message goes out with a fixed marker subject — “🔒 Encrypted message (NodeZero)” — so a real subject is never left readable in the header. Write from NodeZero’s own composer and the subject you type is folded into the body before encryption: Google never receives it, and your recipient reads it once they decrypt. Type a subject into a Gmail compose window instead and Gmail will have autosaved it long before the marker replaces it.

Nobody is enrolled: there is no registry to join and nothing to look up. You can only encrypt to someone whose key card you already hold, and they only hold yours because one of you handed it over. If you have no key for a recipient, NodeZero can open a plain-text draft carrying your card — for that one person, once you ask, after telling you what it discloses. It opens the draft; you press Send.

Security

Built different from the ground up

Traditional password managers store your vault on their servers and protect it with a master password — a single point of failure. NodeZero eliminates both.

Your vault is encrypted locally before it ever leaves your browser. Usernames, passwords and notes each get their own AES-256-GCM nonce, and the whole bundle — titles and URLs included — is sealed again before it is written anywhere. Your DID key never touches a server. There's no central database to breach and no recovery backdoor for attackers to exploit.

The vault key itself is random and permanent. Whichever ways in you set up — a security key, a passphrase, your recovery phrase — each holds a separately encrypted copy of that key rather than deriving it, so adding or changing one never re-keys anything. Where a passphrase exists, its copy is stretched with Argon2id — memory-hard, so guesses cost an attacker RAM rather than cheap parallel GPU work.

NodeZero also adds end-to-end encrypted email inside Gmail. There is no NodeZero server involved at any point — not for keys, not for delivery. Keys travel as signed key cards you hand to the other person, so no directory exists that could reveal who uses NodeZero. Vault sync goes through your own Google Drive, sealed before it leaves the machine, and we have no way to track your usage.

Be clear about the shape of that protection: it covers the message body, not the envelope Gmail routes on. Google still sees your recipients, when you wrote and how often, roughly how long the message was, and that NodeZero produced it. Attachments are not encrypted at all — NodeZero refuses the send rather than deliver a message it can only half protect. Nobody can honestly do better than this inside Gmail, and we would rather say so than let you assume otherwise.

Your recovery phrase can rebuild the vault from nothing but the twelve words, and it never leaves your device. A built-in security audit scores your vault for weak, reused, and aging passwords, and you can verify any contact by reading a safety number to them over a channel an attacker would have to compromise separately.

Read the source on GitHub
Traditional
Vault stored on company servers
Encrypted vault synced via your own Google Drive — only you hold the key
Metadata left unencrypted
The whole bundle is sealed at rest — titles and URLs included, not just the passwords
Master password is the only thing in the way
A random vault key each method merely wraps — and the passphrase that wraps it is stretched with Argon2id
Lost device means locked out
12-word recovery phrase, stretched over ~2 million PBKDF2 iterations before it opens anything
Every sync and action tracked with counters tied to your account
Vault syncs through your own Google Drive — no central server, no usage tracking
Sent email content visible to your provider
The message BODY is encrypted before Gmail receives it — what Google stores is ciphertext (drafts you type in Gmail are not)
Encrypted-mail products imply your provider learns nothing
We say so plainly: Google still sees recipients, timing, rough size, and that NodeZero is in use
Sync conflicts silently overwrite your data
Smart merge-before-upload with per-entry conflict resolution and tombstones
No way to verify the server is honest
Every unlock checks the Ed25519 signature over the vault, and refuses a vault that fails it
Changing your password does not really revoke the old one
A retired passphrase cannot be spliced back in — the wrap table is signed and checked against the header
Deleting a contact on one device brings it back on the next sync
Deletions leave tombstones, so a removed contact stays removed everywhere
Encrypted email needs PGP, key servers and a manual key ceremony
Encrypted Gmail with no key server at all — keys arrive as signed cards you hand over
No visibility into password health
Security audit report scores weak, reused, and aging passwords from 0 to 100
Requires a heavy desktop app
Lightweight browser extension — zero install friction
Privacy Architecture

Zero-knowledge sync, zero central servers

Your vault syncs via your own Google Drive. NodeZero encrypts everything locally before upload, into Drive's app-private folder — what lands there is one opaque blob.

01

Encrypt Locally

Your vault key is random, generated once, and never leaves your device. Entries are encrypted under it and the whole bundle is sealed again before storage. All of it happens entirely in your browser before any data leaves your device.

Client-Side Only
02

Your Google Drive

The encrypted vault file is stored in your own Google Drive, in the app-private folder NodeZero is scoped to — not on our servers, and not anywhere we could reach. You can revoke access anytime from your Google account settings.

You Own the Storage
03

Smart Merge

When syncing across devices, NodeZero performs merge-before-upload with per-entry conflict resolution, and deletions leave tombstones so they are not undone by an older copy. Every unlock checks an Ed25519 signature over the vault and refuses a vault that fails it.

Tamper-Proof

No central server. No usage tracking. There is no NodeZero server for your vault to sit on — the only copy off your machine is the sealed blob in your own Drive. Every cryptographic operation runs locally, in your browser.

How It Works

Three steps to total control

No accounts. No emails. No phone numbers. Just install, secure, and browse.

01

Install & Setup

Install the Chrome extension. Register a security key, then set a passphrase for recovery and new devices. Takes under a minute.

02

Secure Your Vault

A 12-word recovery phrase is generated for you. Verify three of them. Your vault is sealed with AES-256-GCM before it touches disk.

03

Browse with Control

Right-click to fill, generate, or save credentials. No auto-fill surprises. You're always in control.

Pricing

100% free. No catch.

Every feature is free, forever. No premium tier, no subscriptions, no paywalls.

Free

ALL FEATURES
$0 / forever

Everything included. No premium tier, no subscriptions, no paywalls. Every feature is free, forever.

  • Unlimited passwords & notes
  • Security key & passphrase unlock
  • Argon2id passphrase protection
  • 12-word recovery phrase
  • Cross-device sync via your own Google Drive
  • CSV import & export (4 formats)
  • Encrypted email for Gmail
  • Key cards & safety-number verification
  • Key-card invite for people not yet set up
  • Contact deletion that survives sync
  • Security audit report
  • Side panel mode & dashboard
  • Context menu actions
  • Auto-lock on inactivity (configurable, 1 hour default)
  • Refuses to send when it cannot encrypt everything
Install for Chrome

Donate

SUPPORT
Any amount

NodeZero is free to use. If you find it useful, consider donating to support continued development.

  • Keep NodeZero free for everyone
  • Fund new features and improvements
  • Support an independent developer
  • No perks or gating — just gratitude
Donate in Monero

No features are paywalled. NodeZero is sustained by donations, not subscriptions.

Architecture

Nothing to trust us with

There is no NodeZero server. Your vault is encrypted on your own device with keys only you hold, and backed up — still sealed — to your own Google Drive. We are not in the path, so there is nothing for us to lose, hand over, or be breached for.

Install for Chrome
Your Keys Only
No Telemetry
Zero Central Servers

Ready to own your credentials?

Install in under a minute. Import your passwords. No account, no email, no tracking. Your keys. Your vault. Your rules.