Your Keys. Your Vault.
No Central Server.
NodeZero replaces LastPass with hardware security key unlock, DID-based identity and end-to-end encrypted email for Gmail. There is no backend to breach and no key directory to subpoena. No usage tracking — not even by us.
No account required · No server · No telemetry · Contact us
Beta — NodeZero is under active development and has not yet undergone a formal third-party security audit. Keep your 12-word recovery phrase safe and exercise caution with high-value credentials.
Everything you need, nothing you don't
Core security is never paywalled. Hardware keys, local encryption, and MFA are free for everyone.
One Key, Many Ways In
Your vault key is random and never derived from anything you type. Each unlock method — security key, passphrase, recovery phrase — holds its own encrypted copy of it, so adding or changing one never re-keys the vault.
DID-Based Identity
Your cryptographic identity is self-sovereign, portable, and free from any central authority.
Sealed at Rest
Usernames, passwords and notes are each encrypted separately with their own nonce. The whole bundle — titles and URLs included — is then sealed again before it reaches disk or Drive, so a lost laptop or a copied backup reveals no site list and no contacts while the vault is locked. Once you unlock it, that data is readable to anything running as you — sealing protects data at rest, not a machine someone is already inside.
Google Drive Sync
Your encrypted vault syncs across devices through your own Google Drive, in the app-private appDataFolder — your storage, your account, revocable from Google's settings whenever you like. Changes made on another device are merged before upload rather than overwritten. No central server.
One-Click Import
Migrate from LastPass, 1Password, Bitwarden, or Chrome in seconds with drag-and-drop CSV import. Duplicate detection built in.
Post-Quantum Message Bodies
A message you send today can sit in somebody else’s storage until a computer exists that can open it. So message bodies are sealed with a hybrid of two key encapsulations at once — ML-KEM-768, the post-quantum standard NIST published as FIPS 203, and X25519, the classical one. It is designed so that an attacker must break both. There is no classical mode to fall back to: the older formats were deleted, not deprecated, so nobody can quietly talk your mail down to weaker encryption. Scope, stated plainly: this covers message bodies between two people who have exchanged current key cards. It does not make your identity, your signatures, your attachments or who you write to post-quantum. And while ML-KEM-768 is a NIST standard, the way NodeZero combines it with X25519 is our own construction, which nobody outside the project has reviewed.
Two-Factor Codes, Beside the Password
NodeZero holds your 2FA codes with the logins they belong to. Enrol by scanning the QR a site shows during setup, by pasting a setup key, or by importing them with the rest of your vault. Codes are generated on your device with a live countdown, and the seed is encrypted like a password — never shown outside the editor. Unusual issuers work too: 8-digit codes, SHA-256 and 60-second periods are read from the setup link rather than assumed. The seed is not saved until you enter a code that matches what NodeZero generates from it — so a mis-scan, the wrong QR, or a clock that disagrees fails the enrolment rather than leaving you with a factor that never works. Worth weighing: a password and its second factor in one vault is a convenience with a cost — whoever opens the vault has both. The vault being local, and unlock able to require a hardware key, narrows that. It does not remove it.
Encrypted Email for Gmail
The message body is encrypted in your browser before Gmail receives it, so what Google stores is ciphertext. Replies encrypt themselves once you have exchanged encrypted mail before, and replying into a thread NodeZero decrypted arms encryption by itself, so the quoted plaintext is not sent onward unencrypted by accident. No PGP, no key servers. Rather than protect a message only partly, it refuses to send when you attach a file or paste an image it cannot encrypt.
What Google Still Sees
NodeZero encrypts the message body — not the envelope around it. Google still sees who you write to, when, and how often, roughly how long the message is, and that you used NodeZero at all. Attachments and inline images are not encrypted; NodeZero refuses the send rather than let them go out looking protected.
Security Key or Passphrase Unlock
Day-to-day unlock is a hardware security key that derives its own secret (YubiKey, SoloKeys, Titan, Feitian), or a passphrase stretched with Argon2id. There is deliberately no face or fingerprint unlock: a browser extension cannot bind a stored key to a Windows Hello or Touch ID scan, so any key it kept would be readable from a copy of the browser profile. Either way your 12-word phrase is the way back on a new device.
Argon2id Passphrase Protection
Your passphrase is stretched with Argon2id — memory-hard, so each guess costs an attacker real RAM rather than cheap parallel GPU work. Tuned to 19 MiB and two passes so unlock stays fast enough that nobody turns it off.
Key Cards & Safety Numbers
No key directory exists, deliberately — nobody can look up whether an address uses NodeZero. Keys travel as signed key cards you hand over, and you can verify one by comparing a safety number over a phone call. Contacts can be deleted, and the deletion sticks across every synced device.
Key-Card Invite
Writing to someone with no key on file? NodeZero can open a plain-text draft carrying your signed key card so they can get started. One named recipient at a time, only when you ask, and only after it has told you what travels in the clear. It opens the draft — you still press Send.
Security Audit Report
Automatic detection of weak, reused, and aging passwords. Composite security score from 0 to 100 with actionable insights.
Side Panel & Dashboard
Open NodeZero as a Chrome side panel for a persistent view. A dashboard landing page shows your security score and vault stats at a glance.
Passkeys You Can Recover
NodeZero can create and store passkeys in your vault, so they sync across your devices and come back with your recovery phrase. Every use needs a click in the NodeZero window. These are software passkeys, not hardware keys — you gain recovery and multi-device use, and give up the non-exportability a security key gives you.
Page Access, Off by Default
Three separate switches — save the logins you type, record passkeys you create elsewhere, act as a passkey. All off to begin with, and until you turn one on NodeZero holds no permission to read or change the sites you visit.
A Badge, Not a Popup
When NodeZero notices a login worth saving, it marks the toolbar icon rather than covering the page. Your browser already has a save prompt, and two of them competing is how a password ends up in the wrong place. The icon also changes colour while the vault is locked.
Lightweight & Fast
A browser extension that downloads in about a megabyte. No desktop app needed. No account required. Install and go.
Built for how you actually browse
Right-click to fill. Import in seconds. Sync across every device. No desktop app required.
Setup in under a minute
Install the extension, register a hardware security key or set a passphrase, set a passphrase, and write down your 12-word recovery phrase. No email. No phone number. No account creation.
- Passkey unlock, with an Argon2id passphrase as backup
- 12-word recovery phrase you control
- Works with YubiKey, SoloKeys, Titan and Feitian
Welcome to NodeZero
A decentralized password manager. Your vault is encrypted and synced via Google Drive — only you hold the keys.
Right-click. Done.
No intrusive popups. No auto-fill surprises. Right-click any login form to fill credentials, generate a strong password, or save a new login. You're always in control.
- Context-menu autofill — no DOM injection
- One-click strong password generation
- Password strength meter built in
Switch in seconds
Export your passwords from Chrome, LastPass, 1Password, or Bitwarden as CSV. Drag and drop into NodeZero. Every entry is encrypted individually with unique random keys.
- Import from 4 major password managers
- Each entry encrypted with a unique key
- CSV is never uploaded — parsed locally in your browser
Import Credentials
Where are you importing from?
Go to chrome://settings/passwords → click ⋮ → Export passwords → Save CSV.
Version: 3
Aglo+rIkeKAlAJYUULeJClz0z8Dq
Encrypted email inside Gmail
Turn on Encrypt in any Gmail compose window and your message is encrypted for all recipients when you press Send. NodeZero mints a fresh ephemeral X25519 keypair for every message and wraps the content key separately for each recipient. There is no server and no directory — keys travel as signed cards you hand to the other person. Gmail autosaves drafts as you type, and those are not encrypted, so the privacy starts at Send.
- Body encrypted for every recipient (To + CC + BCC)
- Auto-decrypt with optional Gmail permission
- No PGP, no key servers — uses your existing DID identity
What this does not cover: NodeZero encrypts the message body, not the envelope Gmail routes on. Google still sees who you wrote to, when, how often, and roughly how long the message was — and that NodeZero was used, because the ciphertext is plainly marked. Attachments and inline images are not encrypted at all; rather than send a half-protected message, NodeZero refuses the send. Gmail also autosaves drafts as you type, so anything you compose in a Gmail window has already reached Google before you press Send.
Subject lines: an encrypted message goes out with a fixed marker subject — “🔒 Encrypted message (NodeZero)” — so a real subject is never left readable in the header. Write from NodeZero’s own composer and the subject you type is folded into the body before encryption: Google never receives it, and your recipient reads it once they decrypt. Type a subject into a Gmail compose window instead and Gmail will have autosaved it long before the marker replaces it.
Nobody is enrolled: there is no registry to join and nothing to look up. You can only encrypt to someone whose key card you already hold, and they only hold yours because one of you handed it over. If you have no key for a recipient, NodeZero can open a plain-text draft carrying your card — for that one person, once you ask, after telling you what it discloses. It opens the draft; you press Send.
Built different from the ground up
Traditional password managers store your vault on their servers and protect it with a master password — a single point of failure. NodeZero eliminates both.
Your vault is encrypted locally before it ever leaves your browser. Usernames, passwords and notes each get their own AES-256-GCM nonce, and the whole bundle — titles and URLs included — is sealed again before it is written anywhere. Your DID key never touches a server. There's no central database to breach and no recovery backdoor for attackers to exploit.
The vault key itself is random and permanent. Whichever ways in you set up — a security key, a passphrase, your recovery phrase — each holds a separately encrypted copy of that key rather than deriving it, so adding or changing one never re-keys anything. Where a passphrase exists, its copy is stretched with Argon2id — memory-hard, so guesses cost an attacker RAM rather than cheap parallel GPU work.
NodeZero also adds end-to-end encrypted email inside Gmail. There is no NodeZero server involved at any point — not for keys, not for delivery. Keys travel as signed key cards you hand to the other person, so no directory exists that could reveal who uses NodeZero. Vault sync goes through your own Google Drive, sealed before it leaves the machine, and we have no way to track your usage.
Be clear about the shape of that protection: it covers the message body, not the envelope Gmail routes on. Google still sees your recipients, when you wrote and how often, roughly how long the message was, and that NodeZero produced it. Attachments are not encrypted at all — NodeZero refuses the send rather than deliver a message it can only half protect. Nobody can honestly do better than this inside Gmail, and we would rather say so than let you assume otherwise.
Your recovery phrase can rebuild the vault from nothing but the twelve words, and it never leaves your device. A built-in security audit scores your vault for weak, reused, and aging passwords, and you can verify any contact by reading a safety number to them over a channel an attacker would have to compromise separately.
Read the source on GitHubZero-knowledge sync, zero central servers
Your vault syncs via your own Google Drive. NodeZero encrypts everything locally before upload, into Drive's app-private folder — what lands there is one opaque blob.
Encrypt Locally
Your vault key is random, generated once, and never leaves your device. Entries are encrypted under it and the whole bundle is sealed again before storage. All of it happens entirely in your browser before any data leaves your device.
Your Google Drive
The encrypted vault file is stored in your own Google Drive, in the app-private folder NodeZero is scoped to — not on our servers, and not anywhere we could reach. You can revoke access anytime from your Google account settings.
Smart Merge
When syncing across devices, NodeZero performs merge-before-upload with per-entry conflict resolution, and deletions leave tombstones so they are not undone by an older copy. Every unlock checks an Ed25519 signature over the vault and refuses a vault that fails it.
No central server. No usage tracking. There is no NodeZero server for your vault to sit on — the only copy off your machine is the sealed blob in your own Drive. Every cryptographic operation runs locally, in your browser.
Three steps to total control
No accounts. No emails. No phone numbers. Just install, secure, and browse.
Install & Setup
Install the Chrome extension. Register a security key, then set a passphrase for recovery and new devices. Takes under a minute.
Secure Your Vault
A 12-word recovery phrase is generated for you. Verify three of them. Your vault is sealed with AES-256-GCM before it touches disk.
Browse with Control
Right-click to fill, generate, or save credentials. No auto-fill surprises. You're always in control.
100% free. No catch.
Every feature is free, forever. No premium tier, no subscriptions, no paywalls.
Free
ALL FEATURESEverything included. No premium tier, no subscriptions, no paywalls. Every feature is free, forever.
- Unlimited passwords & notes
- Security key & passphrase unlock
- Argon2id passphrase protection
- 12-word recovery phrase
- Cross-device sync via your own Google Drive
- CSV import & export (4 formats)
- Encrypted email for Gmail
- Key cards & safety-number verification
- Key-card invite for people not yet set up
- Contact deletion that survives sync
- Security audit report
- Side panel mode & dashboard
- Context menu actions
- Auto-lock on inactivity (configurable, 1 hour default)
- Refuses to send when it cannot encrypt everything
Donate
SUPPORTNodeZero is free to use. If you find it useful, consider donating to support continued development.
- Keep NodeZero free for everyone
- Fund new features and improvements
- Support an independent developer
- No perks or gating — just gratitude
No features are paywalled. NodeZero is sustained by donations, not subscriptions.
Support NodeZero with Monero
Every payment to this address lands on a unique one-time output, so donations are not linkable to each other on-chain — and there is no server that could learn who paid.
42R9UJa5HPviUBdMU1rh7fE8hhEEuuVfQaSn6rr3hL5x6rHyYjm5CjFbynnMyCDXx5YHrRgCqwxKT35Eq5NvGAK6S8QCjN9 Send XMR only, on Monero mainnet. Sending any other asset to this address loses it permanently — there is no support channel to recover it.
Prefer Monero — amounts
and senders stay private on-chain.
Bitcoin (public ledger —
amount and your address are permanently visible):
bc1qheclqz87qhryfs97kuya5evjymut7c2zz5dk42
Nothing to trust us with
There is no NodeZero server. Your vault is encrypted on your own device with keys only you hold, and backed up — still sealed — to your own Google Drive. We are not in the path, so there is nothing for us to lose, hand over, or be breached for.
Install for ChromeReady to own your credentials?
Install in under a minute. Import your passwords. No account, no email, no tracking. Your keys. Your vault. Your rules.