End-to-end encrypted

Your passwords.Your infrastructure.Your control.

A private vault for every device, with a hosted option when you want it and self-hosting when you do not.

Checking registrationDeploy your own

Checking registration availability

Built for control

One vault. Every way in.

Use the hosted vault in seconds, or run the same code on your own Cloudflare account.

Authwell vault preview
All itemsSearch vault
G

Developmentdeveloper@example.com

C

Cloud servicesadmin@example.com

P

Personal emailprivate@example.com

B

Banking••••••••••••

Know where your data lives

Security explained without theatre.

Authwell is designed so the server cannot read your vault. The implementation is open for inspection, but it has not yet received an independent security audit.

Read the security model
  1. 01

    Encryption happens on your device

    Your master password and decrypted vault contents are never sent to the Authwell server.

  2. 02

    The server stores ciphertext

    Cloudflare Workers, D1, and R2 handle encrypted vault data, attachments, and sync metadata.

  3. 03

    Self-hosting stays first class

    Run the same API on infrastructure you control and connect the web, extension, Android, or CLI clients.

$ git clone github.com/ryan12324/LockBox$ bun run deploy:api$ VITE_API_URL=https://api.example.com bun run deploy:web✓ Your vault. Your Cloudflare account.

Self-hosting stays first class

Use our server, or bring your own.

The hosted vault is the fastest way in. The full Workers, D1, R2, web, extension, Android, and CLI stack remains available under an open-source license.

Ready when you are

Open the vault. Keep the choice.

Checking registrationSign in