Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

vault

A fuzzy-search terminal client for Bitwarden and Vaultwarden: press a key, type a few letters, and the password is on your clipboard — and off it again twenty seconds later.

Built for Omarchy, but it is a plain bash script and works anywhere rbw, fzf, and wl-clipboard do.

vault>  git
⏎ password    ctrl-x for more
  github.com          you@example.com
  gitlab.com          you@example.com

Why it does not talk to the API directly

The Bitwarden protocol is end-to-end encrypted: derive a master key with PBKDF2 or Argon2id, authenticate with a hashed password, then decrypt every item client-side with AES-256-CBC + HMAC-SHA256, plus RSA for organization keys.

rbw already does all of that, and keeps the decrypted keys in a background agent the way ssh-agent does. This script is a front end over rbw; it never sees a key and never implements a cipher.

What it does about the clipboard

Copying a password to the clipboard is the whole point, and also the risk. So:

  • Every copy is marked sensitive (wl-copy --sensitive), which sets the x-kde-passwordManagerHint type. Clipboard managers that honour it — Omarchy's does — skip the entry entirely rather than writing your vault to disk.
  • The clipboard clears itself after 20 seconds (VAULT_CLEAR_SECONDS).
  • It will not clobber a later copy. The timer compares a SHA-256 of the current clipboard against what it put there, and clears only on a match, so something you copied in the meantime survives. The plaintext is not held for the countdown, only its hash.
  • Secrets never enter the script. rbw output is piped straight into wl-copy — never a shell variable, never an argument (/proc/*/cmdline is world-readable), never a file.
  • The preview pane shows field names, never values.

tests/clipboard-test.sh asserts all of this, including that a copied secret really is absent from the clipboard manager's history.

Install

sudo pacman -S rbw fzf wl-clipboard gum      # jq and libnotify optional
git clone https://github.com/DukeRupert/omarchy-vault.git
rbw vault access and crypto
fzf the picker
wl-clipboard copying, and the sensitive hint
gum first-run setup prompts
jq optional; fallback for reading URIs and notes
libnotify optional; desktop notifications

Also needs a pinentry program, which rbw uses to ask for your master password. pinentry-gnome3 or pinentry-qt both give a graphical prompt.

First run

Running vault with no configuration asks for your email and server URL, logs in, and syncs. Nothing else to set up.

Keys

enter copies the password — the common case gets the bare key. Everything else lives behind a prefix, tmux style: ctrl-x shows the menu in the preview pane, and the next key acts.

after ctrl-x
⏎ password
u username
n notes — enter copies one line, ctrl-a copies all
t TOTP code (shown as well as copied; it expires in 30s anyway)
e edit the entry in $EDITOR
o open its URI in a browser
f filter by folder
r sync
l lock the vault

Per-line copy in the notes viewer is deliberate: notes are usually a list of recovery codes, and you want one of them, not the block.

On Omarchy

Bind it to a key in ~/.config/hypr/bindings.lua:

o.bind("SUPER + SLASH", "Passwords",
  "omarchy-launch-tui --app-id=TUI.float /path/to/vault")

The explicit --app-id=TUI.float matters: omarchy-launch-tui would otherwise derive org.omarchy.vault, which is not in Omarchy's float list, and the window would tile instead of floating centred.

What it does not do

  • No vault editing beyond rbw edit. Adding, deleting, and attachments are the web vault's job.
  • No organization management.
  • Wayland only, for wl-clipboard. An X11 port would need xclip and would lose the sensitive hint, which is most of the point.

Development

tests/clipboard-test.sh    # clipboard behaviour, using sentinels not real secrets
bash -n vault              # syntax

The action-key state machine is testable directly, since fzf calls back into the script for every keypress:

S=$(mktemp -d); : > "$S/folder"
./vault --key u some-id "$S"     # -> put          (types, no prefix pressed)
touch "$S/mode"
./vault --key u some-id "$S"     # -> the actions for "copy username"

License

MIT — see LICENSE.

About

Fuzzy-search TUI for Bitwarden and Vaultwarden — copies to a clipboard that clears itself and stays out of clipboard history.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages