A fuzzy-search terminal client for Bitwarden and Vaultwarden: press a key, type a few letters, and the password is on your clipboard — and off it again twenty seconds later.
Built for Omarchy, but it is a plain bash script and
works anywhere rbw, fzf, and wl-clipboard do.
vault> git
⏎ password ctrl-x for more
github.com you@example.com
gitlab.com you@example.com
The Bitwarden protocol is end-to-end encrypted: derive a master key with PBKDF2 or Argon2id, authenticate with a hashed password, then decrypt every item client-side with AES-256-CBC + HMAC-SHA256, plus RSA for organization keys.
rbw already does all of that, and keeps the
decrypted keys in a background agent the way ssh-agent does. This script is a
front end over rbw; it never sees a key and never implements a cipher.
Copying a password to the clipboard is the whole point, and also the risk. So:
- Every copy is marked sensitive (
wl-copy --sensitive), which sets thex-kde-passwordManagerHinttype. Clipboard managers that honour it — Omarchy's does — skip the entry entirely rather than writing your vault to disk. - The clipboard clears itself after 20 seconds (
VAULT_CLEAR_SECONDS). - It will not clobber a later copy. The timer compares a SHA-256 of the current clipboard against what it put there, and clears only on a match, so something you copied in the meantime survives. The plaintext is not held for the countdown, only its hash.
- Secrets never enter the script.
rbwoutput is piped straight intowl-copy— never a shell variable, never an argument (/proc/*/cmdlineis world-readable), never a file. - The preview pane shows field names, never values.
tests/clipboard-test.sh asserts all of this, including that a copied secret
really is absent from the clipboard manager's history.
sudo pacman -S rbw fzf wl-clipboard gum # jq and libnotify optional
git clone https://github.com/DukeRupert/omarchy-vault.gitrbw |
vault access and crypto |
fzf |
the picker |
wl-clipboard |
copying, and the sensitive hint |
gum |
first-run setup prompts |
jq |
optional; fallback for reading URIs and notes |
libnotify |
optional; desktop notifications |
Also needs a pinentry program, which rbw uses to ask for your master
password. pinentry-gnome3 or pinentry-qt both give a graphical prompt.
Running vault with no configuration asks for your email and server URL, logs
in, and syncs. Nothing else to set up.
enter copies the password — the common case gets the bare key. Everything else
lives behind a prefix, tmux style: ctrl-x shows the menu in the preview
pane, and the next key acts.
after ctrl-x |
|
|---|---|
⏎ |
password |
u |
username |
n |
notes — enter copies one line, ctrl-a copies all |
t |
TOTP code (shown as well as copied; it expires in 30s anyway) |
e |
edit the entry in $EDITOR |
o |
open its URI in a browser |
f |
filter by folder |
r |
sync |
l |
lock the vault |
Per-line copy in the notes viewer is deliberate: notes are usually a list of recovery codes, and you want one of them, not the block.
Bind it to a key in ~/.config/hypr/bindings.lua:
o.bind("SUPER + SLASH", "Passwords",
"omarchy-launch-tui --app-id=TUI.float /path/to/vault")The explicit --app-id=TUI.float matters: omarchy-launch-tui would otherwise
derive org.omarchy.vault, which is not in Omarchy's float list, and the window
would tile instead of floating centred.
- No vault editing beyond
rbw edit. Adding, deleting, and attachments are the web vault's job. - No organization management.
- Wayland only, for
wl-clipboard. An X11 port would needxclipand would lose the sensitive hint, which is most of the point.
tests/clipboard-test.sh # clipboard behaviour, using sentinels not real secrets
bash -n vault # syntaxThe action-key state machine is testable directly, since fzf calls back into the script for every keypress:
S=$(mktemp -d); : > "$S/folder"
./vault --key u some-id "$S" # -> put (types, no prefix pressed)
touch "$S/mode"
./vault --key u some-id "$S" # -> the actions for "copy username"MIT — see LICENSE.