Lokker
Local-First Password Vault & Digital Workspace

Your passwords don't need a server.

Lokker stores your encrypted vault locally and keeps your master password on your device. Manage credentials, generate 2FA codes, and autofill securely without handing your vault to a centralized cloud database.

Local-First Encrypted Locally No Mandatory Account Browser Autofill Open Source
Live Interactive Demonstration

Store it. Lock it. Use it.

Experience the actual Lokker application interface. Clean, fast, and engineered strictly for your local workflow.

https://lokker.local/passwords
Local Vault

Password Vault

3 credentials stored • AES-GCM 256-bit encrypted

Decrypted in Memory
G
GitHubDeveloper
alex.developer@example.com
••••••••••••••••
P
ProtonMailPersonal
alex.vault@proton.me
••••••••••••••••
A
AWS ConsoleInfrastructure
admin-iam-production
••••••••••••••••
Architectural Independence

Why Local-First Architecture Matters

Your password manager shouldn't need custody of your passwords. Centralized password servers create high-value breach targets.

Traditional Cloud Architecture
Centralized Custody

Your Device → Cloud Server Database → Remote Synchronization

  • ×Encrypted vaults stored on remote vendor servers
  • ×Mandatory user accounts and remote authentication sessions
  • ×Single server breach or subpoena puts millions of vaults at risk
  • ×Ongoing subscription fees and telemetry tracking
Lokker Local-First Model
Zero Server Custody

Your Device → AES-GCM Encryption → Local IndexedDB

  • Vault encrypted and stored strictly on your local hardware
  • Zero mandatory accounts or centralized credential databases
  • Full functionality remains 100% operational offline
  • Open source under AGPLv3 with no telemetry or tracking
Envelope Encryption

What Happens to Your Master Password?

Lokker implements a 3-tier Envelope Encryption Model (VEK / KEK). Your master password never encrypts the data directly.

STEP 01
Master Password
Entered locally on your device
STEP 02
Derive KEK
PBKDF2 100,000 iterations (SHA-256)
STEP 03
Unwrap VEK
Vault Encryption Key (256-bit)
STEP 04
AES-GCM 256
Authenticated payload encryption
STEP 05
Local Storage
Encrypted payload saved in IndexedDB
Optional Cloud CoordinationBackend Live • Teams Coming Soon

Zero-Knowledge Cloud Sync & Team Workspaces

Prefer seamless cross-device synchronization? Lokker now features an optional, end-to-end encrypted coordination backend powered by Fastify v5 and Neon Serverless Postgres.

100% Optional By Design
Unlike commercial password managers, Lokker never mandates accounts or remote logins. Your vault remains fully functional offline on your local device forever. Cloud accounts are strictly opt-in.
Zero-Knowledge Relay
Your encryption keys are derived locally from your master password using PBKDF2. Our Neon Postgres backend only stores encrypted ciphertext payloads and rotating refresh tokens — never plaintext secrets.
Team Workspaces (Coming Soon)
Collaborative shared vaults with Role-Based Access Control (Admins and Members) to securely share credentials, masked emails, and API keys across organizations without compromising personal zero-knowledge boundaries.

Backend Service Ready

Fastify v5 + Neon Database backend with Argon2 password hashing and rotating JWTs is online.

Unified Capabilities

A Complete Local Security Toolkit

Everything you need for credential hygiene and private authentication in a single lightweight application.

Password Vault
Store passwords, usernames, URLs, categories, custom tags, and private notes with instant search.
2FA TOTP Authenticator
RFC 6238 time-based one-time passcodes with circular countdowns and 1-click clipboard auto-copy.
Security Health Audit
Local password strength scoring, reused password detection, and k-Anonymity dark web breach checking.
Import & Export
Multi-format parser for Chrome, Bitwarden, 1Password, and CSV with conflict resolution preview.
Encrypted Bookmarks
Keep private bookmarks organized alongside your credentials with seamless bidirectional association.
Passkeys & WebAuthn
Hardware-bound biometric unlock via Touch ID, Windows Hello, or FIDO2 security keys via PRF.
Zero Custody Guarantee

What We Don't Need to Protect Your Vault

Our architecture is designed so that we never have custody of your credentials.

No Plaintext Database

We operate no server-side password repository or remote storage.

No Master Password Storage

Your master password stays exclusively on your local hardware.

No Mandatory Cloud Account

No registration, email validation, or credit card required for local use.

No Analytics Trackers

Zero third-party telemetry, behavioral tracking, or pixel beacons.

Frequently Asked Questions

Clear, transparent answers about Lokker architecture, cryptography, and privacy.

No. Lokker operates zero central password databases. Your master password, encryption keys, and vault entries are generated, encrypted, and stored entirely within your browser local IndexedDB on your own device.

Your credentials belong to you.

Start with a private, local-first password vault. No cloud accounts, zero subscription fees, and complete cryptographic control.