PyVault is a local password and secrets manager written in Python.
The goal of this project is to build a simple, private and secure way to store sensitive information locally while learning how encryption, databases and application architecture work.
β οΈ PyVault is currently under development.
- π Generate Fernet encryption keys
- π Encrypt and store passwords using Fernet
- πΎ Store each password in a dedicated file per website
- π Decrypt and retrieve stored passwords
- π List all saved entries
- π Search stored passwords
- ποΈ Delete passwords
- π€ Export passwords
- π₯οΈ Simple CLI interface
- π§ͺ Unit tests
- π Encryption / decryption benchmark
- ποΈ SQLite database
- π Master password
- π Vault locking
- π Local API
- π₯οΈ Web interface
I wanted to create a project that was more than a simple Python script.
PyVault is also a way for me to learn how different parts of a real application work together:
- Python
- Cryptography
- Databases
- APIs
- Authentication
- Security
- Software architecture
- Performance testing
Instead of only following tutorials, I want to build the project myself, encounter problems, research solutions and document the entire process.
The architecture below shows both the current project and the features planned for the future.
flowchart TD
User["π€ User"]
PyVault["π PyVault"]
CLI["π₯οΈ CLI<br/>CURRENT"]
GenerateKey["π Generate Key<br/>CURRENT"]
AddPassword["π Add Password<br/>CURRENT"]
ListPasswords["π List Passwords<br/>CURRENT"]
DecryptPassword["π Decrypt Password<br/>CURRENT"]
Fernet["π Fernet Encryption<br/>CURRENT"]
KeyFile["π key.txt<br/>CURRENT"]
SecretFolder["π secret/<br/>CURRENT"]
Search["π Search Passwords<br/>CURRENT"]
Delete["ποΈ Delete Password<br/>CURRENT"]
Export["π€ Export Passwords<br/>CURRENT"]
Tests["π§ͺ Unit Tests<br/>CURRENT"]
Benchmark["π Benchmark<br/>CURRENT"]
MasterPassword["π Master Password<br/>PLANNED"]
Vault["π Vault System<br/>PLANNED"]
SQLite["ποΈ SQLite Database<br/>PLANNED"]
API["π Local API<br/>PLANNED"]
FastAPI["β‘ FastAPI<br/>PLANNED"]
Web["π₯οΈ Web Interface<br/>PLANNED"]
User --> PyVault
PyVault --> CLI
CLI --> GenerateKey
CLI --> AddPassword
CLI --> ListPasswords
CLI --> DecryptPassword
GenerateKey --> Fernet
GenerateKey --> KeyFile
AddPassword --> Fernet
Fernet --> SecretFolder
DecryptPassword --> SecretFolder
ListPasswords --> SecretFolder
CLI --> Search
CLI --> Delete
CLI --> Export
Search -.-> SQLite
Delete -.-> SQLite
MasterPassword -.-> Vault
Vault -.-> SQLite
API -.-> FastAPI
FastAPI -.-> Vault
Web -.-> API
Tests -.-> PyVault
Benchmark -.-> Fernet
CURRENT = already implemented
PLANNED = planned for a future version
PyVault/
β
βββ commands/
β βββ add.py
β βββ decrypt.py
β βββ delete.py
β βββ export.py
β βββ generate_key.py
β βββ list.py
β βββ search.py
β
βββ secret/ β stores encrypted password files
β
βββ tests/ β unit tests
β
βββ images/
β βββ benchmark.png β encryption/decryption benchmark
β
βββ notebooks/
β βββ benchmark.ipynb β Jupyter benchmark
β
βββ main.py
βββ system_info.py
βββ key.txt
βββ .gitignore
βββ LICENSE
βββ README.md
PyVault currently uses Fernet from the cryptography library.
A key is generated with:
key = Fernet.generate_key()The key is currently stored locally in:
key.txt
When adding a password, PyVault encrypts it before storing it:
fernet = Fernet(key.encode())
encrypted = fernet.encrypt(passwd.encode())The encrypted password is then stored in a dedicated file inside the secret/ folder, one file per website:
secret/
βββ github.txt
Example content of secret/github.txt:
gAAAAAB...
The password itself is not stored directly in the file.
β οΈ This is an early prototype. The current key management system is not considered secure enough for production use.
PyVault includes a benchmark using Jupyter Notebook to measure the performance of Fernet encryption and decryption.
The benchmark tests multiple data sizes, from a few bytes up to 1 MB, and performs multiple iterations for each size.
The results are visualized in the following graph:
The benchmark helps measure how encryption and decryption performance changes as the amount of data increases.
The benchmark notebook is located at:
notebooks/benchmark.ipynb
It can be used to experiment with PyVault's encryption system and compare future implementations.
Clone the repository:
git clone https://github.com/KirobotDev/PyVault.git
cd PyVaultCreate a virtual environment:
python -m venv .venv
.venv\Scripts\activatepython3 -m venv .venv
source .venv/bin/activateInstall dependencies:
pip install -r requirements.txtStart PyVault:
python main.pyYou will see:
S. [Stars Project] 0. [Generate Key (Obliged)] Q. [Leave]
1. [Add Password] 4. [Export (Zipfiles)]
2. [List Pswd] 5. [Delete Passwd]
3. [Decrypt Pswd] 6. [Search Website]
Choices :
Choose:
0
PyVault will generate a Fernet key and save it to:
key.txt
Choose:
1
PyVault will ask for:
Enter your key please thanks... :
Enter name your website Example (github) :
Enter your password :
The password will be encrypted and stored in:
secret/<website>.txt
Choose:
2
PyVault will display all files stored in the secret/ folder, one per website.
Choose:
3
PyVault will ask for:
Enter your key :
Enter the file name example (github.txt) :
It will then display:
Your Password is [ your_password_here ]
Unit tests are available in the tests/ folder.
Run them with:
python -m unittest discover testsThe benchmark is available as a Jupyter Notebook.
Install Jupyter if necessary:
pip install jupyterStart Jupyter:
jupyter notebookThen open:
notebooks/benchmark.ipynb
The benchmark measures:
- Encryption speed
- Decryption speed
- Different data sizes
- Average execution time
- Performance scaling
- Generate Fernet key
- Save key locally
- Encrypt passwords
- Save encrypted passwords (one file per website in
secret/) - Store website information
- Basic CLI
- Decrypt passwords
- List saved entries
- Search passwords
- Delete passwords
- Export passwords
- Load existing key automatically
- Better data structure
- Master password
- Better key management
- Vault locking
- Failed attempt protection
- Security tests
- Threat model
- SQLite
- Database models
- Encrypted database fields
- Data validation
- Database migrations
- Local API
- FastAPI
- Authentication
- API documentation
- Web interface
- Vault dashboard
- Password manager UI
- API integration
- Complete documentation
- Automated tests
- CI/CD
- Security review
- PyPI package
PyVault isn't only a software project.
I also want to document the process of building it.
The documentation will cover:
Idea
β
First prototype
β
Encryption
β
Problems
β
Research
β
Solutions
β
Security
β
Testing
β
Benchmarking
β
Final application
The objective is to show what I learned, what went wrong and how the project evolved over time.
Current version: 0.2.0-dev
PyVault is currently an experimental project.
The project is actively being developed and its architecture may change significantly.
Contributions, suggestions and bug reports are welcome.
If you find a problem, feel free to open an issue.
For larger changes, please open an issue first to discuss the idea.
PyVault is released under the MIT License.
See LICENSE for more information.
xql
GitHub: https://github.com/KirobotDev
Built with Python π
Learning by building.
