Store API keys, auth tokens, database URLs, and .env values with AES-256-GCM encryption. Master password never leaves your browser. Nothing is transmitted. Nothing is stored on our servers.
Choose a strong master password. This is the only way to decrypt your vault — if you forget it, your data is unrecoverable. There is no reset flow, because we have no way to reach your data.
If you've exported a vault from another browser or device, you can import the encrypted file here. You'll need the master password used to create it.
Your encrypted vault is loaded. Enter your master password to decrypt in this browser session.
There is no recovery. Septim Vault does not have a way to reset your password — the master password is what derives the encryption key, and we never see it. Your only options are to restore from a backup file (if you have one) or destroy this vault and start fresh.
Add your first API key or token to get started.
Name it something you'll recognize. The value is encrypted individually when saved.
Actions here are permanent. Be sure you have a backup before destroying anything.
We'll re-encrypt every secret in your vault with a new key. This happens entirely in your browser.
Free tier caps at 3 secrets and no export. Lifetime unlock removes both and gets every future update.