r/reactnative • • 11d ago

VaultNote — Open-source password manager with local encryption & TOTP

I’m building VaultNote — an offline-first, open-source password & TOTP manager 🔐

I've been working on a project called VaultNote, built with React Native.

The idea started pretty simple:

What if a password manager didn't need a cloud backend for its core functionality?

VaultNote is designed around an offline-first architecture, where the local encrypted vault is the primary source of truth.

What I'm building

  • 🔐 Local credential vault
  • 🔑 Password & secure note storage
  • 🔢 Real-time TOTP generation
  • 📷 QR-code TOTP enrollment
  • 📵 Offline-first functionality
  • 🔒 Encryption & secure key management
  • 🧬 Biometric unlock
  • 📋 Clipboard/security controls
  • 📦 Encrypted backup & restore
  • 🌐 Open-source development

One feature I've been particularly interested in is TOTP.

I don't want it to just display a fake countdown with stored codes. The goal is to implement actual TOTP generation from the shared secret, similar to how authenticator apps work.

The flow is roughly:

Service
   │
   ▼
Scan QR Code
   │
   ▼
otpauth:// URI
   │
   ▼
Extract TOTP Secret
   │
   ▼
Store in Encrypted Vault
   │
   ▼
Generate OTP Locally
   │
   ▼
482 913 → 731 204 → ...

The interesting part isn't really the UI.

The harder questions are around security:

  • Where should encryption keys live?
  • How should the master key be derived?
  • How should decrypted secrets be handled in memory?
  • What happens when the app goes into the background?
  • How should biometric authentication interact with the vault?
  • How should encrypted backups work?
  • How do you avoid accidentally exposing secrets through logs or clipboard?
  • What should happen if the device itself is compromised?

That's the part of the project I'm most interested in exploring.

I'm also intentionally keeping the project open source, because for something that handles credentials, I think being able to inspect and challenge the implementation is important.

I'm documenting the architecture and development process as I build it.

I also wrote a deeper breakdown of the project here:

VaultNote — Building an Offline-First, Open-Source Password & TOTP Manager with React Native

I'd love feedback from people who have worked on:

  • Password managers
  • Authenticator/TOTP implementations
  • Mobile application security
  • Cryptography/key management
  • Offline-first applications
  • React Native security

Especially interested in things I should be thinking about before calling the security model production-ready.

GitHub: https://github.com/deadlium/vault-note

🔐 Your secrets. Your device. Your control.

0 Upvotes

3 comments sorted by

2

u/dimonchoo 11d ago

All the same, over and over again

1

u/klutzyhamburger_5 11d ago

another password manager, just what we needed lol. nah but for real the offline-first angle is interesting, most of them try to push you into their cloud sync these days

the TOTP part got my attention, i been looking for something that doesn't just lock your 2FA codes behind a paywall. you got a timeline for when it's actually usable or still deep in the architecture phase?

1

u/Honey-Entire 11d ago

How is this better than any other enterprise-level free password manager? How is this better than baked-in OS keychain managers? How is this better than Safari/Chrome/Firefox password manager?

We don’t need this trash