Secure, hardware-bound desktop password manager. Built for privacy. Engineered for extensibility. Completely open source.
Read the documentation on the official website.
- Data Encryption: Sensitive data is encrypted using the
AES-256-GCMauthenticated encryption algorithm. - Hardware Binding: Hardware-bound sessions are cryptographically tied to a unique machine ID, preventing them from being reused on unauthorized devices.
- Zero-Knowledge Architecture: Sensitive data is encrypted and processed locally and does not leave your machine by default.
- Secure Data Portability: Import and export JSON data with encrypted sensitive values.
- Modern Interface: Clean, minimal design with fluid transitions and subtle visual feedback.
- Keyboard-Driven Navigation: Command palette and keyboard shortcuts for efficient navigation and faster access to application actions.
- Accessibility: Designed with accessibility in mind.
- Plugin System: Extensible architecture for integrating additional functionality through plugins.
Download WebStray Authenticator for Windows from GitHub Releases.
Build from source for any supported platform using nw-builder.
- Clone the repository
git clone https://github.com/webstraycom/authenticator.git
cd authenticator- Install dependencies
npm install- Build for your OS
Use the following commands to create a production-ready executable:
Windows (x64):
npx nw-builder . --mode=build --platform=win --arch=x64 --outDir=./dist/winmacOS:
# Intel
npx nw-builder . --mode=build --platform=osx --arch=x64 --outDir=./dist/mac
# Apple Silicon
npx nw-builder . --mode=build --platform=osx --arch=arm64 --outDir=./dist/macLinux (x64):
npx nw-builder . --mode=build --platform=linux --arch=x64 --outDir=./dist/linuxRun the application in development mode:
- Start the development server
npm run dev- Launch the desktop application
In a new terminal, run:
npm startWe take the security of WebStray Authenticator seriously. If you find a security vulnerability, please help us by reporting it responsibly.
- Standard Vulnerabilities: For general security bugs, please open a new issue using the
security reportlabel. - Critical Vulnerabilities: Please report security issues responsibly and avoid publicly disclosing sensitive exploit details before a fix is available.
WebStray Authenticator is provided "as is", without warranty of any kind.
By using this software, you acknowledge and agree that:
- User Responsibility: You are solely responsible for the safety of your master password. If you lose it, your data cannot be recovered.
- Third-Party Plugins: The use of community-made plugins is at your own risk. Plugins have the technical capability to access your decrypted data. We are not responsible for any data leaks or security breaches resulting from their use.
- No Liability: The developers shall not be held liable for any data loss, hardware damage, or security breaches arising from the use of or inability to use this software.
- Development Status: This project is currently in beta. While we prioritize security, please use it at your own risk.
Always audit the source code of any plugin before installation and maintain secure backups.
This project is licensed under the MIT License. See the LICENSE file for details.