One vault, every kind
TOTP codes, passwords, SSH keys, API tokens, env bundles, certs, notes. Every kind gets the same zero-knowledge seal.
coffre · /kɔfʁ/ · n.m. — French for vault, strongbox, chest.
TOTP codes, passwords, SSH keys, API tokens, env bundles — end-to-end encrypted, synced across your devices, isolated per project, self-hostable by design.
Coffre seals every code, password, and secret on your device before any of it touches the network. The server is an honest-but-curious relay — it routes ciphertext, never plaintext.
Seals with your Master Key.
Stores ciphertext, orders operations, fans out push.
Unseals locally, reveals what you asked for.
TOTP codes, passwords, SSH keys, API tokens, env bundles, certs, notes. Every kind gets the same zero-knowledge seal.
Crypto-isolated workspaces — one per project, one per team. Each with its own key, wrapped by yours. Designed to share selectively later.
coffre exec injects a context’s secrets as environment variables. No .env on disk, no secrets in shell history.
Single Docker image. Postgres backend. Deploy to OVHCloud, Coolify, or your laptop.
Every new device is rejected until an existing one signs its Ed25519 approval. No blind trust.
192-bit recovery codes seal a second wrap of your Master Key. Lose your password, keep your vault.
Coffre Cloud — coming 2026
All your codes and secrets, synced across every device. Sign in once and you're done — no server to run, no maintenance, no weekend tinkering. We handle the boring part, you just use it.
Basic: unlimited TOTP for €0.99 / month. Pro adds secrets.
€3.99 / month · €39.99 / year
Every byte of Coffre lives on GitHub under AGPL-3.0. Read it, fork it, audit it, host it, send a patch. The license has teeth on purpose: run a modified copy as a service and you owe your users the same freedom. No proprietary rug-pull — now or later.
If you trust yourself with a Docker host, you can trust yourself with your second factors.
Read the self-host guidegit clone https://github.com/maiko/coffre && cd coffre
cp .env.example .env
# Edit .env and replace every "change-me" value first.
docker compose --env-file .env -f docker/docker-compose.yml up -d
curl http://localhost:8080/health One binary for every item type — TOTP codes, passwords, SSH keys, env bundles. Pair a device, inject secrets into your app as env vars, pipe codes into scripts, import from Aegis or Bitwarden. Same CLI whether you hit Coffre Cloud or your self-hosted server.
CLI reference# Pair this machine with your vault (approve on another device).
$ coffre login --email you@example.com
# Add any item type — TOTP, password, SSH key, env bundle.
$ coffre add --uri "otpauth://totp/GitHub:you?secret=JBSWY3DPEHPK3PXP&issuer=GitHub"
added GitHub:you
# Pipe a TOTP straight into 2FA-protected commands.
$ npm publish --otp "$(coffre code npm)"
# Run any app with a context's secrets injected as env vars.
# No .env on disk. No secrets in shell history.
$ coffre exec -c app-prod -- node server.js