coffre · /kɔfʁ/ · n.m. — French for vault, strongbox, chest.

One vault. Every kind of secret.

TOTP codes, passwords, SSH keys, API tokens, env bundles — end-to-end encrypted, synced across your devices, isolated per project, self-hostable by design.

Your secrets never leave you.

Coffre seals every code, password, and secret on your device before any of it touches the network. The server is an honest-but-curious relay — it routes ciphertext, never plaintext.

  1. Device A

    Seals with your Master Key.

  2. Relay

    Stores ciphertext, orders operations, fans out push.

  3. Device B

    Unseals locally, reveals what you asked for.

One vault, every kind

TOTP codes, passwords, SSH keys, API tokens, env bundles, certs, notes. Every kind gets the same zero-knowledge seal.

Contexts

Crypto-isolated workspaces — one per project, one per team. Each with its own key, wrapped by yours. Designed to share selectively later.

Secrets at runtime

coffre exec injects a context’s secrets as environment variables. No .env on disk, no secrets in shell history.

Self-hostable

Single Docker image. Postgres backend. Deploy to OVHCloud, Coolify, or your laptop.

Device approval

Every new device is rejected until an existing one signs its Ed25519 approval. No blind trust.

Recovery keys

192-bit recovery codes seal a second wrap of your Master Key. Lose your password, keep your vault.

Coffre Cloud — coming 2026

Coffre, without the setup.

All your codes and secrets, synced across every device. Sign in once and you're done — no server to run, no maintenance, no weekend tinkering. We handle the boring part, you just use it.

Basic: unlimited TOTP for €0.99 / month. Pro adds secrets.

€3.99 / month · €39.99 / year

Open source, and staying that way.

Every byte of Coffre lives on GitHub under AGPL-3.0. Read it, fork it, audit it, host it, send a patch. The license has teeth on purpose: run a modified copy as a service and you owe your users the same freedom. No proprietary rug-pull — now or later.

Self-host in thirty seconds.

If you trust yourself with a Docker host, you can trust yourself with your second factors.

Read the self-host guide
bash
git clone https://github.com/maiko/coffre && cd coffre
cp .env.example .env
# Edit .env and replace every "change-me" value first.
docker compose --env-file .env -f docker/docker-compose.yml up -d
curl http://localhost:8080/health

A vault you can pipe.

One binary for every item type — TOTP codes, passwords, SSH keys, env bundles. Pair a device, inject secrets into your app as env vars, pipe codes into scripts, import from Aegis or Bitwarden. Same CLI whether you hit Coffre Cloud or your self-hosted server.

CLI reference
bash
# Pair this machine with your vault (approve on another device).
$ coffre login --email you@example.com

# Add any item type — TOTP, password, SSH key, env bundle.
$ coffre add --uri "otpauth://totp/GitHub:you?secret=JBSWY3DPEHPK3PXP&issuer=GitHub"
added GitHub:you

# Pipe a TOTP straight into 2FA-protected commands.
$ npm publish --otp "$(coffre code npm)"

# Run any app with a context's secrets injected as env vars.
# No .env on disk. No secrets in shell history.
$ coffre exec -c app-prod -- node server.js

Questions.

Is Coffre just for 2FA codes?
No. Coffre is one vault for TOTP codes, passwords, SSH keys, X.509 certificates, API tokens, env bundles, plain notes, and small files. Every kind gets the same zero-knowledge seal.
What's a context?
A crypto-isolated workspace inside your vault. One for Work, one per Client, one per app-environment — each with its own encryption key wrapped by your Master Key. Designed from day one so individual contexts can be shared with teammates in a future release without opening your whole vault.
Has Coffre been audited?
Not yet externally audited. Treat V1 as beta. The crypto is standard (XChaCha20, Argon2id, X25519, Ed25519); the integration is the unknown.
iOS and Android apps?
On the roadmap. The crypto core compiles to native via UniFFI and to WebAssembly for the web — native clients will reuse it.
Does the server see my codes?
No. The server stores ciphertext, routes operations, and fans out notifications. It never holds a key that can decrypt your vault.
How does device pairing work?
A new device generates a keypair and asks to join. An existing, approved device signs an Ed25519 approval with domain-separated bytes. Until that approval lands, the new device sees nothing.
What if I lose my password?
Your 192-bit recovery code seals a second wrap of your master key. Keep it offline, somewhere durable. Lose both and your vault is gone — that's the tradeoff for a server that can't help you.
Why AGPL?
Network-service clause. If you run a modified copy of Coffre for other people, you have to share your changes. Keeps forks honest and keeps Coffre's operator model defensible.