Your keys. Your control.

ClaraKey is an encrypted vault that lives on a USB drive you carry: authenticator codes, recovery codes, passwords, API tokens, SSH keys, notes and files. It never goes online. No cloud, no account, no subscription.

Free & open source (MIT)Fully offlineRuns from USB
0
network connections, ever
7 kinds
of secrets in one vault
Argon2id
+ AES-256-GCM encryption
$0
no subscription, no account
Features

Everything you'd hate to lose, in your pocket

The codes and keys that unlock your accounts, kept where only you can reach them: an ordinary USB drive, encrypted with your master password.

๐Ÿ”ข

Authenticator (2FA)

Time-based codes with a live countdown and one-click copy. Paste an otpauth:// link or type the secret. SHA-1, SHA-256 and SHA-512, 6 to 8 digits.

๐Ÿงพ

Recovery codes

Keep each account's backup codes together and mark the ones you've used.

๐Ÿ”‘

Passwords

With a strong generator (8 to 128 characters, the character sets you choose) using your system's secure random source.

๐Ÿงฉ

API tokens & SSH keys

Store API credentials and import SSH private keys. Nothing is installed into ~/.ssh; export is always explicit.

๐Ÿ“„

Encrypted files

Signing keystores, certificates, GPG keys and 2FA backup files, up to 1 MB each. Just drag them onto the window. Each one's fingerprint is checked on every unlock.

๐Ÿ“

Secure notes

Anything else that belongs behind a lock, with created and modified dates.

โฑ๏ธ

Locks itself

Auto-lock after inactivity (5 minutes by default) and a clipboard that clears itself after you paste (30 seconds by default).

๐Ÿ›Ÿ

Hard to lose

Every save is verified and atomic, the previous version is kept, and encrypted backups can be restored after a check.

The app

Clean, calm, and dark

A native Linux app that opens straight from your drive.

Screenshots use a demo vault with made-up accounts.

How it works

A vault you can hold in your hand

Put it on a drive

Extract ClaraKey onto any USB drive. Everything it needs comes with it, Python and GTK included.

Pick a master password

At least 12 characters; several random words are best. It's the only key to your vault.

Add your secrets

2FA codes, recovery codes, passwords, keys, notes and files. Each change is encrypted and saved right away.

Lock and go

Lock the vault, eject the drive and take it with you. Plug it into a Linux PC and unlock it there.

Get it

Download, extract, run.

One portable bundle for Linux (x86_64). Nothing to install on the computer.

Terminal (Linux)
# extract the download onto your USB drive $ tar -xzf ClaraKey-linux-x86_64.tar.gz -C /media/you/USB $ cd /media/you/USB/ClaraKey $ ./ClaraKey # optional: a one-click ClaraKey icon on this PC (never the vault) $ ./add-to-this-pc.sh --pin

๐Ÿ’พ ClaraKey for Linux

Portable bundle for x86_64 desktops (Wayland or X11). Check it against the .sha256 file next to it on the release page.

Download from GitHub

๐Ÿงท Good habits

  • Lock the vault before you eject the drive.
  • Keep an encrypted backup on a second drive (Settings & backups).
  • Only unlock it on computers you trust.
Privacy & security

Offline by design. Encrypted by default.

ClaraKey never touches the network. Read exactly what's stored where โ†’

No network at all

No cloud sync, no update checks, no telemetry, no time server. Your vault never leaves your drive unless you copy it.

Strong encryption

Your master password becomes a key with Argon2id (64 MiB, 3 passes); everything, titles and notes included, is sealed with AES-256-GCM.

No backdoor

There's no password recovery, for anyone. If you lose the master password, the vault stays locked forever. Keep a backup.

Read every line

MIT licensed, with a written threat model and vault format.

FAQ

Questions, answered

Is ClaraKey really free?

Yes. It's free and open source under the MIT license: no subscription, no account, no paid tier.

What if I forget my master password?

Then the vault can't be opened, by you or anyone else. That's what makes it safe. Choose a passphrase you'll remember (several random words work well) and keep an encrypted backup.

What if I lose the USB drive?

Whoever finds it sees only an encrypted file. Without your master password it's unreadable. To avoid losing your secrets too, keep an encrypted backup on a second drive.

Does it replace a hardware security key?

No. ClaraKey is a software vault, not a FIDO2 or WebAuthn key like a YubiKey, and it can't protect you on a computer that's already compromised. It's a safe, portable home for the codes and secrets you'd otherwise scatter across apps and text files.

Which computers does it run on?

Linux on x86_64 with a desktop (Wayland or X11). Windows and macOS aren't supported yet.

Can it import my existing 2FA accounts?

Yes, by pasting each account's otpauth:// link or typing its secret. Scanning QR images isn't supported yet.

Has it been audited?

Not independently yet. It has automated tests and a real-desktop acceptance run, and its design is documented in the repository. Read the security notes before trusting it with everything.

Who makes ClaraKey?

Created by DevIgnite ร— The Wider Lens Initiative Project, the makers of Clara, ClaimScout and C Terminal. Questions or feedback: clarakey@thewiderlens.info. Issues and contributions are welcome on GitHub.

Carry your keys. Keep your control.

Free, offline and yours. Put your codes and secrets on a drive only you can open.