authbox
Zero-knowledge password manager with MCP credential gateway. BIP-39 seed phrase recovery, deterministic passwords, policy-gated AI agent access with scope, rate limits, time windows, and step-up approval. Supports 70+ API key providers with hash-chain audit trail.
README
<p align="center"> <img src="outputs/launch-kit/01-hero.png" alt="Auth Box" width="720" /> </p>
<p align="center"> <strong>Your Keys. Your Identity. Unstoppable.</strong> </p>
<p align="center"> <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-blue.svg" alt="MIT License" /></a> <img src="https://img.shields.io/badge/tests-131%20passing-brightgreen" alt="Tests" /> <img src="https://img.shields.io/badge/build-passing-brightgreen" alt="Build" /> <img src="https://img.shields.io/badge/Go-1.22-00ADD8?logo=go" alt="Go" /> <img src="https://img.shields.io/badge/Next.js-15-black?logo=next.js" alt="Next.js" /> <img src="https://img.shields.io/badge/React-19-61DAFB?logo=react" alt="React" /> </p>
The password manager that works even if we disappear. 24 words = all your passwords. No email, no account, no server dependency.
Why Auth Box
Every password manager asks you to trust them. Auth Box asks you to trust math.
- No Email Required -- Create a vault in 45 seconds. Just a seed phrase and a master password.
- Survive Without Us -- Your vault is encrypted with keys derived from your seed phrase. Even if Auth Box ceases to exist, your passwords remain yours.
- Passwords Without Storage -- Derive passwords deterministically from your seed + site name. Your vault can literally be empty.
- AI Agent Gateway -- Give AI assistants controlled access to credentials via MCP protocol, with policy-gated, auditable delegation.
- Import Everything -- Migrate from 13 sources: Apple, Google, Chrome, Edge, Firefox, 1Password, Bitwarden, LastPass, Dashlane, KeePass, Samsung Pass, NordPass, Enpass.
- AI Infrastructure Hub -- Manage API keys for 70+ providers (OpenAI, Anthropic, AWS, Stripe...). Drag-drop .env files to auto-import. One-click health checks verify keys are valid.
- Arweave Permanent Storage -- Archive your encrypted vault to Arweave for permanent, decentralized backup. Recovery works even without Auth Box servers.
The Unstoppable Promise
You trust your crypto to 24 words. Why not your passwords?
Auth Box uses the same proven model as Bitcoin wallets:
seed phrase (24 words)
-> master key (PBKDF2-HMAC-SHA512)
-> vault encryption key
-> sync encryption key
-> per-agent delegation keys
-> deterministic passwords (no storage needed)
If you have your seed phrase, you have everything. No server. No company. No dependency.
Screenshots
<p align="center"> <img src="outputs/launch-kit/02-create-vault.png" alt="Create Vault" width="360" /> <img src="outputs/launch-kit/03-login-srp.png" alt="SRP Login" width="360" /> </p>
<p align="center"> <img src="outputs/launch-kit/04-restore.png" alt="Restore from Seed" width="360" /> </p>
Quick Start
# Install dependencies
pnpm install
# Start development
make dev # Postgres + Redis + Web
make dev-api # Go API
make dev-full # Everything at once
- Web app: http://localhost:3010
- API: http://localhost:4010
Architecture
Client (holds all keys) Server (encrypted blobs only)
+-----------------------------+ +---------------------------+
| Web App Extension | E2E | Auth (SRP-6a) |
| (Next.js) (Chrome MV3) | ---> | Vault (encrypted CRUD) |
| | | Agents + Policies (JSONB) |
| @authbox/crypto (seed+HD) | | Audit (hash chain) |
| MCP Gateway (WebSocket) | | PostgreSQL + Redis |
+-----------------------------+ +---------------------------+
Zero-knowledge: The server stores only encrypted blobs. It cannot decrypt anything.
Unstoppable Mode: The server is optional. Your vault works offline with keys derived from your seed phrase.
Monorepo Structure
packages/
crypto/ @authbox/crypto -- BIP-39 seed, HD keys, Argon2id, AES-256-GCM, SRP-6a
shared/ @authbox/shared -- Types, validation schemas
mcp-protocol/ @authbox/mcp-protocol -- AI gateway (MCP over WebSocket)
apps/
web/ @authbox/web -- Next.js 15, Vault Onyx design system
console/ auth-box-console -- Public portal + admin dashboard
extension/ auth-box-extension -- Chrome MV3 (popup + content + background)
services/
api/ auth-box-api -- Go API (chi v5, pgx v5, DDD layered)
Encryption
| Layer | Primitive | Purpose |
|---|---|---|
| Seed | BIP-39 (24 words) | Sole recovery mechanism |
| Master Key | PBKDF2-HMAC-SHA512 | Key derivation from seed |
| Sub-keys | HD derivation (BIP-32 style) | vault / sync / agent / auth / derive |
| Vault | AES-256-GCM | Encrypt all vault items |
| Auth | SRP-6a | Mutual authentication (optional server) |
| Passwords | Deterministic derivation | seed + site = password (no storage) |
Comparison
| Feature | 1Password | Bitwarden | LessPass | Apple Keychain | Auth Box |
|---|---|---|---|---|---|
| Self-sovereign (seed phrase) | No | No | No | No | Yes |
| Works without server | No | Self-host only | Yes | Apple only | Yes |
| Deterministic passwords | No | No | Yes | No | Yes |
| Full vault + deterministic hybrid | No | No | No | No | Yes |
| AI Agent gateway (MCP) | No | No | No | No | Yes |
| Open source client | No | Yes | Yes | No | Yes (MIT) |
| Import sources | Few | 8 | 0 | Apple only | 13 + .env auto-import |
| AI API key management | No | No | No | No | 70+ providers |
| Company disappears | Data at risk | Self-host option | OK (stateless) | Locked | 24 words = recovery |
Tests
Latest verified baseline (2026-03-23):
Go API: PASS 28 tests (SRP/TOTP, rate limiter, security middleware, audit chain)
Crypto: PASS 51 deterministic tests; 2 live Arweave probes opt-in
E2E: 65/65 Real SRP/TOTP login + vault/agent/audit/session CRUD + security
Build: PASS 7/7 turbo packages, 0 errors
Security audit: 12 findings fixed (TOTP bypass, timing attack, session scoping, CORS hardening...) Performance audit: 11 optimizations applied (composite indexes, cache limits, rate limiter refactor...)
Key Commands
| Command | Description |
|---|---|
make dev |
Start infra + web dev server |
make dev-api |
Start Go API |
make dev-full |
Start everything |
make build |
Build all packages |
make test |
Run all tests |
make test-api |
Run the Go API test suite |
make test-crypto |
Run the crypto package test suite |
npx tsx scripts/e2e-test.mjs [api-base] |
Run E2E suite against a real API |
Contributing
See CONTRIBUTING.md for development setup and guidelines.
Auth Box is MIT licensed. PRs welcome.
License
MIT -- Use it, fork it, build on it.
Maurice | maurice_wen@proton.me
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。