SMF·1PASSWORD
Can a prompt replace 1Password?
Security & passwords — password manager
Exhibit tracking slip
Verdict
A local encrypted vault — add, generate, and retrieve logins from one passphrase-protected file — is a one-sitting build. What a personal clone cannot responsibly claim is browser autofill, passkeys, secure sharing with other people, or the recovery path and audited trust a professional security team provides.
Exhibit A — The prompt
Received on30.07.2026Build a local, command-line password vault: one encrypted file on disk holding entries (name, username, password, URL, notes), protected by a single master passphrase. Use a well-vetted encryption library for your language (age, libsodium, or your stack's standard) and a slow key-derivation function (Argon2id) to turn the passphrase into the encryption key — do not write your own crypto. Commands: add, get <name> (copy to clipboard, clear it after ~20 seconds, never print the password to the terminal by default), list, generate <length>, edit, delete. Add a one-off import script that reads a 1Password CSV export and creates the matching entries, so migrating in is a single command. Everything stays local: no server, no account, no telemetry — a 'backup' is just a copy of the encrypted file, which is already safe to put in any cloud drive since it's encrypted at rest.
Do not build browser autofill, passkey support, or secure sharing between people — those need a browser extension and a sync/sharing backend respectively, and that is real scope beyond a personal CLI tool. If any of those three matter to you, say so plainly in the README and point at Bitwarden or KeePassXC instead of pretending this replaces them.
Opening prefills the prompt — press enter to run it.
Exhibit B — What you lose
- B.1 browser and mobile autofill
- B.2 passkey support
- B.3 secure sharing with other people
- B.4 account recovery if you forget the master passphrase
- B.5 independent security audits and breach-watch alerts
Prior art
Exhibit C — Why people still pay: security/trust/cross-platform
Password managers are one place where a professionally audited security team is worth more than the subscription fee — the downside of a mistake is much larger than a few dollars a month.
Questions
Can I import my existing 1Password vault?
Yes for the raw data — 1Password exports a CSV, and the prompt includes an importer for it. What doesn't come across: passkeys, saved 2FA codes tied to their vault, and anything shared with other people.
Will it work on my phone?
Not usefully. There's no mobile app in this build and no browser autofill, so you'd be typing passwords by hand on a phone keyboard — which defeats the point. This is realistically a desktop tool.
What does it cost to run?
Nothing beyond the machine you already own — no hosting, no API key, no subscription. The only cost is your own time if something goes wrong.
What's the one thing that doesn't survive the rebuild?
Recovery. 1Password can help you back into your account with a Secret Key and account recovery; this vault has no recovery path at all. Lose the master passphrase and the encrypted file is permanently unreadable, with nobody to call.
Related tools
Receipt