Sesame: Open Source Passwords, 2FA and Recovery
Your passwords.
Your computer.
Import your vault and keep passwords, 2FA codes, and recovery details together. Sesame never sees your vault, and the whole app is open source.
**Sesame vault**Fictional test data.Click to view full size.
**Sesame vault**Fictional test data
!Image 1: Sesame desktop vault with a login selected
Everything important in one place.
Passwords, 2FA codes, recovery details, and backups.
Move your vault.
Import 15 formats. Review every change before saving.
**Security checkup**Each result links back to the affected login. Test data shown.Click to view full size.
**Security checkup**Fictional test data
!Image 2: Sesame security checkup showing actionable account results
**One login, all the sign-in details**Username, password, 2FA, website and optional recovery details stay together.Click to view full size.
**One login, all the sign-in details**Fictional test data
!Image 3: Sesame desktop vault with a login selected
Sign in from one view.
Copy passwords, read 2FA codes, and find recovery details.
**Browser extension:** packaged for Chrome, Edge, and Firefox, not submitted to the stores yet.
Beta
Ready to test
Vault, imports, 2FA, checks, Windows Hello and PIN unlock, document attachments, backup, and export.
Gated
Built, not yet shipped
Browser extension, in-app updates, and Sync.
Planned
Coming later
Mobile, passkeys, sharing, and emergency access.
Read it, build it, run it yourself.
All of it is AGPL-3.0-or-later. A password manager asks for real trust, so you get all of the code.
147 commits in the last 30 days, as of 22 August 2026.
**sesame-desktop**The Windows app and its Rust vault core.Rust 78 commits**sesame-server**The vault-blind Go API, account portal, and admin interface.Go 34 commits**sesame-website**This site. Static, and it reads nothing you cannot see here.CSS 11 commits**sesame-browser-extension**The Chrome, Edge, and Firefox extension.TypeScript 24 commits
Build the app yourself
The desktop app builds from source with Node, Rust, and the Windows WebView2 runtime. A vault from your own build opens like any other.
Host the server yourself
The API, account portal, and admin interface come from one repository with PostgreSQL. The desktop app works fine without them.
Nothing to opt out of
No analytics, no ads, and no third-party scripts. The Content-Security-Policy is in the source too.
Your vault never reaches our servers.
Encryption, checks, 2FA, and backups run in the Windows app.
- Vault file**Your device**
- Master password or unlock secret**Your device**
- Imported password-manager export**Your device**
- Website account email and password hash**Sesame website**
- Product and release information**Sesame website**
Public beta.
Anyone can download Sesame for Windows. The independent review is still pending, so keep a separate backup of anything you cannot afford to lose. It is free during the beta.
Public download Available
Supported platform Windows
Website account Optional
Sesame Sync Not available
Account registration Open
Browser extension Packaged, not submitted
A website account covers beta access, signed downloads, licences, connected-device management. It never holds a vault.