TechNewsReel
Live

Sesame Debuts Local-First, Open-Source Password Manager in Public Beta

The new 'vault-blind' architecture decouples account management from credential storage to maximize user privacy.

TechNewsReel Newsroom · August 28, 2026

Sesame has launched a local-first, open-source password manager designed to keep user vaults on the device by default. The software is currently in public beta for Windows, while Linux users can access the tool by building it from source.

Built using the Tauri framework, the desktop application utilizes Rust for its vault core and Svelte for the user interface. To facilitate migration, the software supports importing data from 15 different password manager formats. While a browser extension has been packaged for Chrome, Edge, and Firefox, the developers noted that it has not yet been submitted to official browser stores. The project is licensed under AGPL-3.0-or-later.

A 'Vault-Blind' Approach

Sesame enters a market largely dominated by cloud-synced services such as 1Password and Bitwarden. To differentiate itself, Sesame employs a "vault-blind" architecture. The account server, written in Go, is designed to handle account management and metadata without ever receiving the user's vault, master password, or encryption keys. This separation allows users to operate the application entirely offline or link an account for signed updates and metadata without moving the vault's physical location to a remote server.

Implications for Data Sovereignty

For security-conscious users, this architecture significantly reduces the risk associated with central server breaches, as the hosted service does not possess the credentials it helps manage. By combining an open-source codebase with a local-first philosophy, Sesame aligns itself with the "sovereign data" movement, which prioritizes user control over personal information over the convenience of seamless cloud synchronization.

Current Status and Outlook

Because the software is in public beta, it is currently positioned as an experimental tool rather than a production-ready replacement for established industry standards. Users should monitor the project's development on GitHub as it matures. While the core functionality is available, the official submission of browser extensions to app stores remains a key milestone for broader adoption. This approach ensures that the user remains the sole custodian of their sensitive data, shifting the trust model from the service provider back to the individual.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.