# Build brief — a focused alternative to 1Password

> **Verdict:** Partly, if you narrow it · **Buildability:** 63/100 · **Category:** Security
> **Source:** https://www.canitbevibecoded.com/1password
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from 1Password. Verify current pricing and capabilities before acting.

## Context

**1Password** — Password manager for logins, passkeys, secrets, and secure sharing. It currently costs $2.99/mo.

A basic encrypted vault is buildable, but browser autofill, mobile apps, passkeys, sharing, recovery, audits, and trust make this a dangerous thing to replace casually.

This brief describes a focused, single-operator replacement for the part of 1Password that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Create a local encrypted vault, generate passwords, search entries, and optionally sync the encrypted database with a cloud drive.

- Prototype the workflow, but rely on audited libraries and established security tools.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Strong encryption library.
- Browser extension if autofill matters.
- Mobile/desktop storage.
- Backup plan.

### Data and integrations

- Secure key derivation.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a local encrypted password vault to replace 1Password, CLI-first. Requirements:

- A single-binary CLI in Go using filippo.io/age for encryption and Argon2id
  (golang.org/x/crypto) to derive the key from my master passphrase. Use the
  library primitives exactly as documented, invent no crypto.
- The vault is one encrypted file at ~/.vault/vault.age holding JSON entries:
  name, username, password, URL, notes, updated timestamp.
- Commands: add, get <name> (copies to clipboard, clears it after 20 seconds),
  ls, gen (32-char random password), edit, rm.
- Fuzzy name matching on get; never print a password to stdout unless --show
  is passed.
- vault backup writes a date-suffixed copy of the encrypted file to a folder
  set in .env; it is already encrypted, so any cloud drive can sync it.
- Import from a 1Password CSV export so I can migrate in one command.
- Everything local: no server, no accounts, no telemetry.
- Out of scope: browser autofill, passkeys, and secure sharing. Those are why
  people pay 1Password; if I need them the honest move is KeePassXC or
  Bitwarden, say exactly that in the README.
- README: a five-line threat model, how key derivation works, and a warning
  that losing the master passphrase loses everything, there is no recovery.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Browser/mobile autofill.
- Passkey support.
- Secure sharing.
- Recovery.
- Trust, audits, and counterparties matter more than feature parity.
- The last 20 percent is sync, migration fidelity, speed, and edge cases.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.

## Risk

**High consequence.** Use this as a prototype or personal aid. Keep a qualified human and an established provider in the loop for consequential decisions.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [KeePassXC](https://github.com/KeePassXreboot/keepassxc) — Mature open-source local password manager and the safest DIY-adjacent alternative

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/1password
