CabinetPass Vault Viewer Offline · nothing leaves this page

Decrypt your vault in the browser

An independent, open-source implementation of the CabinetPass format. Choose an encrypted backup (.cpv), enter your master password, and everything is decrypted locally with WebCrypto and Argon2id. Use it to verify the app’s encryption — or to read your data without the app.

Drop a .cpv file here, or click to choose
Settings › Export Encrypted Backup, or vault.cpv from your Google Drive app folder
What happens
  1. 1. Derive master key
    Argon2id with the salt and cost stored in the file
  2. 2. Unwrap vault key
    AES-256-GCM, AAD "cabinetpass.dek.v1"
  3. 3. Decrypt vault
    AES-256-GCM, AAD "cabinetpass.vault.v1"
  4. 4. Decompress
    gzip → JSON
  5. 5. Files on demand
    per-file key, AAD "cabinetpass.file.v1:<id>"
  • No network: enforced by Content-Security-Policy.
  • Nothing is stored. Closing the tab or Lock clears everything.
  • Format spec: FORMAT.md · source: GitHub
  • No backup handy? Try the sample backup (password correct horse battery staple).
Decryption log