Apex Documentation
Apex is a local-first, end-to-end encrypted suite for your most sensitive secrets — passwords, TOTP codes, and SSH/GPG keys. Its defining choice: your vault lives on your phone and never on a server. Other devices receive one credential at a time, end-to-end encrypted and approved with a fingerprint.
The suite
Section titled “The suite”- Apex Password — the mobile vault and trust anchor. Stores, generates, and autofills credentials, and approves browser logins on-device. Works offline.
- Apex Portal — a browser extension that requests a single credential from your phone per login. It never holds the vault. (Coming soon.)
- Apex Relay — a content-blind message router that forwards opaque, end-to-end encrypted payloads between your devices. Self-host it or use the managed instance. See Self-hosting the relay.
- Apex Agent — an SSH/GPG agent for your desktop where the private keys stay on your phone. (Coming soon.)
Start here
Section titled “Start here”- Security model — the cryptographic primitives and where keys live.
- Threat model — what Apex defends against, including supply-chain attacks, and what it explicitly does not.
- Cold Vault Protocol — how optional, self-custodied encrypted backups work.
Design principles
Section titled “Design principles”- The phone is the trust anchor. It has a secure enclave, biometric locks, and isn’t plugged into arbitrary peripherals.
- No server-side vault. There is no encrypted vault blob on any server — ours or yours — to breach or be compelled to hand over.
- Least privilege over the wire. The laptop receives the one credential it needs, in memory, for one submission — then it’s wiped.
- Standard primitives only. No proprietary cryptography. Everything is built on algorithms the community already trusts.