Skip to content

Apex Documentation

Apex is a local-first, end-to-end encrypted suite for your most sensitive secrets — passwords, TOTP codes, and SSH/GPG keys. Its defining choice: your vault lives on your phone and never on a server. Other devices receive one credential at a time, end-to-end encrypted and approved with a fingerprint.

  • Apex Password — the mobile vault and trust anchor. Stores, generates, and autofills credentials, and approves browser logins on-device. Works offline.
  • Apex Portal — a browser extension that requests a single credential from your phone per login. It never holds the vault. (Coming soon.)
  • Apex Relay — a content-blind message router that forwards opaque, end-to-end encrypted payloads between your devices. Self-host it or use the managed instance. See Self-hosting the relay.
  • Apex Agent — an SSH/GPG agent for your desktop where the private keys stay on your phone. (Coming soon.)
  • Security model — the cryptographic primitives and where keys live.
  • Threat model — what Apex defends against, including supply-chain attacks, and what it explicitly does not.
  • Cold Vault Protocol — how optional, self-custodied encrypted backups work.
  1. The phone is the trust anchor. It has a secure enclave, biometric locks, and isn’t plugged into arbitrary peripherals.
  2. No server-side vault. There is no encrypted vault blob on any server — ours or yours — to breach or be compelled to hand over.
  3. Least privilege over the wire. The laptop receives the one credential it needs, in memory, for one submission — then it’s wiped.
  4. Standard primitives only. No proprietary cryptography. Everything is built on algorithms the community already trusts.