storage-p

storage-p vs Apple Passwords: zero-knowledge & self-hosted

Both storage-p and Apple Passwords keep secrets safe, but they take different routes. storage-p is a self-hosted, zero-knowledge vault you operate yourself; Apple Passwords is a browser's built-in password feature. Here is a factual side-by-side.

At a glance

  1. Hosting: storage-p runs self-hosted on your own server; Apple Passwords is a managed cloud service.
  2. Encryption: storage-p is zero-knowledge — your key is derived in the browser with Argon2id and the server only ever stores XChaCha20-Poly1305 ciphertext.
  3. Beyond passwords: storage-p also stores SSH/TLS keys, API keys and TOTP, and generates Ed25519 SSH keys and self-signed certificates client-side.
  4. Integrations: storage-p issues scoped API tokens whose every read can require your in-app or Telegram confirmation.
  5. Apple Passwords does not offer a self-hosted server, so your data lives with the vendor; storage-p you run and own end to end.

The core difference

Apple Passwords is handy for filling website logins, but it is tied to the browser and stores little beyond passwords. storage-p is a dedicated, portable vault for passwords, SSH/TLS keys, API keys and TOTP, synced across devices without ever exposing plaintext.

Where storage-p stands out

The server never sees your master password or plaintext — encryption, decryption, key generation and the security audit all run on your device. You can store and generate SSH/TLS material, share via burn-after-read links or end-to-end sealed-box, and grant integrations narrow, auditable access instead of all-or-nothing exports.

When Apple Passwords may fit better

If you only need to autofill logins inside Apple Passwords and want zero setup, it is the most frictionless option.

Switching from Apple Passwords

Moving is straightforward: Apple Passwords can export your entries to a CSV file, which storage-p imports as a generic CSV. See the step-by-step migration guide linked below.