# cloudflare/gokey: a vaultless password manager that derives credentials from a master password and a realm

> gokey generates passwords and private keys on demand instead of storing them in a vault. The trade-off is that everything depends on one master password and, for key generation, a seed file you have to back up yourself.

**cloudflare/gokey** — A simple vaultless password manager in Go

- Repository: https://github.com/cloudflare/gokey
- Stars: 2,437 · Forks: 109
- Language: Go
- License: BSD-3-Clause
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/cloudflare-gokey

## What gokey replaces, and who it is for

Most password managers are storage systems. They keep a vault, encrypt it, and the operational work is in backing it up and syncing it between devices. gokey inverts that. The README describes it as a password manager which does not require a password vault: instead of storing passwords, it derives them on the fly from a master password and a realm string, with a resource URL given as the typical realm. Nothing is written to disk unless you ask for it.

The audience is narrow but real. It suits someone who manages many accounts, dislikes trusting a third party with a vault, and can commit one strong master password to memory. It also suits engineers who need deterministic private keys for test fixtures or per-service identities, because the same inputs always produce the same key material. It does not suit anyone who needs to store secrets that were not generated by gokey in the first place.

## How derivation works, and why the realm string matters

In simple mode, the master password and the realm string are the only inputs. The README states that each unique combination of a master password and a realm string produces a unique password, so `example.com` and `example2.com` yield different results from the same master password. There is no state to persist, which is what makes the tool portable: the same binary on any machine reproduces the same output.

The realm is therefore a naming decision, not a lookup key. If you generate a password for `example.com` and later request `www.example.com`, you get a different password, and the README does not describe a canonicalization step that would normalize those two strings. Consistency in how you write realms is part of the operating discipline, not something the tool enforces for you.

The README is explicit about the entropy ceiling in this mode: generated passwords are as strong as the master password, and deriving private keys from the master password alone is considered unsafe, which is why gokey refuses it unless the `-u` flag is supplied. That flag is documented as UNSAFE, and the README frames it as an override for people who really know what they are doing. Treating `-u` as a convenience switch would discard the only entropy guarantee the tool makes in simple mode.

## The seed file mode and what gokey actually encrypts

For higher entropy, gokey accepts a seed file instead of relying on the master password for the generated material. The seed file holds 256 bytes of random data, and per the README it is encrypted with AES-256-GCM using the master password as the key. Because the file is encrypted, the README says it is reasonably safe to store or back up to a third party location such as Google Drive or Dropbox.

The master password does not disappear in this mode, it changes role. It protects the seed file, while the derived passwords and keys come from the seed data. Two secrets now matter: the master password and the seed file. The README states the consequence plainly: if you forget the master password or lose the seed file, you lose all derived passwords and keys. There is no recovery path described, because there is nothing stored to recover from.

The `-skip` option reads a number of bytes to skip when reading the seed file, which lets one blob serve as a source for more than one stream. The README lists the flag but does not document a workflow around it, so anyone relying on it should confirm the behavior against the source before building a scheme on top.

## Installing gokey and generating a first password

The README gives a standard Go install path. With Go installed, the binary lands in `$GOPATH/bin`, which defaults to `$HOME/go/bin`.

```bash
go install github.com/cloudflare/gokey/cmd/gokey@latest
```

The README also points to precompiled binaries in the Releases section for people who do not want a Go toolchain. Once the binary is on your path, the simplest invocation takes a master password and a realm and prints the result to stdout.

```bash
gokey -p super-secret-master-password -r example.com
```

You should see a generated password on stdout. Repeating the same command with the same two values reproduces it, which is the property the whole tool rests on. If you would rather not put the master password in your shell history, the README documents `-P /path/to/password` to read it from a file, and says that if neither a master password nor a password file is provided, gokey asks for it interactively.

To move beyond passwords, create an encrypted seed file first. The README's example writes 256 bytes of random data, encrypted, to the named output path.

```bash
gokey -p super-secret-master-password -t seed -o seedfile
```

With that file in place, key generation becomes possible. This example produces an ECC P-256 private key for the realm `example.com`.

```bash
gokey -p super-secret-master-password -s seedfile -r example.com -t ec256
```

The `-t` flag selects the output type. The README lists `pass` (the default), `seed`, `raw`, `ec256`, `ec384`, `ec521`, `rsa2048`, `rsa4096`, `x25519` and `ed25519`. The `-l` flag sets the number of characters for a password or bytes for a raw stream, defaulting to 10 for `pass` and 32 for `raw`. Output goes to stdout unless `-o` names a path.

## Where gokey breaks down

The failure modes all trace back to the same design choice. Because nothing is stored, nothing can be recovered. A forgotten master password in simple mode means every derived password is gone, and the README says so directly. In seed mode, losing either the master password or the seed file has the same effect.

Rotation is awkward for the same reason. Changing the master password changes every derived password at once, since the master password is an input to every derivation. There is no documented way to rotate one credential while leaving the rest untouched. If you have thirty accounts and you want a new password for one of them, the tool does not offer a per-realm rotation knob; changing the realm string is the lever you have, and that means remembering a new realm for that one site.

The simple mode also caps the strength of everything it produces at the strength of the master password. That is fine for a website password and not fine for a private key, which is why the README gates key generation behind a seed file and marks `-u` as unsafe. A user who wants key material without managing a second file is asking gokey to do something it deliberately refuses.

Finally, gokey generates credentials, it does not store them. Existing passwords from before you adopted it have to live somewhere else, so most users end up running gokey alongside a conventional manager rather than instead of one.

## How this differs from a deterministic password generator like LessPass

LessPass is the closest well-known comparison: it also derives site passwords from a master password plus a site, login and counter, with no vault. The difference is scope. LessPass targets website passwords and folds options such as length and character set into the derivation inputs, so different option sets produce different passwords for the same site. gokey keeps the derivation surface smaller, a master password (or seed) plus a realm, and extends the output space well past passwords into `raw`, ECC and RSA private keys.

That extension is what justifies the seed file. A tool that only makes passwords can treat the master password as sufficient entropy; a tool that emits a 4096-bit RSA key cannot, and gokey's documentation says as much. The cost is that gokey asks you to manage a second artifact that LessPass users do not have to think about. If you only ever need website passwords, the seed file is overhead. If you need reproducible key material, it is the reason to pick gokey over a password-only generator.

## Maintenance, licence and upgrade cost

The repository is not archived, and the last push was on 2026-07-10. The most recent tagged release is v0.2.1 from 2026-03-31, preceded by v0.2.0 in November 2025 and v0.1.3 in April 2024. The gap between v0.1.3 and v0.2.0 is roughly a year and a half, so release cadence has not been steady, and anyone pinning a version should expect to move in larger jumps rather than small increments.

The module targets Go 1.24.0 and depends on `golang.org/x/crypto` and `golang.org/x/term`, with `golang.org/x/sys` as an indirect dependency. That is a small dependency surface, which limits the amount of third-party code an upgrade pulls in. Building from source requires a Go toolchain at or above the version in `go.mod`; precompiled binaries sidestep that.

The licence is BSD-3-Clause. That is a permissive licence, and the practical implication for adopters is that redistribution and modification are allowed provided the copyright notice and disclaimer are retained. This is a description of the licence text, not legal advice; if you plan to embed gokey in a product, have counsel review the actual LICENSE file.

One upgrade consideration is specific to this tool rather than general: if a future release changes the derivation, previously generated passwords and keys would stop reproducing. The README does not document compatibility guarantees for derivation across versions, so pin the version you generate credentials with and confirm reproducibility after any upgrade.

## Conclusion

gokey fits engineers who want reproducible passwords for many resources without syncing a vault, and who are willing to protect one strong master password and, for key generation, a seed file. It is the wrong tool if you need to store existing credentials, rotate a single password without changing your master password, or share credentials with a team. Before adopting it, verify that you can regenerate the same output from the same master password and realm, and confirm you have an offline copy of any seed file you create.

## FAQ

### What does cloudflare/gokey do?

It is a password manager that does not use a vault. It derives passwords and private keys from a master password and a realm string, so nothing has to be stored, backed up or synced.

### How do I install cloudflare/gokey?

The README gives a Go install command: go install github.com/cloudflare/gokey/cmd/gokey@latest, which places the gokey binary in $GOPATH/bin (by default $HOME/go/bin). Precompiled binaries are also listed in the Releases section.

### What is the difference between simple mode and using a seed file in gokey?

In simple mode the master password is the only source of entropy, so passwords are as strong as that password and key generation is blocked unless you pass -u. With -s and a seed file, the master password only protects the seed, and the generated passwords and keys are derived from the seed data instead.

### What password and key types can gokey generate?

The README lists pass, seed, raw, ec256, ec384, ec521, rsa2048, rsa4096, x25519 and ed25519, selected with the -t flag. The default is pass, and -l controls the password length or the number of bytes for a raw stream.

### What happens if I forget my master password or lose my seed file?

The README states that if you forget your master password or lose your seed file, you lose all derived passwords and keys as well. Nothing is stored, so there is no recovery path described.

## Sources

- [cloudflare/gokey on GitHub](https://github.com/cloudflare/gokey)
- [Issues](https://github.com/cloudflare/gokey/issues)
- [License: BSD-3-Clause](https://github.com/cloudflare/gokey/blob/main/LICENSE)
- [README](https://github.com/cloudflare/gokey/blob/main/README.md)
- [Releases](https://github.com/cloudflare/gokey/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cloudflare-gokey
