EcoPaste: a local-first clipboard manager for macOS and Windows
🎉跨平台的剪贴板管理工具 | Cross-platform clipboard management tool
At a glance
- What is it?
- EcoPaste is a Rust-first Tauri desktop app that keeps clipboard history in local SQLite and skips content that looks like a secret. This is what the repository documents, where the boundaries are, and how it compares with CopyQ and Maccy.
- Who is it for?
- Adopt EcoPaste if you work on macOS or Windows, want clipboard history searchable offline, and are comfortable with a project whose latest published build is a nightly dated 2026-08-13. Skip it if you need Linux or Wayland support, a stable tagged release, or a clipboard manager that stores history in the cloud.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 48 days ago.
- What is it written in?
- Mainly Rust, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem EcoPaste targets, and who it is for
Clipboard managers exist because the operating system clipboard holds one item. EcoPaste's README describes it as "a local-first clipboard manager for macOS and Windows" and lists the content types it captures: plain text, HTML, RTF, images, files and folders. That list matters more than the phrase clipboard manager. Tools that only keep text are cheap to build; keeping file and folder references means the app has to track paths that can move or disappear between the copy and the paste.
The intended user is someone who copies constantly and does not want that history leaving the machine. The README states that clipboard data, resources and settings stay local, and that search runs through SQLite FTS5 rather than a remote index. There is no account, no sync service and no server component in the repository layout. If your threat model includes the clipboard contents of a work laptop, that is the design decision you are buying.
It is not aimed at people who want clipboard history across devices. Nothing in the README mentions sync, and the backup format is a file you move yourself.
Rust owns behavior, React renders: the Tauri split
The README states the architecture directly: "durable behavior lives in Rust, while the React frontend focuses on rendering and interaction." The repository backs that up. There is a src-tauri/ directory for the Rust side and a src/ directory for the frontend, with package.json pinning React 19, Tauri v2 bindings and Vite. The npm package is named eco-paste and declares Apache-2.0.
The data flow implied by the feature list runs in one direction. Native shortcuts and tray integration trigger capture in Rust; captured items are written to a local SQLite database; the React window queries that database and renders the list, with react-virtuoso handling long histories. Filtering by source application and content type, plus FTS5 search, are read paths over the same store. Preview windows, notes, pins and favorites are writes back into it.
The secret-skipping feature sits on the capture path, before storage. The README says EcoPaste skips "high-confidence secrets such as private keys, service tokens, AWS keys, and JWTs." That word high-confidence is doing real work. Pattern matching of this kind is a filter, not a guarantee, and the README does not claim otherwise.
One consequence of the Rust-first split is that the frontend cannot be swapped for a different framework without touching the boundary. That is a maintainability choice, and it raises the cost of frontend-only contributions.
Installing EcoPaste and a first real use
The README does not contain install instructions. It points to a contribution guide for development setup and to the project homepage at https://ecopaste.cn, and the release list shows nightly builds tagged v1.1.1-nightly.20260813.1 and earlier. Treat the homepage and the releases page as the source for a downloadable build; the repository itself documents the build path, not the end-user installer.
For a local build, package.json requires Node 20 or newer and pnpm 10 or newer, and the preinstall script enforces pnpm with only-allow. The dev script chains an icon build and Vite:
pnpm install
pnpm devThe first command installs dependencies; the second builds icons and starts the Vite dev server. The Tauri side is exposed through a separate script, so a packaged desktop build goes through the Tauri CLI rather than Vite alone:
pnpm tauri devOnce the app is running, the first useful action is to copy two or three different things in a row, then open the EcoPaste window and confirm all of them appear in order. The README lists configurable capture order, size limits and retention, so if an item is missing, the size limit or retention setting is the first place to look, not the capture code. Search is the second thing to try: type a word from one of the copied items and confirm the FTS5 index returns it.
On macOS, the package list includes tauri-plugin-macos-permissions-api, which implies a permission prompt is part of first-run behavior. The README does not describe that flow.
Where EcoPaste is the wrong tool
Linux is the clearest boundary. The repository topics include linux and the description says cross-platform, but the README headline and the badge row say macOS and Windows, and package.json's description repeats that pairing. The README never documents a Linux install or a Wayland caveat. Anyone who needs a clipboard manager on a Linux desktop should not plan around EcoPaste on the strength of the topic tags.
Release channel is the second boundary. Every release listed is a nightly build, the most recent dated 2026-08-13, and package.json still declares version 1.1.0. A nightly is a moving target: the release script supports beta and rc pre-releases, which suggests the maintainers treat nightlies as the leading edge rather than the stable line. If you need a version that will not change under you, that is a reason to wait or to pin a specific build.
The third boundary is secrets. Skipping private keys, service tokens, AWS keys and JWTs reduces the chance of storing a credential in history. It does not remove the risk, because the filter is pattern-based and the README's own wording, high-confidence, admits lower-confidence cases pass through. On a shared or audited machine, a clipboard manager that persists history is still a persistence mechanism. If that is unacceptable, the right answer is no clipboard manager, not a better filter.
Finally, the README does not document rollback for an upgrade, and it does not describe what happens to existing history when the SQLite schema changes between nightlies. Export a .ecopastebak before upgrading.
How EcoPaste differs from CopyQ and Maccy
CopyQ and Maccy are the two comparisons people search for alongside EcoPaste, and the differences are structural rather than cosmetic.
CopyQ is a long-running clipboard manager with a scripting interface and a plugin model, and it runs on Linux as well as macOS and Windows. Its approach is extensibility: users write commands and scripts to transform clipboard items. EcoPaste's README describes a different posture. There is no scripting surface in the feature list; the extension points are configuration (capture order, size limits, retention, display density, list sorting, window behavior) and item actions. If your workflow depends on running a shell command over every copied item, CopyQ is built for that and EcoPaste, as documented, is not.
Maccy is a macOS-only clipboard manager. The practical difference is reach: EcoPaste covers Windows in the same codebase, which matters if you move between the two. The cost is that EcoPaste carries a Tauri runtime and a React frontend, while a native macOS app can lean entirely on AppKit. The README makes no performance claim in either direction, so the honest position is that the trade-off is architectural, not measured.
Against both, EcoPaste's distinguishing feature is the combination of FTS5 search over history and the secret-skipping filter on capture. Neither is unique on its own. Together with the local-only storage statement, they define what the project is optimizing for.
Maintenance, licensing and the cost of upgrading nightlies
The repository is not archived, and the last push was on 2026-08-13. The release history shows nightlies at roughly monthly or better intervals through July and August 2026, which is consistent with ongoing work, but the published artifacts are pre-release builds rather than a tagged stable line.
That shapes the upgrade cost. Nightly builds change frequently, the SQLite store is the durable part of the app, and the README documents export and import of .ecopastebak backups including encrypted containers. The safe upgrade path the documentation supports is: export a backup, install the new build, import if the history does not survive. The README does not document a downgrade path, so keeping the previous installer is your own responsibility.
Licensing is Apache-2.0, declared in both package.json and the LICENSE file. Apache-2.0 is a permissive licence with an explicit patent grant and requires that notices and the licence text be preserved in redistributions. If you fork EcoPaste into an internal tool, the obligation to keep attribution travels with the code. That is a summary of the licence identifier in the repository, not legal advice; read LICENSE before redistributing.
One more cost worth naming: the repository carries configuration directories for several AI coding assistants (.claude/, .cursor/, .codex/, .gemini/ and others) alongside AGENTS.md. That tells you the maintainers expect contributions to be written with those tools in the loop. It does not change the licence or the build, but it does mean the contribution guide is the document to read before sending a patch.
Editorial conclusion
Adopt EcoPaste if you work on macOS or Windows, want clipboard history searchable offline, and are comfortable with a project whose latest published build is a nightly dated 2026-08-13. Skip it if you need Linux or Wayland support, a stable tagged release, or a clipboard manager that stores history in the cloud. Verify before installing: which release channel you are downloading from, whether the macOS accessibility permission prompt appears on first paste, and whether the .ecopastebak export restores cleanly on your machine.
Frequently asked questions
What is EcoPaste and which platforms does it support?
EcoPaste is an open-source clipboard manager built with a Rust-first Tauri architecture. The README describes it as a local-first clipboard manager for macOS and Windows, and those are the two platforms its badge row lists.
How do I install EcoPaste?
The README does not contain install steps; it points to the project homepage at https://ecopaste.cn and to the contribution guide for development setup. For a local build, package.json requires Node 20 or newer and pnpm 10 or newer, and the preinstall script enforces pnpm.
Does EcoPaste keep my clipboard data on my machine?
The README states that clipboard data, resources and settings stay local to your machine, and that search runs through SQLite FTS5. There is no sync or account feature in the documented feature list.
Does EcoPaste store passwords and API keys in the clipboard history?
The README says EcoPaste protects sensitive content by skipping high-confidence secrets such as private keys, service tokens, AWS keys and JWTs. Because the filter is pattern-based and described as high-confidence, it is a reduction in risk rather than a guarantee.
Is there a stable release of EcoPaste, or only nightly builds?
The release list contains nightly builds only, the most recent tagged v1.1.1-nightly.20260813.1, while package.json declares version 1.1.0. The release scripts support beta and rc pre-releases, but no stable tag appears in the release history given.
Can I back up and restore EcoPaste history?
The README lists export and import of .ecopastebak backups, including encrypted backup containers. It does not document a downgrade path, so export a backup before changing builds.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/ecopastehub-ecopaste)